If you open your computer's case, it is already vulnerable to hacking, because no consumer x86 computer is secure under that threat model. Yes, this is another bullshit hyped attack with minimal practical consequence because under their threat model you are already pwned.https://twitter.com/WIRED/status/1259669698494509056 …
-
Show this thread
-
If your attack relies on soldering wires to a flash chip and/or getting root access to the computer, you are hereby banned from the news media.
7 replies 27 retweets 212 likesShow this thread -
Replying to @marcan42
I described from the top of the piece exactly what's required for the attack. (Which doesn't include soldering, by the way) It's a new, invasive, physical access hacking technique, no more, no less.
1 reply 0 retweets 0 likes -
Replying to @a_greenberg
Here we go again. Do you know what a threat model is? Do you realize there are approximately two dozen other ways you could completely compromise a laptop after opening the case like that? Does it make sense then that the headline is total clickbait?
2 replies 1 retweet 9 likes -
Replying to @marcan42
Yep, I do know what a threat model is! And described exactly what's necessary to carry out the attack in the piece, so users can judge for themselves if they should be scared. If there are 24 other previously known unpatchable ways to do this attack, that is actually news to me.
1 reply 0 retweets 0 likes -
Replying to @a_greenberg
If you want to own a computer by opening the case, all you need to do is flash the BIOS chip. Or the firmware chip of any device with DMA access. Or any internal device with no DMA access but a buggy driver (i.e. most). Or just hijack a bus like LPC. The list goes on.
2 replies 0 retweets 3 likes -
This Tweet is unavailable.
-
This Tweet is unavailable.
TB has security mechanisms against this, with trusted devices. The attacks described require either opening the laptop or opening an already trusted device.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.