AES Finder – the utility to find AES keys in running process memory
github.com
github.com
Stuff like this always reminds me of that guy (haven't seen him in decades, sadly). Oh, you used AES encryption? That's lovely, but your computer knows the key and I can trick it into telling me it.
Truecrypt likely changed the game on some of the claims he made, but that conversations predated it's existence.
Today the angle of attack seems to be around OTP + Password with a timeout on the credentials generated. It narrows the window, but doesn't completely block it.
I suspect similar techniques are still used today, like we see with this tool. If you can get a dump of the computer active memory you can ultimately get the decryption keys on consumer hardware.
What methods are available to get a memory dump if Firewire is disabled? Feds couldn't break my encryption after ~1.5 years but my devices were all off when they showed up. Ironically the one device they did get into was a cell phone powered on but it had little evidentiary value and in one funny way was partly exculpatory.
All these attacks target decryption keys in memory, so they don't work on devices which are turned off.
E-SATA or PCIe hotplug might still work. However the former is getting less common, and the latter is uncommon in consumer mainboards.
(a) FBI understood truecrypt
(b) the target understood truecrypt
(c) the target misunderstood the entire purpose of truecrypt, and they would misuse it to expose themselves
and (d) the FBI expected this and intentionally blew their cover, leaving the target a chance to destroy the drive.
I had this new Symbian phone with Bluetooth (2?) and there was an app you could get for OS X that would lock your machine when it lost BT signal.
Sub in a larger battery (still one of my favorite mini hacks, removing a little plastic so the 30% bigger Ngage battery would fit) and I was good to go, until the app stopped working.
Big part of why I bought an Apple Watch (and then keep forgetting to set it up)
The badge had to be inserted into a reader for the computer to be unlocked. It was also attached (via a badge holder) to the RFID badge needed to open any locked doors. This meant that to get to and go to the washroom, I had to take my badge out, which locked the computer.
It was a very neat and secure system.
[1]: https://github.com/MantechUser/aes-finder/blob/master/aes-fi... [2]: https://en.wikipedia.org/wiki/AES_key_schedule
E.g. look for a byte swapped AES key schedule in dropbox process memory and you should find its sqlite3 encryption key.
The problem is predictability of the layout, right? The layout is chosen for throughput, but CPU caches can cope well with some nonlinear layouts.
Processes could conceivably put keys in memory in a non-standard way that is more difficult to write a tool to scan for, but the fact that they don't is not a problem, and even if they did it would not make it impossible to write a tool.
It stores keys in privileged registers.
https://github.com/mmozeiko/aes-finder
Unless there’s some newsworthy aspect to the child repo being a special different fork.
Says "Improved cross platform capability, key dumping, memory dump search." but it's not even new code so nm comment on it.
Says "Improved cross platform capability, key dumping, memory dump search." but it's not even new code so nm to comment on it.
<shrug emoji>
https://github.com/simsong/bulk_extractor/blob/master/src/sc...
I believe I also saw that talk at a CCC camp back then.
Edit: ah yes, here it is: https://media.ccc.de/v/cccamp07-en-2002-Cryptographic_key_re...