4 ms·
That doesn't prevent extraction by someone with supervisor/hypervisor access (so if Elcomsoft can't extract it it's only because they are lazy), it just tries t
by devit 5y ago
That doesn't prevent extraction by someone with supervisor/hypervisor access (so if Elcomsoft can't extract it it's only because they are lazy), it just tries to make it less likely that an attacker can extract it from a locked machine they have physical access to (by rebooting into a boot image of their choice and reading the RAM, the so-called "cold boot" attack).
It's mathematically impossible to prevent key extraction unless you put the key in an HSM (the TPM might function as such, but it may not have good performance) and use that for decryption (the most you can do is make the key larger up to the amount of RAM you have, at the costing of wasting RAM).
Even if you use an HSM, the malware can just extract the data itself or even on-the-fly decrypt the disk with the HSM and re-encrypt with a known key and then exfiltrate the known key, so all this does is make the attack slower since you need to read/write the whole disk.