Reply to topic  [ 7 posts ] 
MacBook batteries found to be vulnerable to malware 
Author Message
Doesn't have much of a life
User avatar

Joined: Fri Apr 24, 2009 12:43 pm
Posts: 1798
Location: Manchester
Reply with quote
MacBook batteries found to be vulnerable to malware:
http://www.macworld.co.uk/mac/news/?newsid=3293117

Quote:
After studying the batteries in several MacBooks, MacBook Pros and MacBook Airs, security researcher Charlie Miller found that Apple laptop microcontroller chips are shipped with default passwords that, once discovered, can be used as a hiding spot for malware as well as a conduit for disabling the battery and even blowing it up.


I'm struggling to get my head around this. How the hell can a battery be hacked? What I mean is I can understand that it has a chip embedded to handle the power management, but how can it be used to store malware and how does it get on there in the first place? It's just bizarre!
:roll: :?

I'm guessing it's just one of those proof of concepts hacks, but still...

_________________
* Steve *

* Witty statement goes here *


Mon Jul 25, 2011 12:42 pm
Profile
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 7:35 pm
Posts: 6580
Location: Getting there
Reply with quote
I suppose it could get onto the battery using some pop-up type web program.

... or something.

I guess once it's on there all they can really do is destroy the battery. I can't really see how they could do anything with it though?

Unless it was able to get to the low level OS and access the network connection or something?

No idea...

_________________
Oliver Foggin - iPhone Dev

JJW009 wrote:
The count will go up until they stop counting. That's the way counting works.


Doodle Sub!
Game Of Life

Image Image


Mon Jul 25, 2011 1:03 pm
Profile WWW
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
The battery must communicate its status with the computer. If this interface isn't well written and secured, then a bit of code running on the computer (which could be loaded using one of the dozens of unpatched vulnerabilities in OS X), then they can probably force a buffer overflow on the battery, causing code to be executed on the battery.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Tue Jul 26, 2011 3:59 am
Profile ICQ
I haven't seen my friends in so long
User avatar

Joined: Fri Apr 24, 2009 6:37 am
Posts: 6954
Location: Peebo
Reply with quote
And I doubt that the majority of batteries will have a secure design because it has never occurred to anyone that a battery could be used to store or propagate malware/viruses.

_________________
When they put teeth in your mouth, they spoiled a perfectly good bum.
-Billy Connolly (to a heckler)


Tue Jul 26, 2011 5:43 am
Profile
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
davrosG5 wrote:
And I doubt that the majority of batteries will have a secure design because it has never occurred to anyone that a battery could be used to store or propagate malware/viruses.

I agree. Though has this route ever been used by a virus writer? It might be all theoretical right now. I suspect that every laptop is vulnerable in this way.

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Tue Jul 26, 2011 9:22 am
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 7:56 pm
Posts: 12030
Reply with quote
When are they updating ClamXAV to run on your battery then? ;)

_________________
www.alexsmall.co.uk

Charlie Brooker wrote:
Windows works for me. But I'd never recommend it to anybody else, ever.


Tue Jul 26, 2011 9:24 pm
Profile
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
ProfessorF wrote:
When are they updating ClamXAV to run on your battery then? ;)

I suspect that it will require a firmware upgrade to secure this route. Maybe it will be in the Lion version update? ;)

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Tue Jul 26, 2011 9:58 pm
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 7 posts ] 

Who is online

Users browsing this forum: No registered users and 7 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.