LWN.net Logo

Cold Reboot Attacks on Disk Encryption

Cold Reboot Attacks on Disk Encryption

Posted Feb 23, 2008 0:52 UTC (Sat) by jcm (subscriber, #18262)
Parent article: Cold Reboot Attacks on Disk Encryption

The crux of the matter is that people are lazy. They don't want to reenter their password on 
resume, or after leaving the machine unattended, so passwords are retained in memory 
unnecessarily. As a partial aide, perhaps we should store passwords physically in the first
few 
pages of RAM after any machine vectors - that would make it more likely you would have to 
remove the chips to read the important bits.

Jon.


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.