
Björn Ruytenberg, a security at Eindhoven University of Technology, has discovered that he can hack almost any computer built before 2019 by exploiting a vulnerability in Thunderbolt ports. Fortunately, the attack , dubbed “ThunderSpy,” only works when the attacker has physical access to your device.
Using ThunderSpy, a hacker can easily read and copy all the data on your device, even if it is locked or in sleeping mode.
Thunderbolt ports are vulnerable to other attacks as well. Last year, a team of researchers found several more flaws that exist in several computers that have Thunderbolt ports. These flaws, also referred to as the ThunderClap collection, can be used to gain access to the data on the vulnerable device.
At the time, researchers recommended that users use the 'security levels' feature, which prohibits untrusted devices from accessing the system. Unfortunately, the 'security levels' feature does not help in dealing with the ThunderSpy attack, as the attack applies changes to the firmware of the internal chip in order to operate. However, when the first flaws were found, Intel announced a new security mechanism called “Kernel Direct Memory Access Protection”, which can even deal with the ThunderSpy attack.
After Ruytenberg's discovery, it became known that Intel's mechanism is present in only a few computers manufactured up to 2019. More specifically, the researchers discovered that the kernel DMA is not present at all in Dell devices ,while it is present in only a few models from HP and Lenovo. For this reason, Ruytenberg created a toolthat you can use to see if your computer contains Kernel DMA.
How the ThunderSpy attack works:

In a video made by Ruytenberg, he shows how anyone can easily change the chip's firmware using an SPI device that "wears" an SOP8 clip. The process requires removing the device's cover. However, once the device is connected to the computer, it takes an attacker a maximum of 2 minutes to change the firmware and gain access to the files.
Thunderspy as an evil-maid attack?
Fortunately, the attack is not considered an evil-maid type, as it requires physical access to the targeted device. For the same reason, this attack is not as well known compared to others that are executed remotely, which is why it is not used as often. Nevertheless, ThunderSpy remains a serious attack, because it is almost invisible to its victims.
