Apple's Core Is Secure

Researchers now say they used a third-party drive to facilitate infamous MacBook hack at Black Hat

Dan Jones, Mobile Editor

August 18, 2006

2 Min Read
Dark Reading logo in a gray background | Dark Reading

After all the kerfuffle over Apple Inc. (Nasdaq: AAPL)'s device driver security, precipitated by a demo of a MacBook hack at the recent Black Hat Inc. security conference, it turns out that the researchers weren't using Apple software but exploiting a weakness in a third-party driver.

At the show, SecureWorks Inc. researchers Jon Ellch and David Maynor showed a video demo of a hack using wireless drivers to quickly access a MacBook computer. The two researchers demonstrated how the drivers could be used to establish a connection and seize control of a laptop, even if the laptop was not associated with any WiFi access point. (See Users Eye New 802.11 Security Issues .)

When the hack was unveiled, Maynor told The Washington Post that they showed it on an Apple because of the "Mac user base aura of smugness on security." The researchers, however, have now put a notice on their Website to clarify that the hack used a third-party USB driver, which they are not naming until a patch is available.

"The video presentation at Black Hat demonstrates vulnerabilities found in wireless device drivers. Although an Apple MacBook was used as the demo platform, it was exploited through a third-party wireless device driver -- not the original wireless device driver that ships with the MacBook."

The researcher's admission, however, is unlikely to calm the frazzled nerves of enterprise users fretting about 802.11 security. Some higher-ups have already said that they will advise users to ensure that, until fixes are found, their WiFi radios are switched off when not in use. The hack also works against Windows machines. Intel Corp. (Nasdaq: INTC) has issued some patches but said that users should contact their laptop manufacturers for brand-specific updates. (See Intel's Centrino Vulnerability.)

— Dan Jones, Site Editor, Unstrung

About the Author

Dan Jones

Mobile Editor

Dan is to hats what Will.I.Am is to ridiculous eyewear. Fedora, trilby, tam-o-shanter -- all have graced the Jones pate during his career as the go-to purveyor of mobile essentials.

But hey, Dan is so much more than 4G maps and state-of-the-art headgear. Before joining the Light Reading team in 2002 he was an award-winning cult hit on Broadway (with four 'Toni' awards, two 'Emma' gongs and a 'Brian' to his name) with his one-man show, "Dan Sings the Show Tunes."

His perfectly crafted blogs, falling under the "Jonestown" banner, have been compared to the works of Chekhov. But only by Dan.

He lives in Brooklyn with cats.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights