Apple firmware updates are leaving Macs vulnerable

Would love to see what details exactly they think can be accessed via UEFI anyway, never mind the physical access part of that security.
 
Would love to see what details exactly they think can be accessed via UEFI anyway, never mind the physical access part of that security.

You could easily exploit the efi with malware, that is if it’s vulnerable. No need for physical access.

AFAIK Sierra scans your efi once a week for code changes. That said, I guarantee you that a lot more windows laptops and even normal desktops are affected, something Duo can’t really test. Apple was an easy target here due to the hardware being identical.
 
The article should read - people not updating their software leaves mac's vulnerable.
Even so, less than concerned.

Not really. Efi should update with your OS updates. Can’t expect average joe to update the efi manually. 99% won’t know what the hell that even is.
 
Everything, trust me.

Not really.

Trust me.

If the HDD is FileVaulted EFI still won't let you in.

If it's referring to target drive as a vulnerability that's a design feature.

Either way all of the above requires physical access.
 
You could easily exploit the efi with malware, that is if it’s vulnerable. No need for physical access.

Malware via the OS. So if the OS is secure the EFI is secure.

So we are back to physical access again. In which case pretty much all machines in their default configuration are vulnerable.

But this is exactly why I would like to see some details. Until then it's all just bull****.
 
The article should read - people not updating their software leaves mac's vulnerable.
Even so, less than concerned.

Not at all.

The article is all about the software updates not doing anything with UEFI and in fact rolling it back to older less secure version.

So doesn't matter how updated it is.
 
Malware via the OS. So if the OS is secure the EFI is secure.

So we are back to physical access again. In which case pretty much all machines in their default configuration are vulnerable.

But this is exactly why I would like to see some details. Until then it's all just bull****.

The OS can be as secure as Fort Knox. The user operating the OS on the other hand can click here or there and catch malware. Granted, it’s more difficult on OS X but malware for OS X is real.

https://blog.malwarebytes.com/malwarebytes-news/2017/08/solution-corner-malwarebytes-mac/
 
The OS can be as secure as Fort Knox. The user operating the OS on the other hand can click here or there and catch malware. Granted, it’s more difficult on OS X but malware for OS X is real.

https://blog.malwarebytes.com/malwarebytes-news/2017/08/solution-corner-malwarebytes-mac/

Yeah for sure.

Always the case of "don't be a retard".

But it's also why the root account is disabled by default on OSX. But I guess the same idiot user could compromise that too.
 
Top
Sign up to the MyBroadband newsletter
X