Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> DMA is disabled when a machine is locked

For Firewire. What about for Thunderbolt?



This was asked on Reddit, and the answer was yes ...

http://www.reddit.com/r/netsec/comments/15ydem/inception_is_...


Another post[1] on the same website suggests that DMA is also disabled for Thunderbolt when the machine is locked.

[1]: http://www.breaknenter.org/2012/02/adventures-with-daisy-in-...


It's still slightly problematic for me. To prevent the re-activation of DMA, I have to disable the Guest account. Unfortunately, this also disables the "Find My iPhone" application. I would like to have both. Is there a way to have the Guest account, but not let people log into it when the machine is locked?

EDIT: Got it. It reactivates the Guest user when you turn on the "Find My" feature, but you can deactivate Guest user afterwards.


Note that this isn't necessary. If you have full disk encryption enabled, the machine will reboot (to a limited OS) when the Guest account is requested.


Does thunderbolt always use DMA? Perhaps if it's just being used as a screen output then it can turn DMA off but still work.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: