Support us by visiting our sponsors and win a €20 Amazon Voucher every month

Follow maltainfosec on TwitterTwitter or RSS 2.0 feed

Feb 27
A joint group of people from Princeton have recently managed to prove the fact that RAM chips, when cooled to a very low temperature, can continue to retain the contents of RAM for up to several minutes after they have been physically removed from a computer.

The group, then built their own tools and programs to read off the contents of the memory after the computers were rebooted - proving that disk encryption technologies (such as Truecrypt for instance) can be defied. This is demonstrated in a video posted on youtube (see extended body of article)

The concept can also be also easily demonstrated following a simple experiment outlined on the groups page here.

Q. What can users do to protect themselves?
A. The most effective way for users to protect themselves is to fully shut down their computers several minutes before any situation in which the computers’ physical security could be compromised. On most systems, locking the screen or switching to “suspend” or “hibernate” mode does not provide adequate protection. (Exceptions exist; some systems may not be protected even when powered off. Check with the developer of your disk encryption software for further guidance.)


Following up this, according to Ivan Krstic, director of security architecture at OLPC (One Laptop per Child) - the recently announced MacBook Air is resistant to what is now known as the "Cold-Boot Encyption Attack" simply because the machines DDR2 RAM (2gb) is soldered on and cannot be physically removed. In addition, if Apple release an EFI firmware upgrade to zero the contents of the RAM at every boot, then the MacBook
"...would become one of the only—if not the only—mainstream laptop featuring full-disk encryption that's highly-resistant to the troublesome Princeton attack."


(source)

Microsoft also reacts to this vis-a-vis their BitLocker technology in Vista. Ryan Naraine reports on this here.

Microsoft suggests that the most secure method to use BitLocker is in hibernate mode and with multi-factor authentication.
According to Robert Hensing, a software engineer in Microsoft's SWI (Secure Windows Initiative) team, this class of attack is not new and was actually raised at the 2006 Hack in the Box conference in Kuala Lumpur, Malaysia.


The Register
also has their views on this...BitLocker, meet BitUnlocker.

A question directed to Digital Forensic experts - Is this a blessing in disguise? What's your take on it?

Update: More information on the discussion can be found here

Continue reading "Recovering passwords from RAM"

Posted by Donald Tabone

5023 hits
Feb 27


We acclaim another step in the right direction, in line with the scope of http://maltainfosec.org :-)

In a bid to combat cyber exploitation of children, IT Minister Austin Gatt yesterday announced an intensive awareness campaign as students marked Safer Internet Day.

Dr Gatt also launched an information package, which will be distributed to all students from Year Four in primary schools right up to Year Five in secondary schools, as well as their teachers and parents.

Over 43,000 information packages and interactive CDs will start being distributed to parents and students this week, while posters, DVDs and CDs will be circulated in schools.

Attending an event organised by Aġenzija Appoġġ at the Playmobil Funpark in Ħal Far, Dr Gatt said that while children's education was sacred for the government, so was their security.

Echoing a post on the Times of Malta 27th Feb 2008

Posted by Donald Tabone

2918 hits
Feb 14

Valentine’s Day isn’t stopping controllers of the Storm Trojan from using the holiday theme to trick users into downloading the malware.

Continue reading "Happy Valentine’s Day from: The Storm Trojan"

Posted by

4479 hits
Feb 13
On February 1st, 2008 Microsoft offered $44.6 billion for Yahoo. A truly desperate attempt to catch Google.

Source: http://eatliver.com/i.php?n=2801

:-)

Posted by Donald Tabone

9414 hits
Feb 7
As reported on MaltaMedia Dec 27,2007

In June 2005 Malta, as a Beneficiary Country, signed a Twinning Agreement entitled Capacity Building Programme in Information Security with the United Kingdom, as a European Union Member State for a period of 28 months.

The project implementation was entrusted to Malta Information Technology and Training Services Ltd (MITTS Ltd) as the Government’s designated INFOSEC Authority under the direction and guidance from the Ministry for Investment, Industry and Information Technology (MIIIT). The UK Twinning Partner was entrusted to Northern Ireland Public Sector Enterprises (NI-CO) in conjunction with QinetiQ Ltd which is an international defence and security company.
The purpose of this Twinning Agreement was to increase the understanding and facilitate the implementation of the EU Council Security Regulations 2001/264/EC issued on the 19th of March 2001 and to support Information Security measures in the Government of Malta Public Service to enable adherence to these regulations, which is a compulsory condition for all the Member States and thus of the Acquis Communautaire. In this light the project saw to the basic, advanced and specialised training of officials in the Public Service, government agencies and entities in particular areas related to Network Security, Wireless Security and Digital Forensics.

Study visits were organised for Maltese personnel to travel to various European countries to view operational security processes in practice with the aim of sharing good practices and acquire knowledge from other EU Member States.

The Twinning Agreement came to an end in October 2007 and has been mainly financed by the European Union.

The full article can be read here.

Posted by Donald Tabone

3299 hits
Feb 5

Have you been ever scammed on eBay? If so, read on...

Ask eBay users about auction fraud and payment scams, and you'll hear different stories with the same theme: While eBay can be a great marketplace, both buyers and sellers need to beware.

Continue reading "How to buy and sell on eBay scam-free"

Posted by Donald Tabone

9218 hits
Feb 5
For those of you wondering what the title is on about, I invite you download this PDF presentation (E. H. Spafford 2001, 2002) and you'll know exactly what it refers to.

Albeit rather outdated, this 26 page presentation by the Center for Education and Research in Information Assurance and Security (CERIAS) talks about valid myths and misconceptions that these days still surround us.

After presenting a (humorous) pictorial time-line of the evolution of computers, he talks some of the causes of security problems, followed by their effect and a bunch of myths that we somehow are lead to believe. In that so, he then continues to explain the reality of things the way they actually are.

How about security expertise? Spafford again shows us the reality of things amidst general misconceptions that continue to float around us.

Still valid today --- Spafford concludes with the following points which we acclaim

- Security is an unattainable absolute.
- We should be seeking high levels of trust, based on sound methods of assurance.
- Assurance is an on-going process, not a set of add-on features.


Like I very often like to evangalise during security awareness sessions I hold from time-to-time, hopefully we are now a bit more aware that...

- Security is not simple.
- Security is not an add-on.
- Quality and security are closely linked.
- Training and knowledge are critical to counter superstition and folklore … but trends and lack of resources mean we are likely to face many challenges.

Posted by Donald Tabone

2855 hits