Show HN: Simple demo of a cold boot attack using a Raspberry Pi
github.com
github.com
With the freeze spray I did also manage to unplug the power cable completely and switch SD cards manually.
Edit: In "Cold Boot Attacks are Still Hot: Security Analysis of Memory Scramblers in Modern Processors" they say "To assess the feasibility of cold boot attacks on today’s denser and smaller components, we measured the retention time of five DDR3 and two DDR4 modules from various manufacturers. At normal operating temperatures, a significant fraction of the data is lost within 3 seconds of losing power."
The Pi 4 I used makes use of DDR4 from what I recall.
In practice, however, most electronics is fine (!) with the right materials – even a relatively bog-standard gaming CPU [1]...
[1] https://www.youtube.com/results?search_query=ln2+overclockin...
I would not expect "residual power" to last for 0.75 seconds. Even if it did, RAM has to actively be refreshed by the memory controller. (DDR self-refresh is only enabled during sleep and I dunno if the Pi even supports that)
Cryptographers worry even when a few key bits are leaked.
Can you elaborate a bit? Off the top of my head, I feel like that scenario would leave 128-choose-8 possibilities open, or about 1.4 trillion. Are we calling that "trivial" or am I misunderstanding the attack?
(If you're calling that "trivial", I think that could be reasonable in a cryptography context where you're considering attackers with a lot of resources. It's just different from how I usually use that word. I don't disagree with your conclusion that leakage of even a few bits is worth worrying about.)
That only amounts to log2(C(128, 8)) ~= 40.3.
Your encryption key is now just 40-bit strength.
Posting a secret key here and specifying "exactly one bit was flipped" reduces the problem to N guesses where N is the key length since you know all the other N - 1 bits are correct. Leaking just a few bits has catastrophic consequences, in your example all bits except one are leaked.
Is it possible to determine that this has happened though? If you're trying to recover an image and a bunch of bits are flipped, the result might be somewhat corrupted but a coherent image will still be visible. You know that the data was corrupted and where the damage is. Ciphers have avalanche effects, a single bit flip produces completely unusable output which by design reveals no information.
All that is to say, yes, this is a viable attack vector, even if some or many of the bits are flipped
It's something I'd like to try too. Good point re. the temperature also, I bought a PT100 temperature probe I need to use to measure the surface temperature of the RAM chip too.
* Control physical access: don’t allow an attacker access to the DRAM chips.
* Control logical access: use trusted boot systems which don’t allow an attacker to dump arbitrary memory, combined with physical access control so they can’t directly address memory externally.