Privacy Digest

News that can impact your privacy.
Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password
Home Blogs MacRonin's blog
    • FAQ
    • Wishlists
    • Contact
    • Categories/RSS

Bookmark Us

Bookmark Privacy Digest 
Bookmark This Page 

Syndicate

Syndicate content
more

Advertisements

car insurance prices
Tracking System

Popular content

Last viewed:

  • Attackers exploit zero-day Windows flaw | CNET News.com
  • First 'Pretexting' Charges Filed Under Law Passed After HP Spy Scandal
  • Comcast tweaks Terms of Service in wake of throttling uproar
  • Navy secretary laments continued loss of private data
  • Cheney Role in Bush Administration Draws Fire
  • Online Anonymity Creates New Ethical Challenges
  • "Trial Lawyers" at the ACLU? Telecom immunity & FISA

tags in Topics

Activists Alert Anonymity Companies Copyright Court (US) Databases Data Mining DMCA Editorial EFF Entertainment Exploits Fourth Amendment Government Hmmm ID Infrastructure Law Enforcement Laws Politics Privacy Remember Reports Rights Security Spin Zone Surveillance Telecommunications Tracking
more tags

View blog authority
Congressional Research
Broadcast Flag

Researchers: Disk Encryption Not Secure

Submitted by MacRonin on February 21, 2008 - 1:37pm
  • Academia
  • Alert
  • CDT
  • Cryptography
  • Exploits
  • Hmmm
  • How-To
  • Privacy
  • Reports
  • Security
  • Studies

Researchers: Disk Encryption Not Secure - Via Threat Level:

Researchers with Princeton University and the Electronic Frontier Foundation have found a flaw that renders disk encryption systems useless if an intruder has physical access to your computer -- say in the case of a stolen laptop or when a computer is left unattended on a desktop in sleep mode or while displaying a password prompt screen.

The attack takes only a few minutes to conduct and uses the disk encryption key that's stored in the computer's RAM.

The attack works because content as well as encryption keys stored in RAM linger in the system, even after the machine is powerered off, enabling an attacker to use the key to collect any content still in RAM after reapplying power to the machine.

"We've broken disk encryption products in exactly the case when they seem to be most important these days: laptops that contain sensitive corporate data or personal information about business customers," said J. Alex Halderman, one of the researchers, in a press release. "Unlike many security problems, this
isn't a minor flaw; it is a fundamental limitation in the way these systems were designed."

The researchers successfully performed the attack on several disk encryption systems -- Apple's FileVault, Microsoft's BitLocker, as well as TrueCrypt and dm-crypt -- but said they have no reason to believe it won't work on other disk encryption systems as well, since they all share similar architectures.

They released a paper about their work as well as a video demonstration of the attack (below).

(Read Original Article - Via Threat Level.)

Bookmark/Search this post with:
  • Twitter Twitter
  • Digg Digg
  • StumbleUpon StumbleUpon
  • Technorati Technorati
  • del.icio.us del.icio.us
  • Facebook Facebook
  • Furl Furl
  • LinkedIn LinkedIn
  • Yahoo Yahoo
  • MacRonin's blog
  • Add new comment

Recent blog posts

  • The Secrecy Double-Standard
  • Fully-qualified Nonsense in the SSL Observatory
  • Appeals Court Strengthens Warrantless Searches at Border
  • Justice Dept. to Congress: Don’t Saddle 4th Amendment on Us
  • Feds, RIAA Ask $22,500 in Damages Per Song
  • Building a better Certificate Authority (CA) infrastructure
  • Where’s EFF? Why EFF Is Sometimes Quiet About Important Cases
  • Congressman Wants YouTube Video Covered Up
  • Man Creates "Creepy" Stalking App
  • Boston College Says Using WiFi Is a Sign of Infringement
more

Performancing Metrics

Compilation © Copyright 1997-2010 Paul Hardwick, with Web Hosting provided by MacRonin.com.