Skip to main content

Thunderbolt flaw allows access to a PC’s data in minutes

Thunderbolt flaw allows access to a PC’s data in minutes

/

Affects all Thunderbolt-enabled PCs manufactured before 2019, and some after that

Share this story

Thunderbolt

Vulnerabilities discovered in the Thunderbolt connection standard could allow hackers to access the contents of a locked laptop’s hard drive within minutes, a security researcher from the Eindhoven University of Technology has announced. Wired reports that the vulnerabilities affect all Thunderbolt-enabled PCs manufactured before 2019. 

Although hackers need physical access to a Windows or Linux computer to exploit the flaws, they could theoretically gain access to all data in about five minutes even if the laptop is locked, password protected, and has an encrypted hard drive. The entire process can reportedly be completed with a series of off-the-shelf components costing just a few hundred dollars. Perhaps most worryingly, the researcher says the flaws cannot be patched in software, and that a hardware redesign will be needed to completely fix the issues.

Apple’s Macs have offered Thunderbolt connectivity since 2011, but researchers say that they’re only “partially affected” by Thunderspy if they’re running macOS. The result, the report claims, is that macOS systems are vulnerable to attacks similar to BadUSB. This is a security flaw that emerged back in 2014 which can allow an infected USB device to take control of a computer, steal data, or spy on a user.

Björn Ruytenberg, the researcher who discovered the vulnerabilities, has posted a video showing how an attack is performed. In the video, he removes the backplate and attaches a device to the inside of a password-protected Lenovo ThinkPad laptop, disables its security, and logs in as though he had its password. The whole process takes about five minutes. 

This is not the first time security concerns have been raised about Intel’s Thunderbolt technology, which relies on direct access to a computer’s memory to offer faster data transfer speeds. In 2019, security researchers revealed a Thunderbolt vulnerability they called “Thunderclap” which allowed seemingly innocuous USB-C or DisplayPort hardware to compromise a device. Security issues like these are reportedly the reason Microsoft hasn’t added Thunderbolt connectors to its Surface devices.

In a blog post responding to the report, Intel claims that the underlying vulnerability is not new, and that it was addressed in operating system releases last year. However, Wired reports that this Kernel Direct Memory Access (DMA) Protection has not been universally implemented. The security researchers say they could only verify that some HP and Lenovo laptops used it, and that they couldn’t find any Dell machines with the protection applied. In comments emailed to The Verge, a spokesperson for Dell disputed this finding, and said that in 2019 it started shipping laptops which have Kernel DMA protection when SecureBoot is enabled.

Ultimately, Ruytenberg says that the only way for users to fully prevent against such an attack is for them to disable their computer’s Thunderbolt ports in their machine’s BIOS, enable hard drive encryption, and turn off their computer when leaving it unattended. The researcher has developed a piece of software called Spycheck (available via the Thunderspy site) that they say should tell you whether your machine is vulnerable to the attack.

Thunderbolt 3 is due to be integrated into the USB 4 specification. Researchers say that USB 4 controllers and peripherals could also be vulnerable and will need to be tested once available.

Update May 11th, 8:07AM ET: Updated with more details about the vulnerabilities in macOS.

Update May 12th, 3:20AM ET: Updated with Dell’s response to findings.

Today’s Storystream

Feed refreshed An hour ago Yes, it happened again.

R
Twitter
Richard LawlerAn hour ago
PC gamers showed up for a PlayStation hit.

NPD’s August update for videogame sales has arrived, noting that PS5 was number one in hardware sales for the month and that new-gen hardware sales are up significantly from last year due to improved supply for both the PS5 and Xbox Series X / S.

But the most astounding leap came from Marvel’s Spider-Man, which jumped from 84th on the chart the month before to number 3, thanks to Sony re-releasing the PlayStation exclusive on PC via Steam (and Steam Deck).


D
External Link
Dan SeifertAn hour ago
Apple’s CarPlay is still frustratingly basic.

Stephen Hackett at 512 Pixels has blogged about the frustrations he’s had migrating to a new iPhone and not having his CarPlay preferences carry over, despite every other app on his phone copying over correctly.

I’m with him on that, but I’m more annoyed by the second point he highlights: CarPlay still treats every vehicle you connect to as a different thing. Instead of preserving your preferences when you plug in to a different car, it makes you set it all up again for each new vehicle. This is annoying for families with more than one car; it’s downright maddening for frequent users of rental cars. Seems like a simple thing to fix!


R
Quote
Richard Lawler12:49 PM UTC
Adnan is out.

