Skip to main content

Hacked in 30 seconds: Thunderbolt flaw in Mac computers can disclose passwords that fast

Apple MacBook 13-inch Touch Pad
Bill Roberson/Digital Trends
If you run any type of Thunderbolt device on your Mac, you’ll want to upgrade to MacOS 10.12.2 in short order. The latest update fixes a vulnerability in FileVault 2 — Apple’s second-generation full disk encryption platform — that allowed the disclosure of your system password by simply plugging in a $300 Thunderbolt device.

This device was able to gain access even when the Mac was asleep, researchers said. The hack works by forcing the computer into a reboot (ctrl+cmd+power), plugging in the special Thunderbolt device, and waiting about 30 seconds for the password to appear.

Security researcher Ulf Frisk says the issue is the result of two problems, one being the fact that Macs do not protect themselves from Direct Memory Access (DMA) attacks before the computer is started. The other is that the FileVault password is stored in clear text in memory and not automatically scrubbed once the disk is unlocked.

The password is put in multiple locations, and does apparently change location after reboots. However, it’s in a specific memory range making it fairly easy to scan for and eventually find. Frisk notified Apple of the vulnerability in August, and agreed to withhold it pending a fix, he wrote in a blog post.

“Anyone, including but not limited to your colleagues, the police, the evil maid, and the thief will have full access to your data as long as they can gain physical access – unless the Mac is completely shut down,” Frisk pointed out.

Mac OS 10.12.2 was released last week and fixed a variety of issues including a more reliable auto unlock, graphics, and System Integrity Protection (SIP) issues on some 2016 MacBook Pros, along with a host of other stability improvements.

The Thunderbolt vulnerability was only one of the many security updates in this release: if you’re interested you can learn more about those updates from Apple’s website.

Ed Oswald
For fifteen years, Ed has written about the latest and greatest in gadgets and technology trends. At Digital Trends, he's…
Beware — even Mac open-source apps can contain malware
A pair of glasses rests on a desk in front of multiple computer monitors filled with code.

Installing apps on a Mac is generally considered to be safer than doing so on Windows and open-source software is usually benign but there are exceptions to both of these assumptions that can do untold damage to your privacy and security.

A recent discovery by Trend Micro provides a startling example of this risk. An open-source app designed to help Mac owners with iPhone and iPad app signing has been altered to include a nasty hack that steals your Apple Keychain data. The original app is called ResignTool and it’s available for free on the popular open-source site, GitHub. The app is six years old and both the code and the ready-to-run app can be downloaded from GitHub. That isn’t the problem.

Read more
This creepy Mac app can record every moment of your online life
The Rewind app on an iMac with a pink background, showing a grid of faces from a Zoom call

A new app for your Mac claims it can record every moment of your online life and store it for retrieval. We're talking about every moment, from your emails to your chats to your FaceTime and Zoom calls.

Rewind is a work in progress from Brett Bejcek and Dan Siroker, two American entrepreneurs who between them have worked with Spotify and Optimizely. They claim Rewind is like a search engine for your life.

Read more
Update your Mac now to patch this crucial security flaw
The MacBook Air on a table in front of a window.

Apple just released another critical security update with the zero-day fixes appearing in MacOS Monterey 12.6 and Big Sur 11.7. The vulnerability even affects the iPhone and iPad, requiring an update to iOS 15.7 and iPadOS 15.7 to protect these devices.

This is the eighth zero-day this year, putting Apple on track to beat last year's unfortunate record of 12 zero-day flaws.

Read more