5 ms·
Sure, the key files won't be on the computer, but the decryption key must necessarily be resident in RAM or otherwise accessible by the CPU (in a register, suc
by SageRaven 14y ago
Sure, the key files won't be on the computer, but the decryption key must necessarily be resident in RAM or otherwise accessible by the CPU (in a register, such as with TRESOR mentioned elsewhere) to encrypt/decrypt disk blocks of a running system.
- drucken 14y agoMy point is that there are security products with configurations where the keys are cleared from RAM when the system is not running (including hibernation modes). Therefore, in those configurations they are at most only vulnerable while they are running. Used in that way, this greatly mitigates the risks mentioned in the article.