The curious case of the supposed Apple MacBook Wi-Fi hack

“So remember a few weeks ago when Brian Krebs posted a report titled ‘Hijacking a MacBook in 60 Seconds or Less’ on his Washington Post computer security weblog? He reported on a supposed Wi-Fi security exploit demonstrated at the Black Hat security conference, wherein ‘security researchers’ Jon Ellch and David Maynor hacked into a MacBook via Wi-Fi,” John Gruber writes for Daring Fireball.

Gruber writes, “The Washington Post’s Brian Krebs seems to have painted himself into a particularly uncomfortable corner. It was Krebs who broke the original story, and it was Krebs who gave it the made-for-Digg headline ‘Hijacking a MacBook in 60 Seconds or Less.’ It was Krebs who then wrote, in a follow-up:”

During the course of our interview, it came out that Apple had leaned on Maynor and Ellch pretty hard not to make this an issue about the Mac drivers — mainly because Apple had not fixed the problem yet. Maynor acknowledged that he used a third-party wireless card in the demo so as not to draw attention to the flaw resident in Macbook drivers. But he also admitted that the same flaws were resident in the default Macbook wireless device drivers, and that those drivers were identically exploitable. And that is what I reported.

I stand by my own reporting, as according to Maynor and Ellch it remains a fact that the default Macbook drivers are indeed exploitable.

Gruber writes, “It is becoming more and more clear that the reporting Krebs “stands by” is false. Maynor and Ellch, I believe, have discovered no such exploit against a stock MacBook. And if I’m right, not only has Krebs blown the story with regard to the security of the MacBook, he has also impugned the integrity of Apple by publishing the claim that the company “leaned on” Maynor and Ellch — an accusation Krebs published without evidence, without details regarding what exactly constituted “leaning on”, and without comment from Apple.”

Full Gruberlicious article here.

Related MacDailyNews articles:
SecureWorks admits falsifying Apple MacBook ‘60-second wireless hijacking?’ – August 18, 2006
Re: Brian Krebs’ reporting on supposed MacBook Wi-Fi exploit – August 04, 2006
Hijacking an Apple Macbook in 60 seconds video posted online – August 03, 2006
Hijacking an Apple Macbook in 60 seconds – August 02, 2006

26 Comments

  1. Poor Krebs.

    Busted with his pants down.

    Now throwing a tantrum against the Mac community because we called him on it. He even had to resort to name calling and stereo typing of the Mac community, drawing on old, tired claims.

    I can’t believe the guy works for the Washington Post.

    What a loser.

    (Oh, and yet again, a fantastic article by Daring Fireball. I recommend everyone buy the 20 buck shirt for the site. They are very cool, and it supports and awesome site.

    Unlike all of the crappy ads on this site…MDN, you have a lot to learn…

Reader Feedback (You DO NOT need to log in to comment. If not logged in, just provide any name you choose and an email address after typing your comment below)

This site uses Akismet to reduce spam. Learn how your comment data is processed.