7 ms·
Cold Boot Attacks
- bardworx 8y agoFrom a security standpoint, isn’t there a common understanding that if an attacker gains physical access to your computer, you already lost? As a side note, there are so many vulnerabilities constantly coming out that I’ve almost became desensitized. I’m sure that’s not a good thing but it’s almost like “when” not “if” someone will just steal my data. Not sure if anyone agrees or I’m just a one-off...
- lazyjones 8y ago> isn’t there a common understanding that if an attacker gains physical access to your computer, you already lost? I don‘t think so. It would mean that securing information in the workplace is nearly impossible and colocation hosting security intrusion boils down to picking a physical lock (of your rack).
- jarfil 8y agoSome parts of a computer are easier to access than others. Like, it's quite easy to access the contents of a hard drive, but not so much some value stored in a particular register in the CPU. That's why it makes sense to encrypt data stored on a hard drive, but we expect the CPU to be able to handle plaintext securely. Turns out, we should think of RAM more like a hard drive than like something internal to the CPU.
- knorker 8y ago> Cold boot attacks aren’t new. They were developed by a research group back in 2008 Older than that. E.g. Pettersson's talk at CCCamp 2007.
- En_gr_Student 8y agoI'd be surprised if some analog of this didn't come out in the 80's. The fundamentals were all there, even arpanet.
- liftbigweights 8y agoThat's why the #1 rule of security is physical security. If someone has physical access to your computer, it's pretty much game over.
- atmoz 8y agoWell, yes and no. Not necessarily if you turn off your computer or use hibernation instead of sleep, AND you use full disk encryption. This will stop short-term attacks, like cold boot attacks and the like. Of course, if they "borrow" your laptop for a while, opens it up, installing key loggers, modifying the firmware/hardware, and you do not notice this: you are f*ed. I mean: even if you believe that "if someone has physical access to your computer, it's pretty much game over" you don't necessarily drop encryption and user password on the laptop and always put it in sleep mode.
- arcticbull 8y agoTell that to the FBI trying to get into an iPhone
- liftbigweights 8y agoThey succeeded... https://money.cnn.com/2016/03/28/news/companies/fbi-apple-iphone-case-cracked/index.html https://money.cnn.com/2016/03/28/news/companies/fbi-apple-ip...
- leejoramo 8y agophysical access = compromised system There are things you can do to mitigate this problem, but once someone has physical access to a computer they have many pathways to gaining access to data and control.
- arachnids 8y agoThis is already not true for modern iPhones. I think the time to stop accepting this has come. We should demand better from commodity devices.
- deleted 8y ago[deleted]
- comboy 8y agoI think most disagreement in this thread comes from not separating two very different cases. 1) I got access to you hardware and I want to extract data from it 2) I got access to your hardware and I get to give it back to you and you continue using it as if nothing happened
- ams6110 8y agoThat's true, but it's what encrypted filesystems are supposed to prevent. The lesson is that sleep/low power modes are not enough. You should be powering-off or hibernating any time the computer is not in use. Unfortunately this is against many enterprise policies for desktops, because they like to apply updates during off-hours and need the computers to be on (or at least able to wake up from sleep) to do that. For laptops, you should configure them to hibernate when the lid is closed, not just sleep.
- snaky 8y agoIf their slides are correct, then disabling boot from USB is enough. But then they state > Using a simple tool, Olle and Pasi learned how to rewrite the non-volatile memory chip that contains these settings, disable memory overwriting, and enable booting from external devices The phrasing is confusing in that had they find a way to switch 'boot from USB' BIOS setting 'using a simple tool'.
- acura 8y agoCold boot, you keep using this word and you don't know what it means. Or is it me who have a screwed definiton of cold boot?
- detaro 8y agoCold boot attack: An attack in which a running system is reset and information extracted from its memory that survived the reset. Seems like the article is using it correctly.
- jo909 8y agoAs defined in the article: "when a computer is reset without following proper procedures (what’s known as a cold/hard reboot)" Even if you disagree, "cold boot attack" is the established name for the actual attack, the new aspect presented here is how to circumvent a certain firmware protection that would overwrite the memory on a cold boot to prevent that attack. If you would give your definition we could see if it is right, too.
