3 ms·
TRESOR only helps against passive attacks since since the code is still exposed in memory. Active attacks that modify memory can easily circumvent it.
by sweis 13y ago
TRESOR only helps against passive attacks since since the code is still exposed in memory. Active attacks that modify memory can easily circumvent it.
- aryastark 13y agoNot sure what you mean. TRESOR prevents cold boot attacks. If your Linux OS is compromised, TRESOR wouldn't help you anyway. But that's not the point of it, either.
- sweis 13y agoYes, TRESOR can help against cold boot attacks, which are passive and read-only. Several physical attack vectors can modify the contents of memory, thus compromise the software stack and divulge keys kept in registers or cache. Our approach at PrivateCore is to fully encrypt main memory with an authenticated cipher mode and keep the software stack pinned in cache. An attacker able to physically modify memory can only conduct a DoS attack by inserting junk data.