6 ms·
When Lightning Strikes Thrice: Breaking Thunderbolt 3 Security
- deleted 6y ago[deleted]
- dataflow 6y ago> there is no malicious piece of hardware that the attacker tricks you into using > All the attacker needs is 5 minutes alone with the computer, a screwdriver, and some easily portable hardware. Just started reading, but the comparison is already a little bizarre. It almost seems like the digital version of "This murderer is on the loose and you're in danger! He doesn't need to inject poison into your food. All he needs is just 5 minutes in front of you with a knife!"
- DiabloD3 6y agoI think that was the point.
- mehrdadn 6y agoThen I guess the comparison didn't help, but what I'm trying to say is, hidden threats are harder to protect against, not easier. Telling me I need to watch out for a threat because it's visible doesn't make any sense. You tell people to be more on alert for hidden threats, not for obvious ones.
- ashtonkem 6y agoAs a general rule, anyone with physical access to your machine already owns it. Physical security matters, a lot. That being said, malicious hardware is a problem. A hacked phone charging terminal at the airport could certainly be a serious problem if there are enough vulnerabilities in the USB stack.
- nneonneo 6y agoPlease tell this to the Intel SGX folks. They don’t seem to have gotten that memo yet...
- mjg59 6y ago> As a general rule, anyone with physical access to your machine already owns it. People frequently say this, but never really explain it. As far as I can tell, it translates to "Nobody cares about physical security" - except it's clear that people /do/. Things like Boot Guard are only really relevant to physical attacks. DMA protection in firmware is only really relevant to physical attacks. It's extremely obvious that the industry is attempting to avoid short term physical access to a device being sufficient to compromise it, and research that demonstrates that it's still possible is valuable.
- zinodaur 6y agoAn example: Macbook chargers these days have charge ports that are also used for USB devices. This means that if a user plugs in a compromised "charger", it can set its own HID type (and pretend it is a keyboard or a mouse), open a terminal and start typing malware into the computer. All of this is a bit silly though, because physical intervention implies a level of commitment that lends itself to more reliable approaches: https://xkcd.com/538/ https://xkcd.com/538/
- mjg59 6y agoAnd a thing you can do for machines that have built-in keyboards is refuse to enable new HID devices until the user provides affirmative consent. The people who have reason to care about these attacks have defenses, and research that demonstrates those defenses are incomplete is useful research.
- zinodaur 6y agoYeah thats a good point - I personally have the bad habit of clicking "yes" to that dialogue whenever I see it, since it does sometimes spuriously appear. I certainly wouldn't attempt a teardown of all of the equipment currently plugged into my machine when I saw a message like that. Do you know if HIDs can impersonate other HIDs? E.g., if you attached a dongle to a usb keyboard, could that dongle claim the identity of the keyboard and thereby avoid the prompt? My favorite "security interface failure" is the fact that OSX apps frequently demand a user login and password in a popup window. E.g., Slack does this. It would be so easy for an app render this popup (even on a webpage!) and I would totally type my password into it. I feel like the only answer to this is to have a sacred corner of the screen that only the OS is allowed to write to
- kichik 6y agoIf all it takes is a malicious Thunderbolt device, why is a screwdriver needed?
- tptacek 6y agoBecause they need to open up the victim's device to read its TB3 configuration directly off the SPI flash that holds it; that's how they get the malicious device to work in the first place.
- boxed 6y agoThat seems a bit counter to "Thunderspy is stealth, meaning that you cannot find any traces of the attack". No traces on the computer sure, but breaking apart my screen might be possible to see.
- withinboredom 6y agoUnless they opened it before you even receive the device.
- redactions 6y agoMany smaller devices do not require tools and are trivial to clone. Any of the victim devices will do. It's not only useful to attack a target computer. Device identifiers and capabilities are not bound to the security level secret values. Drop off a pre-cloned video adapter in a conference room. If it is used and as a result authorized by a targeted computer at a later moment in time, it's game over. An attacker may now perform DMA operations unless the system has kDMA protection enabled. This requires kDMA support in the BIOS, IOMMU hardware, and in the Operating System. The focus on DMA is however missing a very important observation about security levels from the research: There is a lot of attack surface when you're able to plug in a PCI(e) device as easily as a USB disk.
- tptacek 6y agoYou almost certainly know more about this than me, but hasn't macOS been breaking this attack --- malicious PCIE DMA --- for several years now with its IOMMU configuration? Ivan Krstic has a whole series of BH slides about this, and in the context of T2. The point about attacking trusted devices and pre-cloning devices is well taken.
