3 ms·
The threat is not against the Plans to the Empire but the password for the encryption system. That, as the video shows, can be done and without any particular
by all 16y ago
The threat is not against the Plans to the Empire but the password for the encryption system. That, as the video shows, can be done and without any particular haste. As the article suggests, freezing the RAM lengthens the decay process. The method is likely to have been known by three-letter agencies for some time now. The good guys are seldom, if ever, ahead of the bad guys, so it seems likely that the latter know it, too.
But, for the sake of argument, let's say that they don't crack it on the first go. So what? The password has to be in RAM every time the machine starts. AFAIK (and I would be pleased to be wrong about this), nobody shreds data on the hard drive because the user gets their password wrong. So, said bad guys can try to their heart's content.
As far as I'm concerned, it is a major hole in any argument for full-disk encryption.
- tptacek 16y agoI think you're misunderstanding both the attack and full-disk encryption. The decryption key is not in RAM every time the machine starts; you have to enter material to derive the key at bootup. And the attacker does in fact have minutes to recover whatever's in RAM once the machine shuts down --- which means that if you shut your machine down before leaving the office (which you have to do), remanence simply isn't a threat at all. Everyone "shreds" their hard disk if they lose the password. That is the point. Also, the Plans are to the Death Star, not the whole Empire.
- nonane 16y agoRarely does one shutdown a laptop anymore. Usually people just close the lid and the computer is put to sleep. In sleep state the contents of RAM is preserved AFAIK and should give the attacker more time to think their plan through.
- tptacek 16y agoThe rules are different when you use full-disk encryption. You shut your machine down. PGP WDE actually prevents "sleep" from working, but regardless, you still need to be vigilant.
- rsanders 16y agoPGP WDE doesn't prevent sleep from working on my MacBook. It disables hibernation, but that's not a security choice. It's just a limitation of the implementation. What you say is the right policy to maximize security, but PGP WDE doesn't enforce it.
- tptacek 16y agoYou're right. Sorry, I misspoke.
- gojomo 16y agoThe OP is worried about thieves, not three-letter-agencies.
- all 16y agoTrue, but the point of the article is that both now have this level of know-how. So all bets are again off once physical security is compromised - regardless of whether its a farmboy from Langley or Nebraska.
- donw 16y agoYou're looking at a different threat model. Hard drive encryption isn't there to stop the government, the police, or the Girl Scouts. It's there so that when the Pink Panther walks away with your laptop, he doesn't get instant access to to all of your data. If Mr. Laptop Thief wants your home directory, he's going to need to do a hell of a lot more work than reinstalling the OS and throwing the machine up on eBay. If your drive isn't encrypted, I'll wager that a laptop thief would take a few minutes to poke around and look for something interesting, like that file 'Corporate Strategy 2010.doc', or "My Affair With The Underaged Intern, Oh God I Hope This Doesn't Get Leaked Onto The Pirate Bay.avi".
- woodall 16y agoisn't a realistic attack in his threat model Under different circumstances your solution would be 100% correct, however, in this situation we are worried about "everyday" type criminals. These are the guys/girls that find a laptop in an unlocked locker and snatch it; small window of opportunity. In your analogy the description of the criminals is much more sophisticated; Oceans 11 types. Stealing RAM can potentially tip someone off to a threat, a better solution IMO is the Stone-Cold Bootkit[1]. The bootkit can hook into Windows in order to gain unrestricted access. It does this by writing to the MBR unrestricted; haven't we seen this before[2]? Once installed it will log your decryption password and do what ever with it. A BIOS password(windows) and HHD encryption will be enough to keep the NSA out for a while, and a normal criminal out indefinitely. It would be nice to have a mobo with some type of secure memory encryption programs could write to- digitally signed. Of course that could be owned too, but it's a start. In the words of Bruce Schneier, "[sic] it is very difficult to secure data when the attacker has physical control of the machine the data is stored on."[3] Now I am thinking about the /boot partition in linux; where GRUB is stored. [1] http://www.stoned-vienna.com/ http://www.stoned-vienna.com/ [2] http://news.ycombinator.com/item?id=1643451 http://news.ycombinator.com/item?id=1643451 [3] http://www.schneier.com/blog/archives/2008/02/cold_boot_attac.html http://www.schneier.com/blog/archives/2008/02/cold_boot_atta... [4] PSA: http://zedomax.com/blog/2009/02/23/linux-boot-hack-how-to-password-protect-grub/ http://zedomax.com/blog/2009/02/23/linux-boot-hack-how-to-pa...
- tptacek 16y agoYou've cited Schneier citing the same Felton paper that 'all cited. This research, while interesting, does not mean what 'all think it means. It is simply not the case that an attacker who captures your powered-down machine is going to be able to use remanence attacks to recover your encryption key. The real-world attack Felton's paper implicates is this: an attacker captures your powered-on laptop, because you left it sleeping in your bag and your full-disk encryption software can't reliably wipe keys when it wakes from sleep. The attacker restarts the system and uses remanence to dd the previous RAM contents into a drive for analysis. This very well may be an attack that government agencies are prepared to use against laptops, but since it's not going to work against anyone who knows how full-disk encryption works, it's simply not going to be in the arsenal of someone who steals your bag out of a bar.