4.9 • 696 Ratings
🗓️ 27 February 2019
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, February 27th, 2019 edition of the Sands and it's Tom Sonders Stormcast. My name is Johannes Ulrich. |
0:09.6 | And I'm recording from Augusta, Georgia. |
0:14.2 | Researchers from the University of Cambridge, Rice University, and SRIZ University and SRI International took another look at Thunderbolt. Now, |
0:22.8 | Thunderbolt has had some well-known issues and really the type of issue went back all the way, |
0:30.1 | I think at least to Firewire. The problem here is that pretty much these interfaces are |
0:36.1 | providing some form of direct memory access, |
0:40.1 | so someone connected to these interfaces in theory would be able to read arbitrary memory. |
0:48.4 | Now in Thunderbolt, actually, vendors did address this issue with input-out output memory management units. These IOM |
0:57.0 | MUs as they're called can be used to limit what memory a particular peripheral device has access |
1:03.4 | to. But turns out that even though many modern operating systems support IOMUs, most of them |
1:10.1 | actually all but MacOS, do not have |
1:13.4 | them enabled. And in some cases, the implementations are also far from perfect. One vulnerability |
1:20.2 | in macOS, for example, allowed attackers to execute arbitrary code. However, this vulnerability |
1:27.0 | was fixed by Apple back in 2016. |
1:31.0 | To experiment with Thunderbolt, these researchers actually implemented a network card in software |
1:37.3 | that they then connected via Thunderbolt to the test system. |
1:41.8 | And by implementing a network card in software after it was recognized as a network |
1:46.2 | card by the operating system they were then able to essentially interact via the Thunderbolt |
1:53.4 | port at will the quick lesson here is be careful with what you're connecting to Thunderbolt |
2:00.4 | like I said the same applies to other ports as well. |
2:04.5 | Also, be somewhat careful with cables, in particular with Thunderbolt. |
2:08.5 | Most of the cables that you're using aren't actually just passive pieces of copper, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.