I suspect similar techniques are still used today, like we see with this tool. If you can get a dump of the computer active memory you can ultimately get the decryption keys on consumer hardware.
I suspect similar techniques are still used today, like we see with this tool. If you can get a dump of the computer active memory you can ultimately get the decryption keys on consumer hardware.
What methods are available to get a memory dump if Firewire is disabled? Feds couldn't break my encryption after ~1.5 years but my devices were all off when they showed up. Ironically the one device they did get into was a cell phone powered on but it had little evidentiary value and in one funny way was partly exculpatory.
All these attacks target decryption keys in memory, so they don't work on devices which are turned off.
E-SATA or PCIe hotplug might still work. However the former is getting less common, and the latter is uncommon in consumer mainboards.
(a) FBI understood truecrypt
(b) the target understood truecrypt
(c) the target misunderstood the entire purpose of truecrypt, and they would misuse it to expose themselves
and (d) the FBI expected this and intentionally blew their cover, leaving the target a chance to destroy the drive.