Cold Reboot Attacks on Disk Encryption
Posted Feb 21, 2008 17:55 UTC (Thu) by
JoeBuck (subscriber, #2330)
Parent article:
Cold Reboot Attacks on Disk Encryption
It's not clear that this attack provides much additional capability to either industrial spies or cops.
This attack relies on getting a computer that is still running, so that you can either chill the RAM or immediately transfer the data out. But there are other attacks available in that case. If it's a laptop, you can just take the machine, leaving the power running. Even if not, there is technology available to keep the machine running (saw that on Schneier's blog. If someone has physical access to your machine when it's powered on and the encrypted disk is mounted, they have your data.
As a practical matter, the key can be erased from RAM by an appropriate overwriting sequence (like those used for memory tests) that should suffice to prevent recovery. This could happen on shutdown, and the user could also be given a "panic button".
(
Log in to post comments)