Email this article   Print article 


Apple MacBooks Vulnerable To Battery Firmware Hacks

By Stefanie Hoffman
July 22, 2011    8:21 PM ET

Page 2 of 2

In addition, the battery firmware attacks could be conducted remotely, without requiring hackers to have the computers in their possession for successful execution.

“A remote exploit gets you onto the computer and you can start to make changes,” Miller said. “You can make all of these changes while the battery is plugged into the computer.”

What’s more, because a computer’s battery is an unlikely source of infection, an attack could potentially remain undetected by IT administrators, allowing the malware to be used in repeated attacks.

Miller plans to expose the battery firmware exploit during the Black Hat USA hacker conference in Las Vegas during the first week of August. During his presentation, he will also be releasing a tool, known as Caulkgun, that users can download allowing password randomization on the battery's chips.

While Miller tested the hack on a variety of Macbooks--Macbook Pro, Macbook Air-- he said that the exploit could be applied to any operating system. Miller added that he notified Apple of the vulnerability in its battery chips, but has yet to hear back from Cupertino on the status of the fix.

However, Miller added that a typical cyber criminal intent on obtaining credit card and other financial information would likely not use a battery firmware hack for financial gain.

A more likely scenario would be ruining the battery or rendering the computer inoperable and then extorting the owner with the use of their own computer, Miller said.

“The worst thing they would probably do is trash the battery so it doesn’t work anymore,” Miller said. “There’s really not any way you can make money from this.”



<< Previous | 1 | 2

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Tech 10: Hot Antivirus Alternatives For 2013

CRN identifies 10 vendors that have developed innovative ways to detect malware and analyze threats to better protect corporate networks. They take a giant step beyond traditional signature technologies.

10 Emerging Security Technologies Gaining Interest, Adoption

Despite some security defenses being only in their infancy, they are attracting interest for addressing BYOD issues, cloud security concerns and stolen account credentials. Here's a look at some of the top new security areas gaining industry interest.

5 Government Intelligence Facilities You've Never Heard Of

One facility has been around since the dawn of space exploration, while other buildings are still in construction. But, they all have serious data analysis and surveillance support activities associated with them.

  More Slide Shows




Related Videos
Loading...