Showing posts with label Thunderbolt. Show all posts
Showing posts with label Thunderbolt. Show all posts

Friday, August 23, 2013

Asus launches Z87-Deluxe/Quad motherboard, first with Thunderbolt 2



It was only in June that Intel finalized Thunderbolt 2, the second generation of their data interconnet technology, with Intel promising it would enter production by the end of the year. In keeping with that promise, Asus has announced the first Thunderbolt 2-certified motherboard, the Z87-Deluxe/Quad.

Tuesday, July 24, 2012

Apple patches CPU power consumption bug in 2012 MacBooks


apple, thunderbolt, macbook, mac, os
Apple has issued an update that addresses CPU-related power consumption issues with MacBook Air and MacBook Pro models released in June, including the 15-inch Retina display model. Details are slim on the 76.64MB update, but CNET reportsthat it contains new versions of the I/O kernel extensions and frameworks, the Dock application, and shared resources such as desktop pictures, user icons and system sounds. The patch also improves compatibility with certain USB devices interfering with Wi-Fi signals and causing other issues.
Unaddressed by today's update is an audio issue that arises when a 2012 MacBook is connected to an external display via Thunderbolt. A thread on Apple's support forum was created nearly a month ago and has accumulated over 100 replies with various related complaints. Users note that the MacBook's integrated speakers work fine, but they complain of intermittent static and crackling from the speakers in Apple's Thunderbolt Display.
Most of the complaints involve the 11 and 13-inch MacBook Air, though at least one person claims to have the issue with the Retina-equipped MacBook Pro. An exact cause remains unknown, but some folks believe that the adapter connecting Apple's new MagSafe 2 power connector to the Thunderbolt Display's power cord may be at fault. Others note that switching between audio outputs, reattaching all connections and/or restarting the offending program serves as a temporary workaround, but nobody has discovered a permanent solution.

Friday, June 22, 2012

Thunderbolt 1.2.1 update resolves kernel panic issue for Mac users


imac, thunderbolt, wwdc, lion, macbook, mac os x, mac, updates, crashes, kernel panic, errors, system updates, system updater, firewi
Apple has released a new Thunderbolt update (1.2.1) which promises not to crash your Mac this time around. For those of you who have been patiently waiting in hopes of avoiding a system crash, it should now be safe to try your luck with the System Updater once again.

Following several noteworthy product announcements by Apple at WWDC 2012, the company hastily released an update for Mac OS X which promised support for its new Thunderbolt-based network and Firewire converters. Although a seemingly innocuous patch, the well-intentioned Thunderbolt 1.2 update rendered some iMac and Macbook owners' systemsunbootable.

Apple promptly pulled the Thunderbolt 1.2 update from its servers following a growing number of complaints. The company later confirmed the issue on the June 18 with this knowledge base support article and released a new and improved Thunderbolt 1.2.1 update that is (hopefully)kernel-panic free.

If you were one of the unlucky ones but never got around to fixing your system, Apple's support article outlines the official solution to the issue: use Lion's built-in recovery feature.

Users can initiate the repair process by powering up (or restarting) their Mac and hold the Command + R keys simultaneously after the boot-time "chime" sound. When prompted to do so, choose to re-install Mac OS X and log on with your Apple ID. It may take a while, but the recovery process will solve the issue. Also, all of your personal files, application settings and most of your system configuration .plists should remain unscathed.

As always though, it's important to keep a current backup. If you're a Mac user, there's really no easier way to do this than using Time Machine on a secondary or external storage device.

Thursday, December 29, 2011

Intel's Thunderbolt to see wider adoption starting April 2012


Intel is reportedly pushing for wider adoption of its high speed Thunderbolt interconnect in 2012. According to DigiTimes, the company will "fully release" its I/O technology in April -- which happens to coincide with Ivy Bridge's launch -- and already several first-tier PC and component manufacturers are looking into adding Thunderbolt support to their motherboards, notebooks and desktop PCs.

Sony and Asus are mentioned among the companies expected to adopt the technology in their high-end notebook products, although we should note that the former has been offering a Thunderbolt-equipped Vaio Z notebook for a while. Meanwhile, Gigabyte, which has been aggressively adopting new I/O technologies into its product line, is also expected to add Thunderbolt support to select motherboards in April 2012.

Originally known as Light Peak, Thunderbolt is Intel's high-speed interconnect that can transfer data between host computers and external devices such as displays and storage products at speeds of up to 10Gbps. The interface supports hubs as well as daisy chaining up to seven compatible devices.

Up until now only Apple has implemented the technology across its product lines, including the MacBook Air, MacBook Pro, iMac, Mac mini, and LED Display.