- lidHanteyk 6y agoWhat they're trying to get across is that this is not a Bad USB [0] attack, but an Evil Maid [1] attack. In either case, the attacker does not need to rush. To commit a Bad USB attack, the attacker deputizes you and uses your confusion [2] to get you to insert a dangerous peripheral device, on your own time. In an Evil Maid attack, the attacker patiently waits until you trust (read as: "are vulnerable to") their physical presence, and then inserts a dangerous peripheral device. To use your analogy, in the former case, the murderer poisoned your food at the grocer's, and you unwittingly dose yourself when you make your meal. In the latter case, the murderer spends time getting to know you and letting you trust them, and then one day, when you go to the bathroom, they come in and shoot you like Vincent Vega. [0] https://en.wikipedia.org/wiki/USB_flash_drive#BadUSB https://en.wikipedia.org/wiki/USB_flash_drive#BadUSB [1] https://en.wikipedia.org/wiki/Evil_maid_attack https://en.wikipedia.org/wiki/Evil_maid_attack [2] http://www.cap-lore.com/CapTheory/ConfusedDeputy.html http://www.cap-lore.com/CapTheory/ConfusedDeputy.html
- justaguyonline 6y agoWhat would it take to have a Thunderbolt/USB C condom? You know, like those standard USB adapter that just drops the data leads on a usb charger to make attacks like this impossible. Maybe we would have to implement a hardware switch on the device itself? I'm not going to feel safe charging with a public use charger until I find some way to insure only power and not data is making it to my device. Even POE feels like it's safer than modern peripheral standards right now. (I admit this might not be perfectly linked to the article, it's just a need I've felt for a while but I can't seem to buy a solution for.)
- ashtonkem 6y agoI just bring my own brick for such circumstances. It takes no effort for me to evaluate the security, and it’s more flexible than counting on built in USB ports.
- nine_k 6y agoBut buses, trains, planes — they all offer a USB socket, not a power socket.
- banana_giraffe 6y agoI've long since taken to carrying a USB battery that can charge and provide power at the same time. It's more reliable for me than USB condoms, and, well, it's a battery, which is useful too.
- ashtonkem 6y agoThat’s not been my experience, but I’m sure it’s hyper location/company specific. As another commenter mentioned, I too carry a battery for longer trips, which is useful for charging devices when physically on the move and away from outlets. The model I chose from Anker can also top up a MBP, albeit slowly.
- dannyw 6y agoHow about a SSH-like “trust on first use” prompt for all data connections? Each USB/TB device has its own pub/private keypair. If you ever plug in a charging cable and get the prompt, you know something is wrong.
- person_of_color 6y agoReally though, if an attacker has unencumbered access to one’s device, all security goes flying out the window. The website is highly self-promoting.
- jonhohle 6y agoAs another commenter pointed out, public charging or borrowed chargers are an issue. Think airport charging kiosks/counters. Maybe power over data connectors isn’t the best idea (I enjoy single cable docking, but an extra, magnetic power cable wasn’t that much more work).
- tptacek 6y agoBorrowed chargers aren't the threat model here; these attacks involve an attacker opening up your machine and reading the contents of the TB3 controller's SPI flash.
- deleted 6y ago[deleted]
- redactions 6y agoThat isn't entirely accurate. The ability to clone a given device state gives access to any system which has authorized that cloned device. A borrowed thunderbolt device which is not the target machine may also be used to bypass security levels as a result. No need to open the laptop in that case. See section 3.1.1 and 3.1.3 in the report.
- mappu 6y ago> if an attacker has unencumbered access to one’s device, all security goes flying out the window This is rapidly starting to become less true - full disk encryption is everywhere, backed by hardware TPMs; the Lockdown LSM prevents root from owing the boot chain; devices with soldered RAM are functionally immune to cold boot attacks. There are still things an attacker can do - put a hardware keylogger on the keyboard wires, a skimmer on the fingerprint reader - but that requires future input from the victim. It is feasible today to defend against a physical attacker if you have the right hardware upfront and don't use it after the attack.
- vvanders 6y agoLooks like most of these require physical access to the SPI flash and not just the thunderbolt port unless I'm reading the disclosure wrong.
- tptacek 6y agoI skimmed the paper and while the research looks solid, just in terms of the digging they did and the documentation they're providing, this website really buries its lede: if you've got a Macbook running macOS, the Macbook IOMMU breaks the DMA attack, which is the thing you're actually worried about here. Additionally, regardless of the OS you run, Macbooks aren't affected by the Security Level/SPI flash hacks they came up with to disable Thunderbolt security.
- AceJohnny2 6y agoLast time Tunderbolt was broken (Thunderclap [1]), it was found that the Linux driver didn't activate the IOMMU. I assume that's since been fixed. [1] https://lwn.net/Articles/782381/ https://lwn.net/Articles/782381/
- ogre_codes 6y agoYes, buries the lede indeed. "THUNDERBOLT IS HOPELESSLY INSECURE AND BROKEN!!" blah blah blah blah * except on 90% of computers shipping with Thunderbolt. Windows PC makers were much later to TB3 and even now only ship it on a small percentage of their computers. I'm not even sure there is a Linux out of the box system with TB3 support.
