Skip to main content

Hacked in 30 seconds: Thunderbolt flaw in Mac computers can disclose passwords that fast

Apple MacBook 13-inch Touch Pad
Bill Roberson/Digital Trends
If you run any type of Thunderbolt device on your Mac, you’ll want to upgrade to MacOS 10.12.2 in short order. The latest update fixes a vulnerability in FileVault 2 — Apple’s second-generation full disk encryption platform — that allowed the disclosure of your system password by simply plugging in a $300 Thunderbolt device.

This device was able to gain access even when the Mac was asleep, researchers said. The hack works by forcing the computer into a reboot (ctrl+cmd+power), plugging in the special Thunderbolt device, and waiting about 30 seconds for the password to appear.

Security researcher Ulf Frisk says the issue is the result of two problems, one being the fact that Macs do not protect themselves from Direct Memory Access (DMA) attacks before the computer is started. The other is that the FileVault password is stored in clear text in memory and not automatically scrubbed once the disk is unlocked.

The password is put in multiple locations, and does apparently change location after reboots. However, it’s in a specific memory range making it fairly easy to scan for and eventually find. Frisk notified Apple of the vulnerability in August, and agreed to withhold it pending a fix, he wrote in a blog post.

“Anyone, including but not limited to your colleagues, the police, the evil maid, and the thief will have full access to your data as long as they can gain physical access – unless the Mac is completely shut down,” Frisk pointed out.

Mac OS 10.12.2 was released last week and fixed a variety of issues including a more reliable auto unlock, graphics, and System Integrity Protection (SIP) issues on some 2016 MacBook Pros, along with a host of other stability improvements.

The Thunderbolt vulnerability was only one of the many security updates in this release: if you’re interested you can learn more about those updates from Apple’s website.

Editors' Recommendations

Ed Oswald
For fifteen years, Ed has written about the latest and greatest in gadgets and technology trends. At Digital Trends, he's…
This tiny ThinkPad can’t quite keep up with the MacBook Air M2
Lenovo ThinkPad X1 Nano Gen 3 rear view showing lid and logo.

While the laptop industry continues to move toward 14-inch laptops and larger, the 13-inch laptop remains an important category. One of the best is the Apple MacBook Air M2, with an extremely thin and well-built chassis, great performance, and incredibly long battery life.

Lenovo has recently introduced the third generation of its ThinkPad X1 Nano, one of the lightest laptops we've tested and a good performer as well. It's stiff competition, but which of these two diminutive laptops stands apart?
Specs and configurations

Read more
AI can probably crack your password in seconds
password manager lifestyle image

We can now add easily cracking passwords in a matter of seconds to the list of things that AI can do.

Cybersecurity firm Home Security Heroes recently published a study uncovering how AI tools analyze passwords and then use that data to crack the most common passwords used on the web.

Read more
This Mac malware can steal your credit card data in seconds
Apple's Craig Federighi speaking about macOS security at WWDC 2022.

Despite their reputation for security, Macs can still get viruses, and that’s just been proven by a malicious new Mac malware that can steal your credit card info and send it back to the attacker, ready to be exploited. It’s a reminder to be careful when opening apps from unknown sources.

The malware, dubbed MacStealer, was discovered by Uptycs, a threat research firm. It hoovers up a wide array of your personal data, including the iCloud Keychain password database, credit card data, cryptocurrency wallet credentials, browser cookies, documents, and more. That means there’s a lot that could be at risk if it gains a foothold on your Mac.

Read more