6 ms·
This is utterly fascinating. I use TrueCrypt and never dreamt that such a simple attack even existed. Sigh - privacy in the age of information seems to be an i
by visitor4rmindia 17y ago
This is utterly fascinating. I use TrueCrypt and never dreamt that such a simple attack even existed.
Sigh - privacy in the age of information seems to be an impossible dream.
- atamyrat 17y agoMy laptop's BIOS settings are password protected. Good luck with booting from CD/USB/Network without hardware tampering.
- idlewords 17y agoAs the article points out, this is easy to circumvent by removing the hard drive from your laptop. It adds a few minutes to the attack, and requires that the attacker bring a laptop, but you're still hosed.
- timf 17y agoNot my hard drive, the disk itself is fully encrypted and won't work in other laptops without that bios password (I also use a truecrypt-like thing at the filesystem level). The main attack I need to worry about is someone replacing the keyboard, etc.
- Nekojoe 17y agoWhen you get to that level of protection, the main attack I'd be worried about is the $5 wrench. http://xkcd.com/538/ http://xkcd.com/538/ Of course as the strip also points out "Actual actual reality: nobody cares about his secrets"
- timf 17y agoVery true, funny :-) At least with truecrypt you can give them only one of the passwords (it can do that secret "deniable" encrypted partition).
- pmorici 17y agoWhat laptop / HD combination does that, or rather how can I tell if mine supports it?
- hmmmm 17y agoMost corporate laptops support it, IBM/Leonova do. The problem is how do you know there isn't a master password (for AMI's bios it used to be "AMIBIOS") how do you know their encryption is any good (there was an enterprise tape vendor that advertised DES encryption but actually just XORed the data with your password) And finally how do you know they haven't done exactly the same trick but replaced your bios with one that includes a keylogger?
- wizard_2 17y agoAre you using a hard drive password? Those are easily crackable as well as they usually have a vendor supplied master password. Do you mind giving more details?
- timf 17y agohttp://www.thinkwiki.org/wiki/Full_Disk_Encryption_%28FDE%29 http://www.thinkwiki.org/wiki/Full_Disk_Encryption_%28FDE%29
- eli 17y agoUnless you've got a very special sort of BIOS, those passwords aren't very strong. And I'd probably just use a keylogger.
- mahmud 17y ago"There are two types of encryption: one that will prevent your sister from reading your diary and one that will prevent your government." -- Bruce Schneier. Addendum: "Provided it's implemented well".
- tetha 17y agohehe, and then, one realizes that the government might recruit your sister and the dilemma is perfect.
- visitor4rmindia 17y agoDoesn't the OP sort of invalidate this? Any government should find it reasonably easy to install this kind of a keylogger on your computer. It would be quite easy to get a few minutes alone with your laptop.
- mcav 17y ago> Sigh - privacy in the age of information seems to be an impossible dream. Well, it's better than before: Non-electronic documents are arguably much easier to steal. At least with encryption, breaking into your house isn't necessarily enough to get your data.