Anyway, they've already fixed this vulnerability in my MacBook Air. I'm not worried.
Anyway, they've already fixed this vulnerability in my MacBook Air. I'm not worried.
http://www.hermann-uwe.de/blog/physical-memory-attacks-via-f...
From the post, the author says the battery could repeatedly install malware or spyware to your computer.
What would be more worrying is if someone found a way to hack directly to you battery. IE a virus you get installs itself to your battery as its resurrection method rather than in a system file. Worse yet would be if someone maliciously wrote a virus that caused your battery to overcharge a month down the road.
Imagine all those stupid MSN virus' if they could fry your laptop battery.
That's of course beyond the point that a great many other things you buy at a computer store could more easily contain malware.
Theoretically, malware could get onto a machine by whatever means, then use the battery as a nasty hiding place, or target the battery itself.
EDIT: It should be noted that a second vulnerability will be needed to get code from the battery into the machine.
>Using that password, Miller said that he has been able to do almost anything from giving false readings to the charger and the OS to ruin the device, to completely rewriting the firmware.
I don't know if it would be possible to make the battery burst into flame or explode. After the Sony battery fiasco, I'd expect there to be some kind of hardware interlock preventing short-circuits. However, it is possible to overwrite the battery firmware to prevent the battery from being charged, thus turning your Macbook Pro into a very small form-factor desktop.
Net result, changing battery firmware can reduce usefulness of battery (higher charging degrades cell life, blow fuses etc) but the packs should have hardware based protection from being a safety hazard
Now in fairness, being able to make something in my computer start a fire is on a way different level. But we're getting that from "Miller said that it might even be possible to overload the battery so that it catches fire"— he hasn't done it, and doesn't even know if it's possible. My money is on there are some lower-level safeguards to prevent bugs in the firmware from causing fires, even if they do ruin the battery. Li-ion batteries are designed physically with the knowledge that they're a ticking timebomb waiting to go off, and I can't believe that nobody at Apple has started from asking "But what if I were actually trying to make it explode."
observation: Turns out, the battery is secured with Y-cut-head screws, rather than the traditional Phillips screws of the hard drive.
So not only is the hard drive a more obvious target... it's considerably easier to get to in my opinion. (Unless people have Y-shaped screwdrivers lying around, who knows).
Regardless, I think it still speaks to the notion that the battery is harder to attack than the hard drive other than the more obvious reasons.