{"id":204532,"date":"2022-08-26T15:29:00","date_gmt":"2022-08-26T12:29:00","guid":{"rendered":"https:\/\/howto.com.de\/?p=204532"},"modified":"2022-08-26T15:29:12","modified_gmt":"2022-08-26T12:29:12","slug":"thunderbolti-viga-annab-haekkeritele-juurdepaeaesu-teie-andmetele","status":"publish","type":"post","link":"https:\/\/howto.com.de\/et\/thunderbolti-viga-annab-haekkeritele-juurdepaeaesu-teie-andmetele\/","title":{"rendered":"Thunderbolti viga annab h\u00e4kkeritele juurdep\u00e4\u00e4su teie andmetele"},"content":{"rendered":"\n<p><a href=\"https:\/\/www.shutterstock.com\/image-photo\/bangkok-dec-2019-bunch-cable-plugged-1595757916\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">KenSoftTH\/Shutterstock<\/a><\/p>\n<p>Hiljuti postitas \u00fcks teadlane <a href=\"https:\/\/thunderspy.io\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">kontseptsiooni t\u00f5endi,<\/a> mis n\u00e4itas, et ta p\u00e4\u00e4ses lukustatud s\u00fclearvuti sisule juurde vaid m\u00f5ne minutiga. Vea tuum p\u00e4rineb Thunderboltilt. Kuid kuigi ta sai s\u00fclearvuti juurde, vajas ta f\u00fc\u00fcsilist juurdep\u00e4\u00e4su, kruvikeerajat ja valmisosi.<\/p>\n<hr \/>\n<p><strong>V\u00e4rskendatud, 5\/11:<\/strong> Intel \u00fctleb, et see r\u00fcnnak ei t\u00f6\u00f6ta arvutites, kus Kernali DMA kaitse on lubatud. Inteli pressiesindaja \u00fctleb meile: &quot;Seda r\u00fcnnakut ei \u00f5nnestunud edukalt demonstreerida s\u00fcsteemides, kus Kerneli DMA kaitse on lubatud. Nagu alati, julgustame k\u00f5iki j\u00e4rgima h\u00e4id turvatavasid, sealhulgas takistama volitamata f\u00fc\u00fcsilist juurdep\u00e4\u00e4su arvutitele.&quot; Ettev\u00f5te postitas uuringule vastuse ka <a href=\"https:\/\/redirect.viglink.com\/?key=204a528a336ede4177fff0d84a044482&u=https%3A%2F%2Fblogs.intel.com%2Ftechnology%2F2020%2F05%2Fmore-information-on-thunderspy%2F%23gs.5rsrl2\" target=\"_blank\" rel=\"noopener\">ajaveebi postituses<\/a>.<\/p>\n<hr \/>\n<p>Thunderspyks nimetatud r\u00fcnnak kasutab \u00e4ra asjaolu, et Thunderbolt on otsese m\u00e4lup\u00e4\u00e4su port. Sarnaselt PCI-Expressile ja Firewire'ile p\u00e4\u00e4sevad Thunderbolti pordid s\u00fcsteemim\u00e4lule otse v\u00e4ljaspool CPU-d, mis v\u00f5imaldab suurt edastuskiirust. Kuid see teeb nad ka otseste m\u00e4lur\u00fcnnakute suhtes haavatavaks.<\/p>\n<div class=\"sds-iframe-wrapper fitvidsignore\" style=\"position:relative;padding-top:56.25%;max-width:100%;\"><iframe allowfullscreen style=\"position:absolute;top:0;left:0;width:100%;height:100%;\" src=\"\/\/www.youtube.com\/embed\/7uvSZA1F9os\" frameborder=\"0\"><\/iframe><\/div>\n<p>Nagu turbeuurija Bj\u00f6rn Ruytenbergi demonstratsioonivideost n\u00e4ha, p\u00e4\u00e4seb h\u00e4kker, kasutades \u00e4ra Thunderbolti juurdep\u00e4\u00e4su s\u00fcsteemim\u00e4lule, teie andmetele isegi siis, kui s\u00fclearvuti on lukus ja k\u00f5vaketas on kr\u00fcptitud.<\/p>\n<p>R\u00fcnnak pole aga lihtne, h\u00e4kker peab olema h\u00e4sti ette valmistatud ja vajama juurdep\u00e4\u00e4su teie s\u00fclearvutile. H\u00e4kkimine h\u00f5lmab s\u00fclearvuti tagaplaadi (p\u00f5hja) eemaldamist ja seadme \u00fchendamist emaplaadiga p\u00fcsivara \u00fcmberprogrammeerimiseks.<\/p>\n<p>Kuigi Ruytenberg v\u00e4idab, et see on protsess, mida ta saab teha minutitega, eeldab see s\u00fclearvuti tundmist ja seda, mida on vaja tagaplaadi eemaldamiseks (kui see on \u00fcldse v\u00f5imalik). On ebat\u00f5en\u00e4oline, et teie j\u00e4relevalveta s\u00fclearvuti langeks selle Starbucksi r\u00fcnnaku ohvriks, kuid teie varastatud s\u00fclearvutiga on hoopis teine \u200b\u200blugu.