Follow Us

MacBook Wi-Fi hack exposed

Demo didn't use Apple drivers.

A claimed security hole in Apple's MacBook has been exposed as a misrepresentation.

Earlier this month, a researcher at SecureWorks said he had revealed a vulnerability in the laptop's wireless software driver that would allow him to take control of the machine. There was a vulnerability but it was exploited by using a third-party wireless driver rather than the one that ships with the MacBook.

"Despite SecureWorks being quoted saying the Mac is threatened by the exploit demonstrated at Black Hat, they have provided no evidence that in fact it is," said an spokeswoman. "To the contrary, the SecureWorks demonstration used a third party USB 802.11 device - not the 802.11 hardware in the Mac - a device which uses a different chip and different software drivers than those on the Mac. Further, SecureWorks has not shared or demonstrated any code in relation to the Black Hat-demonstrated exploit that is relevant to the hardware and software that we ship."

SecureWorks researcher David Maynor and "Johnny Cache" demonstrated the vulnerability at the Black Hat conference using a MacBook. Maynor told the Washington Post at the time that they demoed the flaw on the Mac because of the "Mac user base aura of smugness on security".

SecureWorks' website has been updated since the demonstration to reflect that fact a third-party driver had been used in the demonstration:"Although an Apple MacBook was used as the demo platform, it was exploited through a third-party wireless device driver - not the original wireless device driver that ships with the MacBook. As part of a responsible disclosure policy, we are not disclosing the name of the third-party wireless device driver until a patch is available."

Only yesterday, Cisco put a big questionmark over another claimed security hole in its firewall. Despite claiming that it was "really easy" to exploit, Cisco has so far been unable to replicate the problem.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *