3 ms·
2. "with the cryogenic RAM freezing technique, presumably" - errr, no. With the "sit down at the computer and turn off the encryption/copy the data to an ex
by pjin 15y ago
2. "with the cryogenic RAM freezing technique, presumably"
- errr, no. With the "sit down at the computer and turn off
the encryption/copy the data to an external drive
technique", I think you'll find. Obvious bullsh*t to anyone
technical but sounds 'cool' to your average 14yr old who
reads these sort of sites.
Errr, actually yes. You may be interested in [1] and [2].
[1] http://citp.princeton.edu/pub/coldboot.pdf http://citp.princeton.edu/pub/coldboot.pdf
[2] http://www.youtube.com/watch?v=JDaicPIgn9U http://www.youtube.com/watch?v=JDaicPIgn9U
- jeffreyg 15y agoI'm assuming he was mocking the ignorance of the article as it addressed live memory acquisition. The author jumped to something obscure (RAM freezing) when there are forensics tools (memorize, etc) that can be used to image memory on a running machine in hopes of getting a decryption key / other passwords.
- wmf 15y agoOr even easier: if the encrypted drive is mounted, just use cp (or the overpriced forensic equivalent). Cold boot attacks are sci-fi.
- tjoff 15y agoAre you guys saying that a person that use full disc encryption doesn't lock the computer when leaving it?
- DasIch 15y agoUnless you are in the same room as the computer I'd consider it rather unlikely that you will be able to turn it off in case of a raid.
- IgorPartola 15y agoThere are lots of ways to overcome that as well. For one, you could set up your computer such that if you don't enter some key combination every minute it shuts down. Or you could set up a tricky kernel that does not allow opening/cp'ing certain files and if you try, triggers a shutdown. Or you could have speech recognition running, and as soon as you utter a certain phrase near your machine, it shuts down. The point is that inaction or inadvertent action by the law enforcement may trigger an action on the machine. Such digital landmines could be made so unpredictable that there would be virtually no way to extract the data on site reliably. In general, there is no solution to this problem. The person protecting their data will always be able to surprise the person that's trying to extract it. Furthermore, no government can control "manufacture" of encryption, the way that it can control manufacture of physical goods. It could mandate that a backdoor must be provided, or that you need to escrow your decryption key such that it could get at your data, but let's face it: people that do have something sinister to hide will not care much for this regulation anyways.
- marshray 15y agoPlug in a USB device that feeds Windows a signed device driver.
- shabble 15y agoThere are other fun ways for your SWAT-team evidence seizure grunts to grab machines without powering them off, such as http://www.wiebetech.com/products/HotPlug.php http://www.wiebetech.com/products/HotPlug.php -- a big UPS with connectors specially designed for vampire-tapping a live PSU lead.
- alexhawdon 15y agoHrm... I was aware of the research but thought it was just a proof-of-concept; didn't realise it was quite that polished. Even still, I would doubt whether or not your average digital forensic investigator would be using such esoteric techniques. Most of the stuff they do is pretty routine using off-the-shelf products like EnCase. Thankfully, for the rest of us law-abiding citizens, your average criminal is pretty thick and therefore the level of sophistication required to catch them isn't that high.