billso.com

Bill Sodeman writes about management, mobile computing and information systems

billso.com header image 2

Researchers develop simple attack against disk encryption

ism tech

Posted Thursday, 21 February 2008, 10:52 HST @828

From BoingBoing comes the most disturbing information security news I have read in a while.

We’ve long assumed that disk encryption is a robust means of storing confidential data on a computer. Disk encryption products work by encrypting all of the data on a drive, including documents, the operating system, swap files and caches. Disk encryption software can start up before the operating system to let the user enter their password or key. Disk encryption software can also be used on USB storage, as well as partitions on an unencrypted drive.

Disk encryption helps travelers keep their data confidential. My post of 5 Janaury 2008 addresses how cryptography works.

Warm RAM, lost key

Princeton University researchers have developed a simple attack that can retrieve the BitLocker disk encryption key from a Windows Vista computer. The user has to have logged into the computer so that the encryption key is then stored in the computer’s RAM. If the computer is in sleep mode, running a screen saver, or still warm, the encryption key can be extracted from RAM. The extracted data can be saved to a USB storage device, so that another computer can take its time to analyze and fix any errors in the extracted key.

The same kind of attack will also work on Apple FileVault, TrueCrypt, PGP Whole Disk Encryption, and other disk encryption products. The research report is available as a PDF file at this web site.

Declan McCullagh has posted his analysis of the report at news.com. he points out that this vulnerability has been used by other researchers to pull data through a FireWire connection to an iPod. It is difficult to harden a computer against this form of attack, but the attack must be carried out in person. It cannot be done across the Internet, at least in the form that the researchers demonstrate. The attacker needs a USB drive preloaded with the attack software. A can of Dust-Off might also be helpful, to chill the RAM.

Watch that drive

The easiest way to harden a computer against this attack is to maintain physical control of the encrypted drive. Don’t leave it alone. Update the encryption software regularly, as the software developers will more than likely develop their own patches to wipe the key from RAM.
This YouTube video produced by the research team is a brief overview of the vulnerability and the attack.

YouTube Preview Image Tags: crime, crypto, hardware, iPod, Microsoft, security, software, storage, USB, Windows
Print This Print This

3 responses so far ↓

  • 1 billsoNo Gravatar // Friday, 22 February 2008, 09:18 HST @762

    Here’s an article about this topic from the New York Times

  • 2 billsoNo Gravatar // Thursday, 28 February 2008, 14:01 HST @959

    Glenn Fleishman of TidBITS has posted a long article about this issue.

  • 3 billsoNo Gravatar // Thursday, 28 February 2008, 15:11 HST @008

    According to news.com via BoingBoing, the flaw in Mac software has been confirmed by Apple. Macs are just as vulnerable as the Windows Vista computers discussed in the YouTube video above.

    But Apple has not announced a patch yet.

    Maybe after TED is done, eh? I’m waiting.

Leave a Comment

What is this?