Skip to main content

Security flaw on modern PCs could leave your encrypted data exposed

MacBook Pro 15
Malarie Gokey/Digital Trends

A vulnerability on most modern PCs and Macs could leave your data exposed. Cybersecurity researchers at F-Secure discovered a weakness in the firmware of most modern computers could allow hackers access to encryption keys and other sensitive data.

Access to sensitive data is gained through a 2008-style cold boot attack, where the hacker forces a computer to restart without going through the normal shutdown process. The computer’s data is briefly accessible in the RAM after power is lost, but many modern devices overwrite the RAM to prevent unauthorized access to data during this type of attack. Researchers discovered that there is a way to disable the overwrite process, essentially reviving the decade-old method of attack.

Recommended Videos

“The attack exploits the fact that the firmware settings governing the behavior of the boot process are not protected against manipulation by a physical attacker,” F-Secure wrote in a blog post. “Using a simple hardware tool, an attacker can rewrite the non-volatile memory chip that contains these settings, disable memory overwriting, and enable booting from external devices. The cold boot attack can then be carried out by booting a special program off a USB stick.”

Please enable Javascript to view this content

Despite the seriousness of the findings, the vulnerability may not be as damaging given that to carry out this exploit, hackers would need physical access to your device. If a hacker has physical access, the exploit can be conducted in approximately five minutes, researchers cautioned.

F-Secure shared its findings with Microsoft, Apple, and Intel, but given that physical device access is required for this type of attack, it doesn’t appear that a fix may be coming soon. Newer Mac systems with a T2 chip aren’t affected by this attack, and Microsoft claims that enabling pre-boot authentication with a PIN or startup key with BitLocker could help mitigate these risks. These more advanced security tactics, however, aren’t available to general consumers who run Windows 10 Home edition.

“Unfortunately, there is nothing Microsoft can do, since we are using flaws in PC hardware vendors’ firmware,” F-Secure principal security consultant Olle Segerdahl told TechCrunch. “Intel can only do so much, their position in the ecosystem is providing a reference platform for the vendors to extend and build their new models on.”

Chuong Nguyen
Silicon Valley-based technology reporter and Giants baseball fan who splits his time between Northern California and Southern…
The best data recovery software for your Mac or MacBook
A rose gold MacBook Air has Disk Utility open with a red warning symbol and an external drive connected.

Apple designed your computer to be reliable and user-friendly, but even the best and newest MacBook hardware can experience glitches. When something goes wrong with your storage, data recovery software can help you restore missing and damaged files.

Another reason for data loss is the sort of embarrassing mistake that happens sometimes. If you've ever accidentally thrown away a file you needed on macOS, then emptied the trash, it's possible to get that file back with a data recovery app.
Time Machine
Best built-in solution

Read more
Your PC’s security is being attacked on two new fronts
Person using Windows 11 laptop on their lap by the window.

Your PC is facing a double whammy of cyber threats, both of them built into basic Windows features -- one that exploits Windows search and another a Wi-Fi vulnerability.

The first vulnerability allows hackers to exploit search in what researchers have called a "clever" way, as reported by Trustwave. It begins when users are tricked into downloading malware, starting with phishing emails with malicious .ZIP attachments containing HTML files disguised as invoices or something along those lines.

Read more
Qualcomm just made some bold claims about gaming on ARM PCs
A laptop and a camera on a table with a Qualcomm logo on the screen.

Qualcomm shared an exciting teaser during the 2024 Game Developers Conference (GDC), hinting that the PC gaming market might not be so limited to x86 architecture going forward. The company spoke during a session titled "Windows on Snapdragon, a Platform Ready for Your PC Games," and it claimed that Windows games will simply work on laptops equipped with the latest Snapdragon X Elite chip -- no extra prep required -- all thanks to emulation.

As reported by The Verge, Qualcomm's engineer Issam Khalil discussed how the company hopes to achieve realistic gaming on its ARM-based chip as early as May this year. Khalil explained the ins and outs of x86/64 emulation on Snapdragon X Elite, explaining that game devs will be able to port their titles to native ARM64 for the best performance, but they can also do "next to nothing" -- the game should just work anyway due to x64 emulation.

Read more