Apple laptops may be vulnerable to ‘irremovable’ virus
A security expert has found a way to install malicious code on a tiny chip built into Apple laptops which would resist any attempt at removal – even replacing the entire hard disk will not delete it.
The attack, which is being called Thunderstrike, is virtually undetectable and would require an attacker to get access to a machine for mere moments. And because it is new, no security software will even be looking out for it.
Trammell Hudson, who works for New York hedge fund Two Sigma Investments, said that the discovery came about when his employer asked him to look into the security around Apple laptops.
“We were considering deploying MacBooks and I was asked to use my reverse engineering experience to look into the reports of rootkits on the Mac,” he wrote in an annotated version of a talk he gave at the 31C3 conference .
His first step was dismantling one of the laptops to get access to the boot ROM, a small chip which contains the code which gets the computer up-and-running when first switched on, before the main operating system is even loaded.
Malicious code can be hidden in this ROM which, unlike a normal virus which resides on the hard disk, cannot be removed. This is known as a bootkit attack. That code can be made to do anything an attacker wishes, from covertly observing the user to leaking sensitive data held on the machine.
Although previous researchers have found that modifying the contents of the ROM in Apple laptops results in the computer being rendered completely unusable, as security measures look for any changes and shuts down if it finds them, Hudson was able to circumvent these checks and install any code he wished.
He said that these security measures were always “doomed to fail” and “futile” because anyone who can get access to the contents of the ROM can also get access to the code which checks the ROM for changes. Instead, he says, there should be some unchangeable hardware chip which performs the checks.
It was further found that the attack could be made without physically taking the machine apart to get to the chip, simply by using the Thunderbolt port. Theoretically any device – a monitor, hard disk or printer – could be used to install malicious code, just by plugging it in following simple steps.
“Since it is the first OS X firmware bootkit, there is nothing currently scanning for its presence. It controls the system from the very first instruction, which allows it to log keystrokes, including disk encryption keys, place backdoors into the OS X kernel and bypass firmware passwords,” Hudson said.
“It can’t be removed by software since it controls the signing keys and update routines. Reinstallation of OS X won’t remove it. Replacing the SSD won’t remove it since there is nothing stored on the drive.
“Given a few minutes alone with your laptop, Thunderstrike allows the boot ROM firmware to be replaced, regardless of firmware passwords or disk encryption. Thunderstrike in its current form has been effective against every MacBook Pro/Air/Retina with Thunderbolt that I’ve tested, which is most models since 2011.”
Hudson has said that Apple is rolling-out a "partial fix" as a firmware update which would stop the ROM being overwritten with malicious code in some circumstances, but not all - such as when a machine is rebooted with a malicious Thunderbolt device plugged-in. He first approached the company about the flaw in 2013 but says that some laptops are still vulnerable as hackers could trick machines into “downgrading” software to a version that doesn’t include the new fix, then attacking the machine.
