Retrieving encryption key from memory
Researchers from Princeton University have developed a technique to defeat disk encryption (vaults) on hard disks - by retriving the encryption keys from memory. The idea is, an attacker, after gaining physical access of the hardware, can pull the RAM out and scan it for encryption keys.
While I am impressed by them being able to figure out where in memory is that supposedly random encryption key, retrieving data from RAM doesn't sound like a break through to me. They talk about freezing the memory chip so as to slow down data decay... well, how about sustaining it by powering it up with an external power source instead. Besides, they claim that the data will disappear after 10 minutes after power down - that doesn't sound like a lot of time between me forgetting my laptop and the attacker picking it up, running over to a hidden room, pry open the casing, grab the can of compressed air, pull the chip, somehow get to another computer that has the memory scanning software.
The most suprising part is, they couldn't get themselves a female narrator (notice they've resorted to a computer voice). What a bunch of nerds. I wonder if their lab is in the basement.
Labels: security
0 Comments:
Post a Comment
<< Home