Filevault, Bitlocker, Truecrypt Cracked


Recommended Posts

A team of security researchers on Thursday reported serious vulnerabilities in disk encryption products including Microsoft's BitLocker, Apple's FileVault, and the open-source TrueCrypt. Because memory contents are not deleted when the computer is rebooted, someone can gain access to the contents of the encrypted volume by restarting it and extracting the encryption keys.

http://www.news.com/2300-1029_3-6230933-1.html

Link to post
Share on other sites
So couldn't this be defeated by just shutting off your computer or just login out of all accounts.

No. The Princeton team discovered that the contents of DRAM can be recovered after it's powered off. At room temperate the data persists for up to a minute or so. Cooling the chips with an air duster extends that to around ten minutes. Liquid nitrogen extends it to at least an hour.

So, you can grab the machine, reboot into a friendly system, and recover the decryption keys. Or you can grab the machine, yank the RAM, cool it, install it in another machine, and recover the keys.

There's no obvious way to protect against this attack on standard hardware.

Edited by jcl
Link to post
Share on other sites
So couldn't this be defeated by just shutting off your computer or just login out of all accounts.

No. The Princeton team discovered that the contents of DRAM can be recovered after it's powered off. At room temperate the data persists for up to a minute or so. Cooling the chips with an air duster extends that to around ten minutes. Liquid nitrogen extends it to at least an hour.

So, you can grab the machine, reboot into a friendly system, and recover the decryption keys. Or you can grab the machine, yank the RAM, cool it, install it in another machine, and recover the keys.

There's no obvious way to protect against this attack on standard hardware.

Hmmmm......Guess I need to put my laptop in the oven at 350 degrees for 20 minutes? :lol:

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...