3 ms·
The key isn't in your head: you know the passphrase used to decrypt the key which is then kept in system memory. Techniques like the cold boot attack[0] or row
by dice 10y ago
The key isn't in your head: you know the passphrase used to decrypt the key which is then kept in system memory. Techniques like the cold boot attack[0] or row hammer[1] can be used to retrieve the key and access your data. In the case of non-hardware-TPM secured encryption schemes the kernel or bootloader which must remain unencrypted for the system to boot can be backdoored to record the passphrase and/or the key.
0: https://en.wikipedia.org/wiki/Cold_boot_attack https://en.wikipedia.org/wiki/Cold_boot_attack
1: https://en.wikipedia.org/wiki/Row_hammer https://en.wikipedia.org/wiki/Row_hammer
- mthoms 10y agoThere is a section at the end of the page outlining mitigation techniques against these sorts of attacks. I'm not knowledgable enough to determine if these are sufficient measures but I just wanted to point it out since it sounds like you didn't see that. They specifically cover cold boot attacks for example.
- dice 10y agoRight, OP was asking why having physical access to a "normal" machine means pwnage: cold boot is one of those ways. The ORWL page describes how they mitigate that.
- mthoms 10y agoOh I see, thank you.
- talltower 10y agoYes, correct. We think we cover the cold boot vector. Here is a section from the product description. Security mesh physically protects DRAM from both freezing specific components and removal. Breaching the mesh will trigger reactive root key delete and system power down. Secure Microcontroller protects against chilling the full device - temps below -37℃ will trigger a tamper event, deleting root key and removing power from system. Link to the complete Product Description: https://www.orwl.org/wiki/index.php?title=File:ORWL_PRD_v0.61.pdf https://www.orwl.org/wiki/index.php?title=File:ORWL_PRD_v0.6...