The Mac Observer

Charlie Miller Finds Way to Hack MacBook Battery

TMO Talk (51)

Security researcher Charlie Miller has announced that he has found a way to hack the chips that control the batteries in Apple’s MacBook, MacBook Pro, and MacBook Air. Using these chips, he was able to brick (or ruin) batteries, or even install persistent malware that would survive a physical hard drive change.

In an interview with Fortune published over the weekend, Mr. Miller said that he found these controller chips all used default passwords, and that with this knowledge, a hacker can learn how to reverse engineer the firmware Apple uses to program and control the chips.

Security Researcher Charlie Miller

Security Researcher Charlie Miller
Photo by Garrett Gee, posted to Flickr

“These batteries just aren’t designed with the idea that people will mess with them,” Mr. Miller told Fortune. “What I’m showing is that it’s possible to use them to do something really bad.”

He added, “You could put a whole hard drive in, reinstall the software, flash the BIOS, and every time it would reattack and screw you over. There would be no way to eradicate or detect it other than removing the battery.”

He also said that while he hasn’t tested it yet, he believes that it would be possible to use these microprocessors to blow up the battery, despite independent safeguards designed to prevent such an occurrences.

“You read stories about batteries in electronic devices that blow up without any interference,” he said. “If you have all this control, you can probably do it.”

Mr. Miller is one of the world’s foremost experts on security when it comes to Apple’s hardware and software, and he has raised the ire of both Apple and Apple fans by publishing information about security holes when he has deemed Apple too slow to respond to information.

At the same time, in February, Apple offered Mr. Miller and other security researchers advance access to Lion, an unprecedented move by the company to work with the independent security community.

As for this hack, Mr. Miller plans to unveil it at the Black Hat hacker conference that takes place in Las Vegas during August. In addition to showing how the hack can be performed, he intends to release a fix for the problem he is calling Caulkgun.

That fix will change the passwords used by your MacBook’s microcontrollers to random strings to prevent the bad guys from being able to waltz in, assuming they had control of your MacBook in the first place.

He also said that he has notified Apple and Texas Instruments, the company that makes the microcontrollers, about the problem.

Post A Comment or Log-in. Need an account? Register here.

4 Observer Comments

I think we grew up just down the street from this guy.  I remember a kid with a magnifying glass and ants. . .

Fair play to him. He might get a job with some specky media mogul.

   Actions Lee Dronick said on July 26th, 2011 at 7:45 AM (Edited: 10/18/2011 6:20 PM):

Fair play to him. He might get a job with some specky media mogul.

The other shoe from the phone hacking scandal has yet to drop.

   Actions ToeFats said on July 27th, 2011 at 5:41 AM:

I was talking to a friend yesterday who said he went to the apple store with weird battery problems.  He reported that the mac store person informed him his battery had been hacked, and that this was getting more common.  He gave him a new battery.
Was this a lame excuse for battery control problems, or is this a real hacking issue?

Post A Comment or Log-in. Need an account? Register here.
 

Recent Headlines - Updated May 27th

Sat, 10:00 AM
MacOS KenDensed - MacOS KenDensed: Apple’s Patent Lawsuit & Antitrust Shuffle
Fri, 5:58 PM
News - Sotheby’s to Auction Steve Jobs Atari Memo (Photo Gallery)
5:42 PM
Free on iTunes - 3 Free iOS Apps for News Hounds
3:00 PM
Rumor - Nest Thermostat Reportedly Coming to Apple Retail Stores
2:40 PM
Particle Debris - The TV Industry’s Dreadful Little Secret
2:33 PM
News - Mobile Devices Account for 20% of Web Traffic in US, Canada
12:49 PM
News - Apple Now Offering “Free App of the Week” for iOS
12:21 PM
News - Tim Cook Declines $75 Million Dividend Payout
11:25 AM
News - Absinthe 2.0 Provides Untethered Jailbreak for iOS 5.1.1
11:09 AM
Quick Look Review - F18 Carrier Landing (iOS) is a Boatload of Fun
10:51 AM
TMO Appearances - Jeff Gamet talks Cool Apps & Accessories on Not Another Mac Podcast
10:12 AM
Hot Forum Topic - Forum Poll: Which is Your Favorite Photo Sharing Service?
 

The Mac Observer Reader Specials

  • Macsales Add 2nd Hard Drive or SSD to Mac mini, MacBook or MacBook Pro. 1TB of Hard Drive or SSD Capacity from $64.99! Video Guides Make it easy - OWC DataDoubler - Macsales.com
  • Mac RAM Upgrades: MacBook Pro 16GB kits $475, 8GB Kits for $119.99! iMac 16GB RAM Kits (4x 4GB) for $229.99! Mac Pro Memory 32GB Kit for $399.99, 64GB Kit for $889.99! Mac Hard Drives 2TB Seagate SATA II for $249.99! Click Here!
  • Macpokeronline.com If you're using a Mac, then you've gotta check out PokerOnAMac.com. Online casinos and poker rooms are literally giving away cash and the casino sites at Poker on a Mac do the unthinkable, they actually reward! Join today, the download is free!
  •  Looking to find online casinos for mac? We can help you find the best real money casino sites where you can play your favorite casino games including blackjack and slots.

Apple Stock Quote (AAPL)

Loading...

Hot Topics

TMO Express

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday. Find out more!

Top Deals From DealBrothers.com

Recent Features

Support The Mac Observer

We noticed you may be running AdBlock on your computer. It takes real money to run this site and to deliver the news, tips, and opinions you love to read.

If you wish to block the ads that pay for the creation of our content, we ask that you instead support TMO Directly, either with a $5 monthly recurring contribution, or a one-time donation of any amount of your choice. Thanks!

Subscribe with Paypal Donate with Paypal