Support us by visiting our sponsors and win a €20 Amazon Voucher every month

Follow maltainfosec on TwitterTwitter or RSS 2.0 feed

Feb 27
A joint group of people from Princeton have recently managed to prove the fact that RAM chips, when cooled to a very low temperature, can continue to retain the contents of RAM for up to several minutes after they have been physically removed from a computer.

The group, then built their own tools and programs to read off the contents of the memory after the computers were rebooted - proving that disk encryption technologies (such as Truecrypt for instance) can be defied. This is demonstrated in a video posted on youtube (see extended body of article)

The concept can also be also easily demonstrated following a simple experiment outlined on the groups page here.

Q. What can users do to protect themselves?
A. The most effective way for users to protect themselves is to fully shut down their computers several minutes before any situation in which the computers’ physical security could be compromised. On most systems, locking the screen or switching to “suspend” or “hibernate” mode does not provide adequate protection. (Exceptions exist; some systems may not be protected even when powered off. Check with the developer of your disk encryption software for further guidance.)


Following up this, according to Ivan Krstic, director of security architecture at OLPC (One Laptop per Child) - the recently announced MacBook Air is resistant to what is now known as the "Cold-Boot Encyption Attack" simply because the machines DDR2 RAM (2gb) is soldered on and cannot be physically removed. In addition, if Apple release an EFI firmware upgrade to zero the contents of the RAM at every boot, then the MacBook
"...would become one of the only—if not the only—mainstream laptop featuring full-disk encryption that's highly-resistant to the troublesome Princeton attack."


(source)

Microsoft also reacts to this vis-a-vis their BitLocker technology in Vista. Ryan Naraine reports on this here.

Microsoft suggests that the most secure method to use BitLocker is in hibernate mode and with multi-factor authentication.
According to Robert Hensing, a software engineer in Microsoft's SWI (Secure Windows Initiative) team, this class of attack is not new and was actually raised at the 2006 Hack in the Box conference in Kuala Lumpur, Malaysia.


The Register
also has their views on this...BitLocker, meet BitUnlocker.

A question directed to Digital Forensic experts - Is this a blessing in disguise? What's your take on it?

Update: More information on the discussion can be found here

Continue reading "Recovering passwords from RAM"

Posted by Donald Tabone

5023 hits
Feb 27


We acclaim another step in the right direction, in line with the scope of http://maltainfosec.org :-)

In a bid to combat cyber exploitation of children, IT Minister Austin Gatt yesterday announced an intensive awareness campaign as students marked Safer Internet Day.

Dr Gatt also launched an information package, which will be distributed to all students from Year Four in primary schools right up to Year Five in secondary schools, as well as their teachers and parents.

Over 43,000 information packages and interactive CDs will start being distributed to parents and students this week, while posters, DVDs and CDs will be circulated in schools.

Attending an event organised by Aġenzija Appoġġ at the Playmobil Funpark in Ħal Far, Dr Gatt said that while children's education was sacred for the government, so was their security.

Echoing a post on the Times of Malta 27th Feb 2008

Posted by Donald Tabone

2918 hits