- acura 8y agoI thought the definition of cold boot was a boot from a powered down state.
- new_age_garbage 8y agoLeaving the computer on is a cold boot attack now?
- detaro 8y agoNo, a cold boot attack is a way of recovering data from a system you gain access to while it is running.
- mannykannot 8y agoAt first, I could not figure out why sleep mode was an issue, but I think the point is that a cold boot attack has to be performed within minutes of the shutdown, and it has to be a 'hard' (just cut the power) type of shutdown, not an orderly shutdown where the OS stops what's running and then instructs the hardware to shut down. An attacker who gets his hands on a computer in sleep mode is in a position to force a hard shutdown and immediate cold boot when he is ready.
- pjc50 8y agoEveryone's quickly jumping in to post "physical access is not secure", while over there Apple have iPhones that appear to be almost completely secure against all but the most dedicated state-level attacks (and of course compromised accounts). We can do better, and should. Without compromising the freedom to change operating system. Mind you we also need to keep pressing on security for the desktop, against ransomware and malicious installs. Again without compromising freedom of choice.
- hannasanarion 8y agoIPhones are probably vulnerable to cold boot too. It's just that cold boot attacks are absurdly difficult to execute. They only work if you already have physical access to an unlocked device before it powers down. If you shut off your machine and wait two seconds before walking away, you can never be cold-booted
- hyperpape 8y agoAre you sure/can you provide sources? Given the substantial efforts law enforcement has been taking to get access to suspects' iPhones, this doesn't seem right.
- albntomat0 8y agoThe commenter above specifically says powered on, unlocked. If the phone is locked or powered off, things are much harder.
- hyperpape 8y agoI guess I was confused by "If you shut off your machine", which is not the same thing as locking it. If cold boot attacks only work against unlocked devices, that makes a lot of sense. But if they work against locked but powered devices, that would be quite possible for LE to exploit in most cases (just carry a battery pack).
- hannasanarion 8y ago
- hannasanarion 8y agoSo do y'all regularly dump liquid nitrogen on your computers after powering them off? Last I checked, cold boot attacks have to be executed within moments of a computer powering down unless it's immediately put on ice. I don't understand why we're worried about this.
- detaro 8y agoMany people do not always power down their computer completely when they leave it unattended.
- retrodpc 8y agoActually, RAM can keep its contents for up to a few minutes after shutdown. See here: https://citp.princeton.edu/research/memory/ https://citp.princeton.edu/research/memory/
- 21 8y agoRead the article. This is about attacking computers in sleep mode.
- chrisper 8y agoWhen you are in sleep mode, your RAM still has power on it.
- jarfil 8y agoSo when are we getting encrypted RAM? With all the talk I hear about "cache being the new RAM", since it's so much faster, particularly the L1, it sounds like it would make sense to have some transparent encryption going on. A random key generated at power on, then kept inside the CPU, and instantly lost at power off, would be enough to secure the contents of DIMMs against attacks like this.
- detaro 8y agoI believe some AMD CPUs already support it, and there's some mention of it in Linux Kernel docs (https://github.com/torvalds/linux/blob/master/Documentation/x86/amd-memory-encryption.txt https://github.com/torvalds/linux/blob/master/Documentation/...), but I'm not sure if it's actually used in practice or not.
- simias 8y agoSomebody could put a hardware keylogger on your keyboard interface instead. Or de-solder your CPU and replace it with a backdoored version.
- 21 8y agoSeriously? How many backdoored CPU attacks have you heard of before? If you need protection against that, might as well live inside a vault.
- cesarb 8y agoIt already exists on AMD: https://en.wikichip.org/wiki/x86/sme https://en.wikichip.org/wiki/x86/sme
- standon 8y agoI have worked with diplomatic security and diplomatic courier service. There is/was class of almost normal SCIF only laptops. They are always attended by a person and they must travel in diplomatic mail. Data inside the HDD is considered safe when the computer is powered off even if stolen, but any break in the custody chain and it was forbidden to open the laptop again. You just bagged it for destruction or data retrieval. Moral of the story: controlling physical access is the key to security. Apple phone may be secure after powered down, but it may not be secure after you start using it again if it was handled by someone in between.