"Thunderstrike" is the name for an attack that can target Mac hardware via the Thunderbolt port. Apple had previously updated the Retina 5K iMac and 2014 Mac mini to partially secure them against Thunderstrike. Now, the upcoming OS X Yosemite 10.10.2 will fix the problem for all recent Macs running Yosemite.
Rick Mogull previously explained how Thunderstrike works on TidBITS:
Macs, like all computers, have firmware that swings into action when you push the power button, booting up the computer, loading the operating system, initializing hardware, and performing other functions. Some technologies, such as FireWire and Thunderbolt, interact with this firmware at an extremely low level, below Mac OS X itself, for feature and performance reasons.
The Thunderstrike proof-of-concept takes advantage of this trust to replace the contents of the Mac's boot ROM with the attacker's own code, effectively embedding it into the Mac's hardware and making it impossible to remove using standard techniques. The attack works because Apple relies on software checks to confirm the firmware is valid, and Hudson developed techniques to circumvent those checks (and even replace the encryption key).
To secure against Thunderstrike, Apple had to change the code to not only prevent the Mac's boot ROM from being replaced, but also to prevent it from being rolled back to a state where the attack would be possible again. According to people with access to the latest beta of OS X 10.10.2 who are familiar with Thunderstrike and how it works, that's exactly the deep, layered process that's been completed.
OS X 10.10.2, which was last seeded to developers earlier this week and will be made available to everyone as soon as it goes into wide release. OS X 10.10.2 also fixes three recently disclosed Project Zero vulnerabilities.
In the meantime, no instances of Thunderstrike have been found in wild, and the attack requires either physical access to the targeted computer, or social engineering sufficient to trick the owner into "attacking" themselves.
So, as with other recent Apple-related security stories, be informed but don't be alarmed. It's known, it's not likely to affect anyone reading this, and the fix is on its way.
We may earn a commission for purchases using our links. Learn more.
Apple releases iPadOS 13.5.1
Apple has released iPadOS 13.5.1, which fixes some security bugs.
Apple might be giving people a reason to upgrade their 2012 MacBook Pro
Anyone who still uses a 2012 MacBook Pro should probably look to upgrade it sooner rather than later following a report that claims Apple will label it "obsolete" this month.
New report backs up claims that we'll wait until October for iPhone 12
Apple would normally announce its new iPhones in September, but the coronavirus situation seems to have put paid to that. All eyes are now on October instead.
Turn your sound up to 11 with these fantastic speakers for your Mac
You wouldn't believe the difference a great set of speakers can make. Regardless of your listening pleasure, you'll notice that difference immediately. Here we've compiled a list of the best computer speakers for your Mac.