Yesterday, a Baltimore City Circuit judge overturned the murder conviction of Adnan Syed, setting him free — for the moment — after serving 23 years in a case documented by the podcast Serial. This morning, host Sarah Koenig released Serial’s first new episode in seven years.

It’s Baltimore, 2022. Adnan Syed has spent the last 23 years incarcerated, serving a life sentence for the murder of Hae Min Lee, a crime he says he didn’t commit. He has exhausted every legal avenue for relief, including a petition to the United States Supreme Court. But then, a prosecutor in the Baltimore State’s Attorney’s office stumbled upon two handwritten notes in Adnan’s case file, and that changed everything.


J
External Link
James Vincent11:48 AM UTC
For every living human there are 2.5 million ants, say scientists, unprompted.

I honestly don’t know what to do with this information, which comes via The Washington Post. This is just one guy’s opinion, but it seems like an awful lot of ants. Like God accidentally maxed out the ant-slider or spilled a bag of “Oops! All ants!” into the biosphere during Creation. What I need is a lie down and to not think about the millions — sorry, 20 quadrillion — of ants out there.


T
External Link
Thomas Ricker9:01 AM UTC
Pixel Watch to start at $349.99?

9to5Google reports that the Bluetooth/Wi-Fi model of the Pixel Watch will start at $349.99, after having previously reported the cellular model will cost $399.99. That puts them above Samsung’s $279.99 Galaxy Watch 5 and closer to what Apple charges (starting at $399 for the Series 8). We’ll know for sure come October 6th.


N
External Link
Nilay Patel3:25 AM UTC
“Obviously Peacock sucks.”

Kim Masters has a good piece on Warner Brothers Discovery looking for a new DC studio chief, with rampant speculation that the endgame is Comcast buying the whole thing in 2024 to beef up Peacock.

Many top industry execs are so convinced a deal will happen that some are pre-mourning an event that may never happen. “People feel like it’s Comcast for sure,” says the head of one company. “It’s going to be so depressing to lose another major studio [after Disney bought Fox]. And Warners was the Tiffany studio.”


N
The Verge
Nathan Edwards2:30 AM UTC
How’s that eSIM-only iPhone working out for you?

In my article about Apple dropping the physical SIM on the iPhone 14, I said it was “probably fine” for people on major US carriers. I also mentioned that my iPhone 11 had a physical Verizon SIM and an eSIM from a carrier in the Netherlands. This weekend I upgraded to an iPhone 14 Pro. The Verizon SIM transferred without a hitch. The other one? Not so much. Guess it’s time to admit to myself that I’m never moving back to Amsterdam.


M
External Link
Mitchell Clark1:50 AM UTC
More testimony on how working at Tesla is a nightmare for women.

Rolling Stone interviewed five women involved in the several sexual harassment lawsuits against the automaker.

Hearing them describe how they were treated, and how Tesla failed to defend them (and sometimes actively punished them) is difficult.


N
External Link
Nilay Patel1:36 AM UTC
Amazon says streaming Thursday Night Football was a huge success.

The official Nielsen numbers aren’t in, but a memo from Amazon’s Jay Marine says the game was “the most watched night of primetime in the U.S. in the history of Prime Video” and he expects the company exceeded the 12.5 million viewers it promised advertisers.

Amazon can’t go five minutes without pushing an unverifiable and unquantifiable statistic, so Marine also claimed the game was “the biggest three hours for U.S. Prime sign ups ever in the history of Amazon — including Prime Day, Cyber Monday and Black Friday.” Truly the emptiest of data points from the people who run Next Gen Stats Powered By AWS.


M
External Link
Mitchell Clark1:20 AM UTC
It sounds like the DOJ isn’t happy with the Apple v. Epic ruling

According to TechCrunch, the Department of Justice will be allowed to argue its concerns about the original ruling during the appeal trial.

The DOJ is worried the decision as it stands could make future antitrust cases more difficult — which is especially important considering reports that it’s working on its own antitrust action against Apple.


N
Instagram
Nilay PatelSep 19
Is the iPhone 13 Pro a sneaky good upgrade deal?

Carriers are all doing huge deals on iPhone 14 models, but if you just want to buy a phone outright, a discounted iPhone 13 Pro might be the best bang-for-the-buck around.


A
External Link
Adi RobertsonSep 19
I don’t think this AI-generated game actually counts as AI-generated.

This Girl Does Not Exist promises “everything you will see in this game” is created by an AI. Except... based on everything I’ve read, that includes none of the game mechanics or interface design! It’s an interesting experiment in artificially generated images and audio, but AI-generated gameplay is a uniquely weird and difficult problem. That said, I’m fascinated by the growing move toward an aesthetics of AI — and this project sits square in that zone.