Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > News > Mac News > Researchers: 2008 iSights vulnerable to low-probability firmware mod

Researchers: 2008 iSights vulnerable to low-probability firmware mod
Thread Tools
MacNN Staff
Join Date: Jul 2012
Status: Offline
Reply With Quote
Dec 18, 2013, 07:31 PM
 
Recently published research by Johns Hopkins University has confirmed what the FBI reported earlier this month -- that it is possible for remote attackers who have installed a software patch on a user's computer to activate an iSight camera on some of Apple's older laptop and iMac computers without powering the LED signifying an active camera.

The 2008 editions of Apple hardware had a hardware interlock between the camera and the light in an attempt to make camera power-on impossible without owner awareness of the situation. Researchers Stephen Checkoway and Matthew Brocker discovered that the firmware of the camera can be updated to disable the feature.

The firmware update requires the user to authenticate the software with the administrative password. Given that an administrative user password is required, the user is at least partially complicit in the software modification, allowing the activation and making this assault somewhat less than stealthy (contrary to some more hysterical media reports). The odds of the modification being done without access to the owner's administrative account password are, to put it mildly, extremely remote.

The researchers claim that the vulnerability is confirmed to affect "Apple internal iSight webcams found in earlier-generation Apple products, including the iMac G5 and early Intel-based iMacs, MacBooks, and MacBook Pros until roughly 2008" and not newer devices. Other researchers believe that the method can be used on newer hardware from Apple and other vendors as well.
( Last edited by NewsPoster; Dec 19, 2013 at 03:42 AM. )
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -4. The time now is 08:36 PM.
All contents of these forums © 1995-2014 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2014, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2