On Fri, 04 Aug 2006 09:46:34 -0700, Jeff Liebermann wrote in :
I suspect there's more going on here than meets the eye. A big problem in security is getting vendors to pay proper attention. My guess is that these guys got fed up with the lack of concern, and decided to build a fire under them with this public presentation. If so (or something like that), my own opinion is, "Bravo!"
I'm frankly sick and tired of vendors _knowingly_ shipping badly flawed products. It's the major reason I largely dropped out of beta testing
-- I have a long list of _major_ bugs I found as a beta tester that were left unfixed in released products (which I'm unable to disclose due to NDAs).
Follow-up to the Macbook Post
I'd like to respond to the people who commented on yesterday's post about the video's depiction of the use of a third-party wireless card on the Macbook. I spent more than an hour with Dave Maynor watching this exploit in action and peppering him with questions about it.
During the course of our interview, it came out that Apple had leaned on Maynor and Ellch pretty hard not to make this an issue about the Mac drivers -- mainly because Apple had not fixed the problem yet. Maynor acknowledged that he used a third-party wireless card in the demo so as not to draw attention to the flaw resident in Macbook drivers. But he also admitted that the same flaws were resident in the default Macbook wireless device drivers, and that those drivers were identically exploitable. And that is what I reported.
I stand by my own reporting, as according to Maynor and Ellch it remains a fact that the default Macbook drivers are indeed exploitable.
To all of the commenters who complained about why this demo was not shown live, I refer you back to the text of the blog post, which pointed out the dangers inherent in showing this type of exploit live to a room overflowing with curious hackers who would like nothing more than to capture a copy of the exploit wirelessly and experiment with it.
Again, the whole point of this story was not to pick on Macs, but to point to a security issue that affects multiple operating systems and one that is long overdue for some serious code review by the companies that OEMs rely upon to produce this software.
As always, thanks for all the comments. Keep them coming.
-- Brian Krebs
Probably because the MacBookPro has Airport functionality built into it.
I can think of a number of legitimate reasons. Why assume otherwise?
Panic is never a good idea. Nonetheless I'm now concerned about the Atheros wireless device in my own notebook computer, and even more for ones I've deployed for clients and friends, since that was reportedly the hardware used in the demo.
I've always turned off my own wireless when not needed, not only for security, but also for power saving and less annoyance. (I like how easy that is with a ThinkPad, one of the reasons I use and recommend them.) However, I really can't expect all my clients and friends to do so.
Until this is all sorted out, I've decided to:
- Monitor updates and security for clients and friends even move carefully than usual.
- Use Wireless Client Bridges instead of integrated wireless adapters as much as possible.