Cisco Learning Network Store Promotions Page
Showing posts with label Thunderbolt. Show all posts
Showing posts with label Thunderbolt. Show all posts

1.27.2015

Apple preparing fix for Thunderstrike malware in upcoming OS X 10.10.2 release

A powerful low-level malware vulnerability in Macs will soon be patched in an upcoming OS release. 

 
It's long been said, both by Apple and independent security experts, that Apple's computers are more secure than those running Windows. That does not mean, however, that Macs are invulnerable to malware threats.
 
One particularly terrifying example is called Thunderstrike. It allows a malicious actor to replace the firmware in Macs with something much more nefarious. The firmware controls extremely low-level functions of the computer, everything that happens from the moment the power button is pressed.
 
On a Macintosh, it's normally completely invisible to the user -- part of Apple's quest to keep things simple. And, as long as everything works, it's not a big deal.
 
Thunderstrike allows someone to use a Thunderbolt device, perhaps something as simple as a Thunderbolt-to-HDMI dongle, to reboot the computer and replace its firmware with custom designed backdoors. It could, in theory, completely bypass any existing protections on the computer. It would also survive reformatting of the hard drive and reinstallation of the OS X operating system, because it would be installed at the very lowest levels of the computer. Ars Technica has much more on exactly how it works.
 
It only requires brief physical access to the machine, say from someone posing as a hotel maid or a customs agent inspecting a computer at a border crossing, to plug in the compromised Thunderbolt attachment and restart the computer.
 
Without a fix from Apple, the only viable protection was to either permanently disable Thunderbolt entirely (not easy, since you'd need to do bad things to the main logic board) or keep ironclad control of your Mac at all times. Those really aren't the greatest options.
 
Apple has already rolled out temporary fixes to the Retina 5K iMac and new Mac Mini, which was introduced late last year. According to iMore, a more permanent solution is coming in OS X Yosemite 10.10.2, and it's expected to be released soon.
"To secure against Thunderstrike, Apple had to change the code to not only prevent the Mac's boot ROM from being replaced, but also to prevent it from being rolled back to a state where the attack would be possible again. According to people with access to the latest beta of OS X 10.10.2 who are familiar with Thunderstrike and how it works, that's exactly the deep, layered process that's been completed."
Luckily, no malicious versions of Thunderstrike have been discovered in the wild, but given the disclosures of US intelligence activities that have come from Edward Snowden, it wouldn't be surprising for the NSA to be examining the vulnerability for potential intelligence uses.
 
It's a good reminder that just because we use Apple products, that doesn't mean we're immune from security concerns -- and it's always a good idea to make sure you're running the latest versions of Apple's operating systems on all your devices.
 
How do you protect your Apple products from potential security vulnerabilities? Let us know in the comments below.
 
~ Jordan Golson 

12.25.2014

Sorry Apple fans, your precious Macs are at risk -- beware of Thunderbolt-injected rootkits

 
Apple makes really great products; Mac computers included. I respect the closed garden and restrictive hardware from a quality perspective, but I take umbrage with the high prices and questionable business practices. While OS X may look pretty from the outside looking in, after playing with it for long periods of time, it becomes apparent that all which glitters is not gold. My interest in Apple's operating system was very short-lived, as Microsoft's Windows is just a superior product.
 
Apple promoters are quick to point out the safety and security of Macs, as Apple is less likely to be targeted by malicious software and contains fewer vulnerabilities. As the smart people know, however, OS X is only "safer", as it has a far smaller install base. In other words, because of its lack of popularity, bad guys pay less attention -- its increased safety and security is a myth. I hate to break it to you Apple fans, but it turns out your precious Macs are currently at risk. Comically, this vulnerability is found in Thunderbolt -- you know, that wildly unpopular standard that Apple seems to love, but its accessories are too costly for many users. True, some Windows machines have Thunderbolt, but it is mostly an Apple affair, and now the fruit-logo company's computers are vulnerable because of its method of implementation.
 
"It is possible to use a Thunderbolt Option ROM to circumvent the cryptographic signature checks in Apple's EFI firmware update routines. This allows an attacker with physical access to the machine to write untrusted code to the SPI flash ROM on the motherboard and creates a new class of firmware bootkits for the MacBook systems. There are neither hardware nor software cryptographic checks at boot time of firmware validity, so once the malicious code has been flashed to the ROM, it controls the system from the very first instruction. It could use SMM, virtualization and other techniques to hide from attempts to detect it", says Trammell Hudson.
 
Hudson further explains, "our proof of concept bootkit also replaces Apple's public RSA key in the ROM and prevents software attempts to replace it that are not signed by the attacker's private key. Since the boot ROM is independent of the operating system, reinstallation of OS X will not remove it. Nor does it depend on anything stored on the disk, so replacing the harddrive has no effect. A hardware in-system-programming device is the only way to restore the stock firmware. Additionally, other Thunderbolt devices' Option ROMs are writable from code that runs during the early boot and the bootkit could write copies of itself to new Thunderbolt devices. The devices remain functional, which would allow a stealthy bootkit to spread across air-gap security perimeters through shared Thunderbolt devices".
 
Yikes. My colleague Mihaita touched on this earlier today; it is extremely embarrassing for Apple, and makes its computers highly susceptible to attack. Believe it or not, it is based on a two-year old vulnerability. What makes this particularly nasty, is that it doesn't matter if your computer is password protected; crafty hackers can simply wreak havoc by accessing your Thunderbolt port with a malicious device. Hell, malicious manufacturers can embed this in legitimate products, creating stealth-like hardware that users willingly install.
 
Does this make you trust OS X less? Tell me in the comments.
 
Photo CreditAngela Waye / Shutterstock
 
~ Brian Fagioli