Apple batteries can be hacked, says researcher
By Tom Brewster,
It is possible to hack Apple MacBook batteries, with the potential to set them on fire, notable security researcher Charlie Miller believes.
Miller will talk about how to compromise an Apple battery by taking over its “embedded controller” at the Black Hat conference in Las Vegas next month.
That controller – the chip responsible for charging the battery - is used in a large number of MacBook, MacBook Pro and MacBook Air laptops.
“I will demonstrate how the embedded controller works. I will reverse engineer the firmware and the firmware flashing process for a particular smart battery controller,” explained Miller, who currently works as Accuvant Labs' principal research consultant.
“In particular, I will show how to completely reprogram the smart battery by modifying the firmware on it. Also, I will show how to disable the firmware checksum so you can make changes. I present a simple API that can be used to read values from the smart battery as well as reprogram the firmware.”
He said hackers with the ability to control a working smart battery could cause safety issues, such as overcharging or fire.
To hack the hardware, Miller found he first needed to crack a four-byte password needed to unlock the battery from “sealed mode,” Kaspersky’s Threat Post reported.
He then had to find another password to gain full control of the battery.
“You can read all the firmware, make changes to the code, do whatever you want. And those code changes will survive a reinstall of the OS, so you could imagine writing malware that could hide on the chip on the battery,” Miller said.
“You'd need a vulnerability in the OS or something that the battery could then attack, though.”
Despite his best intentions, Miller was unable to make the battery explode or set on fire.
He will release a tool at the Black Hat conference to change default passwords on the battery’s chip so the hacks will no longer work and the device will be permanently locked in sealed mode.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- UK regulator shuts down Angry Birds scam
- Apple iPad 3 vs iPad 2 head-to-head review
- IBM bans use of Siri on iPhones
- Chromebooks: What's gone wrong?
- HP plans massive job cuts
- EMC World 2012: Tucci declares Documentum is here to stay
- Dell EqualLogic PS6100XS review
- Macs and Android under malware threat
- RIM loses its head of sales
- Local fibre broadband needs common standards
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






Charlie Miller likely to be used in terror attacks
It is possible to hack Charlie Miller, with the potential to set him on fire.
You can gain access to his brain by leaving subliminal messages in the arrangement of tomatoes on his pizza, which encourage him to over exercise until he spontaneously combusts. Additional messages in the arrangement of the black olives can ensure that he does this adjacent to important US military installations.
The situation is made worse by Domino Pizza's lack of facilities to sign pizza's to check that they have not been tampered with.
However improbable this may seem, its more likely to come to pass than Charlie's own contentions.
By Henry_3_Dogg on Tuesday Jul 26