>Your assumption is incorrect. Even for devices that are designed with the express purpose of being hard to emulate (auth tokens, DRM chips, iPhone cables), it’s at most a simple matter of a grad student or Shenzhen resident with access to a fume hood and an electron microscope finding some burned-in private keys. For devices that aren’t designed to resist emulation, which thunderbolt devices generally aren’t, it’s trivial. This is essentially one of the core messages you should take away from the field of hardware security.
Every source that I can find regarding the 2016 DMA vulnerabilities disagrees with you. Most of them actually specifically require that Thunderbolt security features be turned off because otherwise signed drivers are required to be installed before the peripheral will even connect.
>They all do. Intel calls it VT-d.
Got a source for VT-d being supported on MacBooks? I've been looking pretty hard to find a definitive answer, but all I can find are random unverified forum posts, stackoverflow questions, blackhat presentations, etc, and all of them say that VT-d and IOMMU are not supported/enabled on recent MacBooks and MB Pros.
edit: I finally came across the below link from Apple which does seem to imply that IOMMU VT-d is enabled on Macs that are 2012 and newer. On anything before that, though, and DMA attacks could own you. So uh.. don't run macbooks that are 6 years old, I guess.
https://developer.apple.com/library/content/documentation/Ha...