http://news.cnet.com/8301-13578_3-9876060-38.html
The paper referenced is available at:
http://citp.princeton.edu/pub/coldboot.pdf
From that paper, the most salient sentence for this discussion is:
"On all of our sample DRAMs, the decay rates were low enough that an attacker who cut power for 60 seconds would recover 99.9% of bits correctly."
The long and short is that your password has to be in RAM at some point in order to be matched against what is typed in. RAM decays slowly after a machine has been switched off. As the research shows, one can use a widely-available can of air to make that decay happen even slower. In the process, one can pull the value out of RAM.
Note that this is a hardware problem that no software on the market has been able to address. To do so, you would have to be able to validate x against y without having the value of y ever enter RAM.
Consequently, a reasonably good tech thief can read the password out of RAM. For the not-so-good tech thief, using passwords and social engineering tricks like being nice to someone and then asking them to watch your stuff for a moment will probably do the trick. I tend to see the various implementations of full-disk encryption as more for peace of mind and mitigation of liability than real security.