LWN.net Logo

Cold Reboot Attacks on Disk Encryption

Cold Reboot Attacks on Disk Encryption

Posted Feb 28, 2008 7:25 UTC (Thu) by jimparis (subscriber, #38647)
Parent article: Cold Reboot Attacks on Disk Encryption

The 99.9% solution that I'm happy with is: never leave my computer unattended while the hard
drive encryption keys are present in RAM.  That means I never lock the screen and walk away,
and I never suspend to ram and walk away.  I just suspend to disk and power off completely.

The only new thing this research pointed out to me is just how long it takes for unpowered
room-temperature RAM to lose its contents -- I suspected it was within a second but it's a bit
longer than that.  Anyway, this small window can be fixed by modifying the suspend-to-disk
process to also clear the RAM right before poweroff (I'm still in control of the laptop at
this point, so nobody can interrupt it).


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.