Thunderbolt still has a few hurdles to clear, such as the limited availability of supporting devices and the fact that it is more expensive to implement than USB 3.0. However, the hope is that in mass production the cost of adopting Thunderbolt will go down in the second half of 2012 and the technology becomes standard.

Tuesday, December 27, 2011

Intel's Thunderbolt to see wider adoption starting April 2012


Intel is reportedly pushing for wider adoption of its high speed Thunderbolt interconnect in 2012.According to DigiTimes, the company will "fully release" its I/O technology in April -- which happens to coincide with Ivy Bridge's launch -- and already several first-tier PC and component manufacturers are looking into adding Thunderbolt support to their motherboards, notebooks and desktop PCs.

Sony and Asus are mentioned among the companies expected to adopt the technology in their high-end notebook products, although we should note that the former has been offering a Thunderbolt-equipped Vaio Z notebook for a while. Meanwhile, Gigabyte, which has been aggressively adopting new I/O technologies into its product line, is also expected to add Thunderbolt support to select motherboards in April 2012.

Originally known as Light Peak, Thunderbolt is Intel's high-speed interconnect that can transfer data between host computers and external devices such as displays and storage products at speeds of up to 10Gbps. The interface supports hubs as well as daisy chaining up to seven compatible devices.

Up until now only Apple has implemented the technology across its product lines, including the MacBook Air, MacBook Pro, iMac, Mac mini, and LED Display.

Thunderbolt still has a few hurdles to clear, such as the limited availability of supporting devices and the fact that it is more expensive to implement than USB 3.0. However, the hope is that in mass production the cost of adopting Thu

Monday, October 3, 2011

Massive Security Vulnerability In HTC Android Devices (EVO 3D, 4G, Thunderbolt, Others) Exposes Phone Numbers, GPS, SMS, Emails Addresses, Much More


I am quite speechless right now. Justin Case and I have spent all day together with Trevor Eckhart (you may remember him as TrevE of DamageControl and Virus ROMs) looking into Trev's findings deep inside HTC's latest software installed on such phones as EVO 3D, EVO 4G, Thunderbolt, and others.
These results are not pretty. In fact, they expose such ridiculously frivolous doings, which HTC has no one else to blame but itself, that the data-leaking Skype vulnerability Justin found earlier this year pales in comparison. Without further ado, let me break things down.

The Vulnerability

In recent updates to some of its devices, HTC introduces a suite of logging tools that collected information. Lots of information. LOTS. Whatever the reason was, whether for better understanding problems on users' devices, easier remote analysis, corporate evilness - it doesn't matter. If you, as a company, plant these information collectors on a device, you better be DAMN sure the information they collect is secured and only available to privileged services or the user, after opting in.
That is not the case. What Trevor found is only the tip of the iceberg - we are all still digging deeper - but currently any app on affected devices that requests a singleandroid.permission.INTERNET (which is normal for any app that connects to the web or shows ads) can get its hands on:
  • the list of user accounts, including email addresses and sync status for each
  • last known network and GPS locations and a limited previous history of locations
  • phone numbers from the phone log
  • SMS data, including phone numbers and encoded text (not sure yet if it's possible to decode it, but very likely)
  • system logs (both kernel/dmesg and app/logcat), which includes everything your running apps do and is likely to include email addresses, phone numbers, and other private info
Normally, applications get access to only what is allowed by the permissions they request, so when you install a simple, innocent-looking new game from the Market that only asks for the INTERNET permission (to submit scores online, for example), you don't expect it to read your phone log or list of emails.
But that's not all. After looking at the huge amount of data (the log file was 3.5MB on my EVO 3D) that is vulnerable to apps exploiting this vulnerability all day, I found the following is also exposed (granted, some of which may be already available to any app via the Android APIs):
  • active notifications in the notification bar, including notification text
  • build number, bootloader version, radio version, kernel version
  • network info, including IP addresses
  • full memory info
  • CPU info
  • file system info and free space on each partition
  • running processes
  • current snapshot/stacktrace of not only every running process but every running thread
  • list of installed apps, including permissions used, user ids, versions, and more
  • system properties/variables
  • currently active broadcast listeners and history of past broadcasts received
  • currently active content providers
  • battery info and status, including charging/wake lock history
  • and more
Let me put it another way. By using only the INTERNET permission, any app can also gain at leastthe following:
ACCESS_COARSE_LOCATION Allows an application to access coarse (e.g., Cell-ID, WiFi) location
ACCESS_FINE_LOCATION Allows an application to access fine (e.g., GPS) location
ACCESS_LOCATION_EXTRA_COMMANDS Allows an application to access extra location provider commands
ACCESS_WIFI_STATE Allows applications to access information about Wi-Fi networks
BATTERY_STATS Allows an application to collect battery statistics
DUMP Allows an application to retrieve state dump information from system services.
GET_ACCOUNTS Allows access to the list of accounts in the Accounts Service
GET_PACKAGE_SIZE Allows an application to find out the space used by any package.
GET_TASKS Allows an application to get information about the currently or recently running tasks: a thumbnail representation of the tasks, what activities are running in it, etc.
READ_LOGS Allows an application to read the low-level system log files.
READ_SYNC_SETTINGS Allows applications to read the sync settings
READ_SYNC_STATS Allows applications to read the sync stats
Theoretically, it may be possible to clone a device using only a small subset of the information leaked here.
I'd like to reiterate that the only reason the data is leaking left and right is because HTC set their snooping environment up this way. It's like leaving your keys under the mat and expecting nobody who finds them to unlock the door. For a more technical explanation, see the section below.
Additionally, and the implications of this could end up being insignificant, yet still very suspicious, HTC also decided to add an app called androidvncserver.apk to their Android OS installations. If you're not familiar with the definition of VNC, it is basically a remote access server. On the EVO 3D, it was present from the start and updated in the latest OTA. The app doesn't get started by default, but who knows what and who can trigger it and potentially get access to your phone remotely? I'm sure we'll know soon enough - HTC, care to tell us what it's doing here?