<\/p>\n<p>Ruytenbergi s\u00f5nul ei ole viga tarkvaraprobleem ja seda ei saa parandada. Selle asemel on vajalik kiibi \u00fcmberkujundamine. N\u00e4ib, et teised teadlased pole v\u00e4hemalt osaliselt n\u00f5us ja v\u00e4idavad, et Windows 10 uus <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/information-protection\/kernel-dma-protection-for-thunderbolt\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">kernelitaseme kaitse<\/a> peaks probleemi v\u00e4hemalt osaliselt leevendama. Ja kui kasutate macOS-i, olete ka osaliselt kaitstud.<\/p>\n<p>Rutenberg j\u00e4tkas, et m\u00f5ni muu r\u00fcnnaku vektor v\u00f5ib seadme osalise lahtiv\u00f5tmise vajadusest m\u00f6\u00f6da minna. Kuid sel juhul vajaks h\u00e4kker juurdep\u00e4\u00e4su \u00e4ikeseseadmele, mis on varem s\u00fclearvutiga \u00fchendatud.<\/p>\n<p>Tasub mainida, et Thunderbolti v\u00f5imalikud turvaaukud on \u00fcks p\u00f5hjus, miks Microsoft <a href=\"https:\/\/howto.com.de\/et\/microsoft-surfacei-seadmed-jaetke-turvalisuse-huvides-thunderbolti-pordid-vahele\/\" title=\"ei lisa Surface&#039;i seadmete porti\">ei lisa Surface'i seadmete porti<\/a>. Kui olete praegu mures, kas see viga teie seadet m\u00f5jutab, saate seda kontrollida Ruytenbergi loodud <a href=\"https:\/\/thunderspy.io\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">ThunderSpy veebisaidil .<\/a><\/p>\n<p>Allikas: <a href=\"https:\/\/thunderspy.io\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">ThunderSpy<\/a> <a href=\"https:\/\/www.wired.com\/story\/thunderspy-thunderbolt-evil-maid-hacking\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Wiredi<\/a> kaudu<a href=\"https:\/\/www.wired.com\/story\/thunderspy-thunderbolt-evil-maid-hacking\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external\"><\/a><\/p>\n<p><div id=\"PostUnique_PostSource\" style=\"padding-top: 50px\">:  <a target=\"_blank\" rel=\"noopener nofollow\" href=\"\/\/www.reviewgeek.com\" class=\"external external_icon\">www.reviewgeek.com<\/a><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hiljuti postitas \u00fcks teadlane kontseptsiooni t\u00f5endi, mis n\u00e4itas, et ta p\u00e4\u00e4ses lukustatud s\u00fclearvuti sisule juurde vaid m\u00f5ne minutiga. Vea tuum p\u00e4rineb Thunderboltilt. Kuid kuigi ta sai s\u00fclearvuti juurde, vajas ta f\u00fc\u00fcsilist juurdep\u00e4\u00e4su, kruvikeerajat ja valmisosi.<\/p>\n","protected":false},"author":1,"featured_media":172199,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wp_rev_ctl_limit":""},"categories":[],"tags":[],"class_list":["post-204532","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/howto.com.de\/et\/wp-json\/wp\/v2\/posts\/204532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/howto.com.de\/et\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/howto.com.de\/et\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/howto.com.de\/et\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/howto.com.de\/et\/wp-json\/wp\/v2\/comments?post=204532"}],"version-history":[{"count":0,"href":"https:\/\/howto.com.de\/et\/wp-json\/wp\/v2\/posts\/204532\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/howto.com.de\/et\/wp-json\/wp\/v2\/media\/172199"}],"wp:attachment":[{"href":"https:\/\/howto.com.de\/et\/wp-json\/wp\/v2\/media?parent=204532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/howto.com.de\/et\/wp-json\/wp\/v2\/categories?post=204532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/howto.com.de\/et\/wp-json\/wp\/v2\/tags?post=204532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}