Videos
Interview with Francis Malige, EBRD Managing Director
Armenians Commemorating 106th Anniversary of Genocide
Biden Under Pressure to Recognize Armenian Genocide - KTLA 5 News
Governance and Oversight Capacities Account for Our Bank's Robust Management System - Philip Lynch, Independent Board Member at Ameriabank
'Mr. President, It Is Now in Your Power to Right Decades of Denial' - US Congressman Adam Schiff Urges Joe Biden to Recognize Armenian Genocide
Armenians of Nagorno-Karabakh in Despair After Trauma of Military Defeat - France 24
Interview with Kakhaber Kiknavelidze, an Independent Member of Ameriabank Board of Directors
Only Terrorists Keep Hostages, Putting Forward Preconditions for Their Release - Edmon Marukyan
Rep Adam Schiff Says Congress Should Recognize Artsakh
UN's Guterres Issues Global Appeal to Make 2021 'Year of Healing'
NASA's Mars 2020 Perseverance Rover Landing Animations
Azerbaijan Uses Prohibited Phosphorus Chemical Munitions - Defense Army Video
Artsakh Defense Army Units Neutralizing Azerbaijani Arms Supplies
Artsakh Defense Army Units Neutralizing Azerbaijani Drone
Nagorno-Karabakh's Status Has Been At the Heart of Our Approach - Zohrab Mnatsakanyan
Artsakh Defense Army Releases Video Featuring Damaged Azerbaijani Military Equipment
Artsakh Defense Army Units Inflicting Manpower Losses on Azerbaijan
Gas Pipeline Damaged in Azerbaijani Fire Targeting Nagorno-Karabakh's Capital
President Armen Sarkissian Meets Emmanuel Macron at Élysée Palace
Artsakh Defense Army Neutralizes Azerbaijani Military Hardware
Artsakh Defense Army Units Neutralizing Azerbaijani Military Infrastructures
President Armen Sarkissian Meets with NATO Secretary-General in Brussels
Buildings and Homes Lying in Ruins in Nagorno-Karabakh's Capital After Azerbaijani Shelling
Artsakh Defense Army's Precision Fire Gives Deadly Blow to Enemy
Artsakh Defense Army Units Destroying Azerbaijani Tank
Zohrab Mnatsakanyan: Ceasefire Does not Mandate Azerbaijan to Kill Civilians and Hit Civilian Settlements
Armenians Protest Outside Turkrish Embassy in Los Angeles
Losses in Azerbaijan's Military Featured in Defense Army Footage
Artsakh Defense Army Neutralizing Adversary's Transport Column
Turkey openly backs Azerbaijan 'far more aggressively than in the past' - ABC News on Syrian mercenaries fighting in Karabakh
Iconic Armenian Church Hit in Azerbaijani Attacks in Nagorno-Karabakh City (photos)
Artsakh Defense Army Continues High-Precision Strikes
War Situation in Karabakh on European Parliament's Agenda
Call for Urgent Action: Armenian Journalist Brings Intn'l Colleagues' Attention to Situation iin Artsakh After Azerbaijani Attacks
Turkey's Support to Syrian Mercenaries Fighting Against Artsakh: Facts About Azerbaijani Aggression
Nagorno-Karabakh's Capital Under Azerbaijani Strikes
Armenian Armed Forces Neutralize Azerbaijani Defense Positions
ArmenianTroops Destroy Azerbaijani Armored Fighting Vehicle on Frontline
There is a solid evidence that Azerbaijan has launched a thoroughly planned attack on the NKR
EU calls for Immediate End to Hostilities over Nagorno-Karabakh
- 15:20 • 24.05.21 Interview with Francis Malige, EBRD Managing Director
- 11:39 • 24.04.21 Armenians Commemorating 106th Anniversary of Genocide
- 09:40 • 23.04.21 Biden Under Pressure to Recognize Armenian Genocide - KTLA 5 News
- 15:34 • 22.04.21 Governance and Oversight Capacities Account for Our Bank's Robust Management System - Philip Lynch, Independent Board Member at Ameriabank
- 14:09 • 21.04.21 'Mr. President, It Is Now in Your Power to Right Decades of Denial' - US Congressman Adam Schiff Urges Joe Biden to Recognize Armenian Genocide
