ohohlfeld.com : blog
Ohohlfeld.com Banner

When a machine only slowly forgets – Exploiting TrueCrypt et al.

February 24, 2008

Filed under: papers, research — Oliver @ 10:43 pm

Researchers at Princeton university have released a highly interesting paper on Thursday, which demonstrates that DRAM contents are not immediately lost when the system is turned off. Their paper shows how this property can be used to exploit state-of-the-art hard drive encryption tools, such as TrueCrypt, when the attacker gets physical access to the machine.

The root of the problem lies in an unexpected property of today’s DRAM memories. DRAMs are the main memory chips used to store data while the system is running. Virtually everybody, including experts, will tell you that DRAM contents are lost when you turn off the power. But this isn’t so. Our research shows that data in DRAM actually fades out gradually over a period of seconds to minutes, enabling an attacker to read the full contents of memory by cutting power and then rebooting into a malicious operating system. (…) This is deadly for disk encryption products because they rely on keeping master decryption keys in DRAM. This was thought to be safe because the operating system would keep any malicious programs from accessing the keys in memory, and there was no way to get rid of the operating system without cutting power to the machine, which “everybody knew” would cause the keys to be erased. (Source)

Further information, including images and videos as well as a experimental guide to quickly reproduce these results using Linux, can be found here.

No Comments »

No comments yet.

RSS feed for comments on this post. TrackBack URL

Leave a comment

CAPTCHA image

© 2001-2008 by Oliver Hohlfeld, M.Sc. | Imprint

Send me mail to my E-Mail address:
ty0ode5ndy@tntler.de
ty0ode5ndy@abc.thomas-graf.de
ty0ode5ndy@abc.ohohlfeld.com

nyantakyi.savoulidou@namesp.ohohlfeld.com
max.mustermann@namensp.ohohlfeld.com

Send me mail to my E-Mail address:
tq5nje4ndy@tntler.de
tq5nje4ndy@abc.ohohlfeld.com
tq5nje4ndy@abc.thomas-graf.de

Send me mail to my E-Mail address:
dcwmzq2mdq [at] tntler [dot] de
dcwmzq2mdq [at] abc.ohohlfeld [dot] com
dcwmzq2mdq [at] abc.thomas-graf [dot] de

Send me mail to my E-Mail address:
EMail EMail EMail

Name: e-mail: Subject: Message:

Leave a comment

hurije.polonis
hurije.polonis
hurije.polonis
My Super Secret Homepage

Warning: stristr() [function.stristr]: Empty delimiter. in /home/oliver/public_html/ohcomblog/wp-content/plugins/wassup/wassup.php on line 2093