Monday | 8 September, 2008
Computerworld
'Cold Boot' encryption hack unlikely, says Microsoft
But Vista users can take steps to protect against the eventuality
Gregg Keizer 27/02/2008 11:19:42

Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Users can keep thieves from stealing encrypted data by changing some settings in Windows, a Microsoft product manager said as he downplayed the threat posed by new research that shows how attackers can inspect a "ghost" of computer memory.

Russ Humphries, a senior product manager for Windows Vista security, reacted Friday to reports last week about a new low-tech technique that could be used to lift the encryption key used by Vista's BitLocker or Mac OS X's FileVault. Once an attacker has the key, of course, he could easily access the data locked away on an encrypted drive.

The method -- dubbed "Cold Boot" because criminals can boost their chances by cooling down the computer's memory with compressed gas or even liquid nitrogen -- relies on the fact that data doesn't disappear instantly when a system is turned off or enters "sleep" mode. Instead, the bits stored in memory chips decay slowly, relatively speaking.

Cooling down memory to -58 degrees Fahrenheit (-50 degrees Celsius) would give attackers as long as 10 minutes to examine the contents of memory, said the researchers from Princeton University, the Electronic Frontier Foundation and Wind River Systems. And when they pushed the envelope and submersed the memory in liquid nitrogen to bring the temperature down to -310 degrees Fahrenheit (-190 degrees Celsius), researchers saw just 0.17% data decay after an hour.

The whole thing is unlikely, Humphries argued in a post to the Vista security team's blog. To make his case, he ticked off several preconditions:

-- The attacker would have to have physical access to the machine.

-- The laptop would likely have to be in "sleep" mode, rather than in "hibernate" mode or powered off.

-- The person who finds/steals the laptop must be knowledgeable and interested enough to execute the attack.

"I would posit that the opportunistic laptop thief is somewhat unlikely to carry a separate laptop on which they will have installed tools that allow them to reconstruct cryptographic keys, or for that matter have a can of compressed air handy," said Humphries.

Computerworld Buyer's Guide - Vendors Matched to this Article
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

Unified Communications: Justifications and Predictions

Building a business case for Unified Communications is currently more of an art than a science. However, the difficulty of building a business case for UC does not mean that there is none - just that we need to view (and measure) UC's benefits in accordance with the stage of maturity of the technology's adoption. Read on to find out more.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links