- 12:37 • 03.04.21 Armenians of Nagorno-Karabakh in Despair After Trauma of Military Defeat - France 24
- 17:33 • 11.03.21 Interview with Kakhaber Kiknavelidze, an Independent Member of Ameriabank Board of Directors
- 17:57 • 26.01.21 Only Terrorists Keep Hostages, Putting Forward Preconditions for Their Release - Edmon Marukyan
- 13:33 • 22.01.21 Rep Adam Schiff Says Congress Should Recognize Artsakh
- 09:42 • 29.12.20 UN's Guterres Issues Global Appeal to Make 2021 'Year of Healing'
- 18:41 • 24.12.20 NASA's Mars 2020 Perseverance Rover Landing Animations
- 13:33 • 31.10.20 Azerbaijan Uses Prohibited Phosphorus Chemical Munitions - Defense Army Video
- 16:37 • 30.10.20 Artsakh Defense Army Units Neutralizing Azerbaijani Arms Supplies
- 11:25 • 28.10.20 Artsakh Defense Army Units Neutralizing Azerbaijani Drone
- 13:45 • 24.10.20 Nagorno-Karabakh's Status Has Been At the Heart of Our Approach - Zohrab Mnatsakanyan
- 11:51 • 24.10.20 Artsakh Defense Army Releases Video Featuring Damaged Azerbaijani Military Equipment
- 11:40 • 24.10.20 Artsakh Defense Army Units Inflicting Manpower Losses on Azerbaijan
- 10:39 • 24.10.20 Gas Pipeline Damaged in Azerbaijani Fire Targeting Nagorno-Karabakh's Capital
- 12:41 • 23.10.20 President Armen Sarkissian Meets Emmanuel Macron at Élysée Palace
- 12:16 • 23.10.20 Artsakh Defense Army Neutralizes Azerbaijani Military Hardware
- 12:02 • 22.10.20 Artsakh Defense Army Units Neutralizing Azerbaijani Military Infrastructures
- 10:35 • 22.10.20 President Armen Sarkissian Meets with NATO Secretary-General in Brussels
- 10:51 • 17.10.20 Buildings and Homes Lying in Ruins in Nagorno-Karabakh's Capital After Azerbaijani Shelling
- 15:09 • 15.10.20 Artsakh Defense Army's Precision Fire Gives Deadly Blow to Enemy
- 13:13 • 13.10.20 Artsakh Defense Army Units Destroying Azerbaijani Tank
- 12:56 • 12.10.20 Zohrab Mnatsakanyan: Ceasefire Does not Mandate Azerbaijan to Kill Civilians and Hit Civilian Settlements
- 12:23 • 12.10.20 Armenians Protest Outside Turkrish Embassy in Los Angeles
- 17:23 • 09.10.20 Losses in Azerbaijan's Military Featured in Defense Army Footage
- 15:53 • 09.10.20 Artsakh Defense Army Neutralizing Adversary's Transport Column
- 14:11 • 09.10.20 Turkey openly backs Azerbaijan 'far more aggressively than in the past' - ABC News on Syrian mercenaries fighting in Karabakh
- 15:52 • 08.10.20 Iconic Armenian Church Hit in Azerbaijani Attacks in Nagorno-Karabakh City (photos)
- 10:57 • 08.10.20 Artsakh Defense Army Continues High-Precision Strikes
- 14:24 • 07.10.20 War Situation in Karabakh on European Parliament's Agenda
- 19:31 • 05.10.20 Call for Urgent Action: Armenian Journalist Brings Intn'l Colleagues' Attention to Situation iin Artsakh After Azerbaijani Attacks
- 16:17 • 04.10.20 Turkey's Support to Syrian Mercenaries Fighting Against Artsakh: Facts About Azerbaijani Aggression
- 12:39 • 04.10.20 Nagorno-Karabakh's Capital Under Azerbaijani Strikes
- 13:49 • 03.10.20 Armenian Armed Forces Neutralize Azerbaijani Defense Positions
- 10:12 • 29.09.20 ArmenianTroops Destroy Azerbaijani Armored Fighting Vehicle on Frontline
- 23:42 • 28.09.20 There is a solid evidence that Azerbaijan has launched a thoroughly planned attack on the NKR
- 18:45 • 28.09.20 EU calls for Immediate End to Hostilities over Nagorno-Karabakh
Most popular articles Today Yesterday For a week
Economy
-
11:33 • 21.11.24 Unibank to Issue Subordinated Bonds for the First Time in Armenia
-
16:51 • 11.11.24 New features for Armeconombank’s Premium cardholders
Event
-
11:50 • 20.11.24 US embassy in Kyiv shuts down over anticipated air attack
-
14:40 • 19.11.24 Ucom’s 5G network launched in 11 new cities
Science/tech
-
14:18 • 08.05.24 AstraZeneca withdrawing Covid vaccine worldwide