- oefnak 6y agoDell XPS 15 can ship with Linux.
- zerof1l 6y agoThere were news sometime ago that Microsoft did not include thunderbolt in their surface 3 because it was insecure. I wonder if that's related to this and whether Microsoft knew about this for a while.
- osy 6y agoThis is the kind of garbage that the infosec community often memes about. A marketing website, a domain name, a cute logo for a vanity project masquerading as security research. Basically every one of the "seven" vulnerabilities boils down to "if someone can flash the SPI of the thunderbolt controller then xxx" but if they can flash the TB SPI, then they can also flash the BIOS SPI which has a lot of the same "vulnerabilities" but arguably is more impactful. The reason they only mentioned TB is because the BIOS stuff is well known and you can't put your name on it. Let's break down each of the "vulnerability". 1. "However, we have found authenticity is not verified at boot time, upon connecting the device, or at any later point." This is actually false. Like, the author either didn't experiment properly or is lying/purposely misleading you. The firmware IS verified at boot for Alpine Ridge and Titan Ridge (Intel's TB3 controllers). They aren't for older controllers which does NOT support TB3. When verification fails, the controller falls back into a "safe mode" which does NOT run the firmware code for any of the ARC processors in the Ridge controller (there are a handful of processors where the firmware contains compressed code for). I'm willing to bet the author did not manage to reverse engineer the proprietary Huffman compression the firmware uses and therefore couldn't have loaded their own firmware. Because if they did, it wouldn't have worked. Now the RSA signature verification scheme they use to verify the firmware does suffer from some weaknesses but afaik doesn't lead to arbitrary code execution (on any of the Ridge ARC processors). I would love to be proven wrong here with real evidence though ;) 2. Basically the string identifiers inside the firmware isn't signed/verified. This has no security implications beyond you can spoof identifiers and make the string "pwned" appear in system details when you plug the device in and authenticate it. Basically if you've ever developed custom USB devices you can see how silly this is as a "vulnerability." 3. This is literally the same as #2. 4. Yes, TB2 is vulnerable to many DMA attacks as demonstrated in the past. Yes, TB3 has a TB2 compatibility mode. Yes, that means the same vulnerabilities exist in compatibility mode which is why you can disable it. 5. This one is technically true. If you open the case up, and flash the SPI chip containing the TB3 firmware, you can patch the security level set in BIOS and do stuff like re-enable TB2 if the user disabled it. But if I were the attacker, I would instead look at the SPI chip right next to it containing the UEFI firmware and NVRAM variables (most of which aren't signed/encryption in any modern PC). 6. SPI chips have interfaces for writing, erasing, and locking. If you have direct access to the chip you can abuse these pins to permanently brick the device. Here's another way: take your screwdriver and jam it into the computer. 7. Apple does not enable TB3 security features on Boot Camp. I guess this one is vaguely the only real "vulnerability" although it's well known and Apple doesn't care much about Windows security anyways (they don't enable Intel Boot Guard or BIOS Guard or TPM or any other Intel/Microsoft security feature). Not that it matters but my personal experience with TB3 is that I've done significant reverse engineering of the Ridge controllers for the Hackintosh community.
- dafrankenstein2 6y agoThis video shows the POC demo: https://www.youtube.com/watch?v=7uvSZA1F9os https://www.youtube.com/watch?v=7uvSZA1F9os
- dafrankenstein2 6y agoEasy read on the Wired magazine: https://www.wired.com/story/thunderspy-thunderbolt-evil-maid-hacking/ https://www.wired.com/story/thunderspy-thunderbolt-evil-maid...
- graton 6y agoI wonder if that could be used by used sellers of MacBooks to get into the computers. https://www.vice.com/en_us/article/akw558/apples-t2-security-chip-has-created-a-nightmare-for-macbook-refurbishers https://www.vice.com/en_us/article/akw558/apples-t2-security... I guess MacBook resellers sometimes get computers where the password has been set and they can't get into the computers. I imagine they would be motivated to find anyway they can to unlock the computers.
- mschuster91 6y ago> Contrary to USB, Thunderbolt is a proprietary connectivity standard. Device vendors are required to apply for Intel’s Thunderbolt developer program, in order to obtain access to protocol specifications and the Thunderbolt hardware supply chain. In addition, devices are subject to certification procedures before being admitted to the Thunderbolt ecosystem. I thought that this had changed with USB-C?!
- oicat 6y agoThere is a nice write-up about this on attackerkb. If you're not familiar with it it's a community to provide assessments of vulnerabilities and point out which are worth stopping everything to patch and which are mostly harmless. It's currently in open beta. Main site: https://attackerkb.com/ https://attackerkb.com/ Thunderspy assessment: https://attackerkb.com/topics/mPaHZgsUvk/thunderspy https://attackerkb.com/topics/mPaHZgsUvk/thunderspy