Technical Details

In addition to Carrier IQ (CIQ) that was planted by HTC/Sprint and prompted all kinds of questions a while ago, HTC also included another app called HtcLoggers.apk. This app is capable of collecting all kinds of data, as I mentioned above, and then... provide it to anyone who asks for it by opening a local port. Yup, not just HTC, but anyone who connects to it, which happens to be any app with the INTERNET permission. Ironically, because a given app has the INTERNET permission, it can also send all the data off to a remote server, killing 2 birds with one stone permission.
In fact, HtcLogger has a whole interface which accepts a variety of commands (such as the handy:help: that shows all available commands). Oh yeah - and no login/password are required to access said interface.
Furthermore, it's worth noting that HtcLogger tries to use root to dump even more data, such as WiMax state, and may attempt to run something called htcserviced - at least this code is present in the source:
/system/xbin/su 0 /data/data/com.htc.loggers/bin/htcserviced
HtcLoggers is only one of the services that is collecting data, and we haven't even gotten to the bottom of what else it can do, let alone what the other services are capable of doing. But hey - I think you'll agree that this is already more than enough.
wm_10-1-2011 9-50-42 PM

Proof Of Concept App

In order to help showcase his findings, TrevE created an open-sourced POC (proof of concept) of a simple app that requests a single INTERNET permission, then shows that it can gain access to all the data I mentioned above. I ran the app on an unrooted EVO 3D - see the screenshots below or try it out yourself.
There is also a video walkthrough below the screenshots, shot by Trevor himself.
Proof of concept source and apk:
wm_2011-10-01_10-31-48 wm_2011-10-01_10-32-09 wm_2011-10-01_10-32-25
wm_2011-10-01_10-33-17 wm_2011-10-01_10-36-16 wm_2011-10-01_10-40-23

Patching The Vulnerability

... is not possible without either root or an update from HTC. If you do root, we recommend immediate removal of Htcloggers (you can find it at /system/app/HtcLoggers.apk).
Stay safe and don't download suspicious apps. Of course, even quality-looking apps can silently capture and send off this data, but the chance of that is lower.

Affected Phones

Note: Only stock Sense firmware is affected - if you're running an AOSP-based ROM like CyanogenMod, you are safe.
  • EVO 4G
  • EVO 3D
  • Thunderbolt
  • EVO Shift 4G? (thanks, pm)
  • MyTouch 4G Slide? (thanks, Michael)
  • the upcoming Vigor? (thanks, bjn714)
  • some Sensations? (thanks, Nick)
  • View 4G? (thanks, Pat)
  • the upcoming Kingdom? (thanks, Pat)
  • most likely others - we haven't verified them yet, but you can help us by downloading the proof of concept above and running the APK

HTC's Response

After finding the vulnerability, Trevor contacted HTC on September 24th and received no real response for five business days, after which he released this information to the public (as per RF full disclosure Policy). In my experience, lighting fire under someone's ass in public makes things move a whole lot faster, which is why responsible disclosure is a norm in the security industry. (This is where we come in.)
As far as we know, HTC is now looking into the issue, but no statement has been issued yet.
HTC, you got yourself into this mess, and it's now up to you to climb out of the hole as fast as possible, in your own interest.
The ball is in your court.

Credit

Huge thank you to Trevor Eckhart who found the vulnerability and Justin Case for working with us today digging deeper.