Re: RFC: Flaw in BitLocker, Apple's FileVault, TrueCrypt, and dm-crypt



David H. Lipman wrote:


In a paper published on the Internet, researchers show that data is
vulnerable because encryption keys and passwords linger in the temporary
memory of computers after machines lose power.


I found a really bigger vulnerability: The keys are in memory while the computer is still powered on. One could simply connect some hardware to the memory bugs and read it out directly...
Or could could attach a key logger and wait until the user enters the password...

"We then wrote programs to collect the contents of memory after the
computers were rebooted."


Only applies to hardware reboots. If the computer is properly shut down, the software simply zeros out the key in memory.

Laptops are especially vulnerable to the attack when the machines are in
lock, sleep, or hibernation modes, according to the report.


Hibernate? The hibernate file is stored on the encrypted disc...

"This isn't a minor flaw; it is a fundamental limitation in the way these
systems were designed."


No, it's a well known intangible limit known since at least 40 years: Software cannot defend against an attacker which has physical access to the system.
.



Relevant Pages

  • Re: [Full-disclosure] round and round they go, keys in ram are ripe for picking...
    ... Cold Boot Attacks on Encryption Keys" ... Countermeasures and their Limitations ... possibly making the contents of memory decay more readily. ...
    (Full-Disclosure)
  • Re: death of the mind.
    ... >> vision of science is the sterile state of their explanatory theories. ... engages in the behavior said to "show memory." ... > computers aren't animals and probably aren't like them in very many ways. ... And I've published inferential statistics when forced to - which was most of ...
    (sci.cognitive)
  • Re: self-extracting diskette image to hard disk? (or, IBM keeping inexpensive supercomputers awa
    ... >> also have brought in huge amounts of money, ... > I know what IBM was doing, ... >> claiming not only that memory would be many times larger than existing ... >> selling these super computers for $3000. ...
    (comp.os.os2.misc)
  • Re: Breaking Large Composite Numbers...???
    ... with somewhere between 1 and 10 Tbytes of memory.. ... supercomputers that have more than your 10 TiB of memory. ... because those aren't computers, they are clusters. ... precision calculations on hundred thousands of cores. ...
    (sci.crypt)
  • Re: My next Workstation
    ... I would like to have a RAID array to have better performance. ... In my experience with computers memory is always going to be faster than ... mechanical hard drives. ...
    (Ubuntu)