The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Macbook Battery Hacked?

    Discussion in 'Apple and Mac OS X' started by di1in, Jul 26, 2011.

  1. di1in

    di1in Notebook Consultant

    Reputations:
    0
    Messages:
    121
    Likes Received:
    0
    Trophy Points:
    30
    How on earth did this guy hack a macbook battery? I though hacking from far was limited to software; hardware hacking is actually getting down and dirty with the pcb right?

    Update: the news is out on physorg.com as well
     
  2. preview

    preview Notebook Evangelist

    Reputations:
    141
    Messages:
    350
    Likes Received:
    2
    Trophy Points:
    31
    The battery has firmware (software) that controls it. Many modern (all?) laptop batteries come with firmware as I understand it.

    Apple just botched the security by using a default password for the write mechanism.
     
  3. di1in

    di1in Notebook Consultant

    Reputations:
    0
    Messages:
    121
    Likes Received:
    0
    Trophy Points:
    30
    Thanks @preview

    Is there a way to close this hole?
     
  4. preview

    preview Notebook Evangelist

    Reputations:
    141
    Messages:
    350
    Likes Received:
    2
    Trophy Points:
    31
    The security researcher who found it claims that he'll release a tool soon, but as far as I know there's been no official word from Apple. They are their usual uncommunicative selves and could really learn a thing or two from Microsoft's security department.

    I wouldn't sweat it though as this isn't that big a deal. I don't think there's any malware out there at the moment taking advantage of this hole and even if there were it would still require root access. It can't be exploited without user interaction.

    The old security best practice still holds; don't run strange applications and don't enter your password if you're randomly prompted for it and you should be fine.
     
  5. di1in

    di1in Notebook Consultant

    Reputations:
    0
    Messages:
    121
    Likes Received:
    0
    Trophy Points:
    30
    @preview Thanks mate