Cold boot encryption-bypassing source code published

By Declan McCullagh, CNET News.com
Tuesday, July 22, 2008 10:45 AM

A team of computer scientists has published source code that can in some circumstances bypass encryption used in Microsoft's BitLocker and Apple's FileVault and be used to view the contents of supposedly secure files.

CNET News reported in February on their research, which describes how the contents of a computer's memory could be dumped to a hard drive and the encryption keys forcibly extracted.

The source code includes tools for imaging the target computer's memory through USB and Netboot, and analyzing the memory image to extract AES and RSA encryption keys, even if they're partially degraded. It was published to coincide with the Last HOPE hacker conference over the weekend in New York, where research team member Jacob Appelbaum gave a presentation.

This collection of utilities will be of special interest to security researchers and computer forensics specialists in law enforcement or working for police. (A U.S. Justice Department conference that starts Monday, for instance, includes two panels on computer forensics.) It allows police to seize a computer with an encrypted volume mounted that may be asleep or locked with a screensaver, plug in a UPS, and eventually extract its memory and encryption keys.

If you are worried about this threat or the possibility of nosy border guards rummaging through your files, unmount your encrypted volumes when you're not using them or, better yet, completely power down your computer.

As more people use encryption--FileVault is built into all recent versions of OS X--finding ways to respond to it will become more of a challenge for law enforcement. In December, a U.S. federal judge ruled a man charged with transporting illegal images could not be forced to turn over his PGP pass phrase.

This article was first published as a blog on CNET News.com.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Developing peer-to-peer applications with Jabber

Web Development

Find out how to make use of the Extensible Messaging and Presence Protocol to P2P-enable your applications.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? Let Dr David Scott from Intel take you a for quick tour on developing HPC applications.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajen from Oracle highlights the important considerations ...
    Play video


  • HPC Architecture: Explained

    Why is High Performance Computing increasingly in demand in today's businesses? Find out which is the most widely deployed HPC architecture today.
    Play video

Tags

  1. apple
  2. attack
  3. attacks
  4. botnet
  5. credit
  6. data
  7. dns
  8. facebook
  9. fix
  10. flaw
  11. flaws
  12. fraud
  13. google
  14. iphone
  15. issues
  16. microsoft
  17. patch
  18. researcher
  19. researchers
  20. security
  21. sites
  22. spam
  23. storm
  24. symantec
  25. team
  26. uk
  27. us
  28. users
  29. warns
  30. worm

The business reality of being a S'pore gamer

Blog thumbnail

The Beijing Olympics came to a close last weekend, and Singapore spent much of this week celebrating the nation's lone medal--a silver piece from its women table tennis team. It's..... by Eileen Yu

Read more »