Thunderbolt enables severe security threats

Security researchers at the Network and Distributed Systems Security Symposium in San Diego are announcing the results of some fascinating research they’ve been working on. They “built a fake network card that is capable of interacting with the operating system in the same way as a real one” and discovered that

Such ports offer very privileged, low-level, direct memory access (DMA), which gives peripherals much more privilege than regular USB devices. If no defences are used on the host, an attacker has unrestricted memory access, and can completely take control of a target computer: they can steal passwords, banking logins, encryption keys, browser sessions and private files, and they can also inject malicious software that can run anywhere in the system.

Vendors have been gradually improving firmware and taking other steps to mitigate these vulnerabilities, but the same features that make Thunderbolt so useful also make them a much more serious attack vector than USB ever was. You may want to consider ways to disable your Thunderbolt drivers unless you can be sure that you can prevent physical access to your machine.

9 Comments

  1. 2019-02-26 7:00 pm
    • 2019-02-27 12:07 pm
      • 2019-02-28 6:15 pm
  2. 2019-02-26 7:25 pm
  3. 2019-02-27 2:28 am
  4. 2019-02-27 10:04 am
    • 2019-02-27 11:40 am
  5. 2019-02-27 8:20 pm
  6. 2019-03-01 6:32 am