Attacks on popular disk encryption systems BitLocker, FileVault, dm-crypt, and TrueCrypt

TechAdGetsdotcom | Security | Sunday, February 24th, 2008

Contrary to popular assumption, DRAMs used in most modern computers retain their contents for seconds to minutes after power is lost, even at operating temperatures and even if removed from a motherboard. Although DRAMs become less reliable when they are not refreshed, they are not immediately erased, and their contents persist sufficiently for malicious (or forensic) acquisition of usable full-system memory images. We show that this phenomenon limits the ability of an operating system to protect cryptographic key material from an attacker with physical access. We use cold reboots to mount attacks on popular disk encryption systems — BitLocker, FileVault, dm-crypt, and TrueCrypt — using no special devices or materials. We experimentally characterize the extent and predictability of memory remanence and report that remanence times can be increased dramatically with simple techniques. We offer new algorithms for finding cryptographic keys in memory images and for correcting errors caused by bit decay. Though we discuss several strategies for partially mitigating these risks, we know of no simple remedy that would eliminate them.

http://citp.princeton.edu/

Video here: http://techadgets.com/blog/?p=14




No Comments »

No comments yet.

RSS feed for comments on this post. TrackBack URI

Leave a comment










-

Accessoriesnotebook.com
Clean The Computer Of Spyware Entries With Reliable Spyware Removal Software by Arvind Singh
The Newest Work Hazard For Computer Users: CVS by Amy Thomas
Benefits Of Proper Computer Recycling & Disposal by Sam Brown
Dangers Of Illegal Computer Disposal by Sam Brown
How To Correct A Continually Rebooting Computer by Otis Cooper
Cellularmobile.info
Bulk SMS - a Revolution Of Mobile Phone Industry by ECS Technologies
Cell Phone Ring Tones; Personalize the music that you want to hear on your mobile phone by Daryl Plaza
Mobile Web Design and Development by Giovanni Gallucci
An Introduction to Mobile Psychiatric Rehabilitation by Megan Hazel
Beware of Hidden Costs When Purchasing Mobile Home Park Software by Jill Shaffer
Techadgets.com
Earn Money With Miss Upload and transfer paypal
South Korea First space rocket failed to reach proper orbit
Rockets with payloads into orbit successfully
Join freeautoresponse.com email marketing
UFO claim known as Britain's Roswell could be a "banana skin"
Digitaleditingsoftware.net
Hidden Secrets of Software by Jeffrey Colin Edwards
How To Copyright And Patent Your Software by Richard Cunningham
Hidden Secrets of Software by Jeffrey Colin Edwards
How To Copyright And Patent Your Software by Richard Cunningham
Hidden Secrets of Software by Jeffrey Colin Edwards
Freeeditingsoftware.net
Computer Fix It Software
A Review of Billing Software
User-Designed Applications. An Evolution in the Business Software Industry has Arrived.
Features And Benefits Of Anti-Spam Software
What Is Anti-Spam Software by Arvind Singh - ArticleCity.com