5 ms·
Actually this applies to "all" other similar encryption technologies and is not limited to mac or firewire. You can also use Thunderbolt, PCMCIA, ExpressCard an
by hukl 15y ago
Actually this applies to "all" other similar encryption technologies and is not limited to mac or firewire. You can also use Thunderbolt, PCMCIA, ExpressCard and even esata ports to have direct access to a computers RAM in which you passphrase is being held.
Basically all ports which use DMA are possible if I remember correctly.
Further reading:
http://en.wikipedia.org/wiki/DMA_attack http://en.wikipedia.org/wiki/DMA_attack
- hukl 15y agoBasically the only "defense" is to shut your computer down when you're leaving it alone / unattended for some time.
- willvarfar 15y agoTurning off the machine can be easily socially engineered around by a determined targeted attacker; all from fire alarms to a visit from IT staff to giving you a free memory stick at a trade show and so on. If you were to be gifted a new USB keyboard tomorrow from some random company, you'd likely accept it unquestioningly. Also, given that you leave your computer unattended, even whilst turned off, gives the attacker opportunity to insert a small device out of sight, rather as cleaners really have done with keyloggers on computers at banks. Isn't when you are present the time when its hardest for them to attack because of the physical contact required? Of course, in films the robber-dressed-as-janitor always manages to walk into the server-room with a tool box.. There are three types of attacker, right? 1) your password/data is valuable, its a targeted attack, the attacker will take the risk of direct access to the machine; they can do this by socially engineering you to insert the trojan hardware, or they can add some small hardware dongle when you don't see or understand 2) law enforcement, they will grab the machine, you'll know they have done so; DMA attack is just a lot more straightforward than freezing it and probing type attacks. 3) those prepared to use a $5 wrench http://xkcd.com/538/ http://xkcd.com/538/
- nodata 15y agoWhy won't disabling features which give easy access to ram work?
- willvarfar 15y agoIt would have to be disabling by omission. I've seen dumb terminals for military networks that simply don't have any slots for any peripherals. Which means staff go to great lengths to work around these limitations and basically open everything up and email documents to their hotmail account so they can print them off elsewhere etc.
- Derbasti 15y agoBecause the point of DMA is to give fast access to RAM without involving the CPU. That is what makes the speed of Firewire or PCMCIA or Thunderbolt or PCIE feasible. Without DMA, these technologies would not work. Also, the password needs to be stored in memory and accessible by DMA, since you would not be able to use it without having it readily available.
- VonLipwig 15y agoI thought things had been like this for a while now. A year ago Wired magazine had a good article about a guy who ran a site buying and selling credit card details and law enforcements attempts to catch him. The computer had full disk encryption which they couldn't touch. Instead they needed to raid the guys house when the computer was on and secure it so the techs could pull what they needed from memory. I didn't think it could be done in under an hour though.
- JoachimSchipper 15y agoActually, the "standard" solution is epoxy ("glue"). ;-)
- CoreDev 15y agoIt should be mentioned that in the past the University of Princeton had successfully extracted encryption keys from a cold booted computer after the PC has been completely turned off. They even demonstrate what they had recovered and how many bits has been lost. Check this page and videos: https://citp.princeton.edu/research/memory/ https://citp.princeton.edu/research/memory/ https://citp.princeton.edu/research/memory/media/ https://citp.princeton.edu/research/memory/media/
- gst 15y agoI use suspend-to-disk which suspends to my encryped swap partition. No need to "shut down" your computer, just don't use suspend-to-ram.
- mike-cardwell 15y agoThere are certainly other defenses. I patched my kernel with TRESOR, so the key for my full disk encryption lives in the debug registers of my CPU and stays out of RAM. The encryption operations are all performed directly on the CPU utilising its AES-NI instructions. So even if you manage to read my RAM, you wont get my full disk encryption key. I wrote up how I did this (and loads of other things) at https://grepular.com/Protecting_a_Laptop_from_Simple_and_Sophisticated_Attacks https://grepular.com/Protecting_a_Laptop_from_Simple_and_Sop... EDIT: Of course, my RAM may contain other compromising data than my encryption key. So yes, I do shut it down when it's not attended, and have disabled firewire etc. Lots of details about other things I've done are at that blog post.
- tonfa 15y agoYou are sure you can do remote DMA with eSATA? I've always thought Firewire was the only consumer product doing it.