If you open your computer's case, it is already vulnerable to hacking, because no consumer x86 computer is secure under that threat model. Yes, this is another bullshit hyped attack with minimal practical consequence because under their threat model you are already pwned.https://twitter.com/WIRED/status/1259669698494509056 …
-
-
Since the authors are getting nitpicky: If your attack relies on disassembling your computer, or one of your already trusted devices, and hooking up wires to it without technically soldering, you are still banned from the news media.
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
I found a huge vulnerability in the bank vault! Someone with the keys to open it can get inside!
-
Dual access rooms were invented for this very reason. So you at least can't get back out of the bank vault.
End of conversation
New conversation -
-
-
I always say if someone has physical access to your device consider it game over.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
I described from the top of the piece exactly what's required for the attack. (Which doesn't include soldering, by the way) It's a new, invasive, physical access hacking technique, no more, no less.
-
Here we go again. Do you know what a threat model is? Do you realize there are approximately two dozen other ways you could completely compromise a laptop after opening the case like that? Does it make sense then that the headline is total clickbait?
- Show replies
New conversation -
-
-
the only interesting thing in that paper is downgrade from SL3 by using TBT2 compatibility mode, which i'd like to see an actual exploit for, by the way, because i couldn't even get the latter mode to work at all
-
(by "exploit" here i mean "description of a setup that causes a benign PCIe device to enumerate through PCIe with SL3 enabled")
- Show replies
New conversation -
-
- Show replies
New conversation
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.