CITP Luncheon Speaker Series: Trammell Hudson – Thunderstrike 2: More Mac EFI Firmware Vulnerabilties
Sherrerd Hall, 3rd floor open space Princeton, NJ, United StatesThis talk describes Thunderstrike, an attack that installs persistent firmware modifications into the boot ROM of Apple's popular MacBooks. The bootkit can be installed by an evil-maid via the externally accessible Thunderbolt ports. Alternatively, a remote SW attack can amplify root privileges yielding the same result. Once installed, 1) it can prevent software attempts to remove it, 2) it can survive reinstallation of the operating system as well as hard drive replacement, and 3) it can spread virally across air-gaps by infecting additional Thunderbolt devices.