|
The TCPA does not address this scenario at allThe TCPA does not address this scenario at allPosted Feb 26, 2008 17:28 UTC (Tue) by hmh (subscriber, #3838)In reply to: Isn't this exactly why the TCPA chip was invented ? by ballombe Parent article: Cold Reboot Attacks on Disk Encryption
While the TPCA doesn't give away its storage encryption key easily, you still need to have the unwrapped (aka unprotected) session key for your encrypted disk somewhere in main memory to work with it. The complete fix for this problem really goes through extra hardware. Designing extra-volatile memory is easy, but you need to get that memory inside a more protected location (like inside the MCH, CPU, or data storage unit itself). And an attacker with enough resources would still be able to get to it. What we can do easily, is to reduce the windows of opportunity where the keys are available unprotected in RAM, which is good enough for a lot of scenarios. Frankly, if it can be made safe enough that regular laptop and data thieves can't get to the data, I would be personally happy enough.
(Log in to post comments)
|
Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.