Security concerns over new Thunderbolt I/O technology
h-online.com
h-online.com
http://www.mactech.com/articles/mactech/Vol.21/21.02/Securit...
(halfway down, "Disabling Fiewire Direct Memory Access", EFI passwords on x86 do the same as OF passwords on PPC machines)
A real solution would be some sort of DMA whitelist provided by the OS driver.
1) As much time as you need, within reason. 2) Privacy complete the attack.
Physical access should not mean getting close with a wire, it should mean opening the case and messing with the internals.
Your personal preferences are irrelevant to a concept that has been proven over centuries. Physical access is physical access, and I can get root while sitting at most unix-like OSes (including yours) without touching a nutdriver.
I think what would be an even better scenario is that, since Thunderbolt devices are meant to be daisy-chained and have 2 ports for that purpose, a 'standard' thunderbolt projector could have a homebrew device chained to it, that the presenter knows nothing of. (Hidden, explained as something else, etc). Then this standard-made projector can be made to be a malicious one simply by daisychaining another device on to it that could copy the contents of the presenter's hard drive.
Wouldn't true security professionals understand that once you grant physical access to the machine, that all is lost?