Slashdot Mirror


A $300 Device Can Steal Mac FileVault2 Passwords (bleepingcomputer.com)

An anonymous reader writes: Swedish hardware hacker Ulf Frisk has created a device that can extract Mac FileVault2 (Apple's disk encryption utility) passwords from a device's memory before macOS boots and anti-DMA protections kick in. The extracted passwords are in cleartext, and they also double as the macOS logon passwords. The attack requires physical access, but it takes less than 30 seconds to carry out. A special device is needed, which runs custom software (available on GitHub), and uses hardware parts that cost around $300. Apple fixed the attack in macOS 10.12.2. The device is similar to what Samy Kamker created with Poison Tap.

1 of 88 comments (clear)

  1. Re:Even worse by Ol+Olsoc · · Score: 5, Insightful

    Think of having an Apple device taken by the security services at an airport. The laptop is turned on behind a secure counter with an extra hidden device plugged in.

    Think of doing the system update.

    --
    The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.