http://www.schneier.com/blog/archives/2012/08/an_analysis_of...
Paper here:
http://eprint.iacr.org/2012/374.pdf
Currently, there seem to be three vectors:
1) Weak passwords
2) If you opt-in to store a recovery key with Apple
3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thunderbolt or Firewire) (Edit: seems like this is not the case, see below)
But no backdoor has been found (yet!)
I'm curious if this could be addressed with software protections somehow? Something that triggers memory wipes and automatic shutdowns?
Though that specifically obviously requires hardware.
* Source http://security.stackexchange.com/questions/18720/how-secure...
> If you enable LUKS root, DMA attack mitigation is also enabled(boot.initrd.luks.mitigateDMAAttacks ). It consists of blacklisting firewire drivers.
Edit: still at risk of the "Evil Maid Attack" http://www.aspecrypt.com/evil_maid_attack.html
3) If attacker has physical access to machine, and
machine is powered on (direct memory access via
Thunderbolt or Firewire)
This may have changed, but turning on FileVault used to disable DMA in many situations (laptop had been suspended being a key one) until the user logged back in. Not that this isn't a vector, but it's actually a very narrow one; you basically need the person to already be logged in at the time you want to steal the keys.http://www.frameloss.org/wp-content/uploads/2011/09/Lion-Mem...
Though apparently there was a company offering a commercial solution for getting FileVault passwords using this method so...
http://privacycast.com/filevault-vulnerability-how-to-protec...
There's also a really interesting pdf from Apple containing more details on FileVault 2:
http://training.apple.com/pdf/WP_FileVault2.pdf
which suggests turning on firmware passwords to prevent DMA.
He specifically mentions he could access the FileVault key of a machine by having physical access, and discovered two secret keys (KPPW and KPST) one of which is enabled when the input buffer is "SpecialisRevelio" [2].
It's a very interesting deck to read through.
[1] http://www.nosuchcon.org/talks/D1_02_Alex_Ninjas_and_Harry_P... [2] http://harrypotter.wikia.com/wiki/Specialis_Revelio
FileVault could be some hypothetical magic uncrackable encryption with a keyspace bigger than the known universe...and it would never matter if there was a backdoor in the OS.
If you want your data to be reasonably secure against someone who casually steals it then they're fine but if you want to be secure against government employees, or even well connected corporations, then Apple & Microsoft solutions are not very useful.
[1] https://en.wikipedia.org/wiki/NSAKEY [2] http://news.cnet.com/8301-13578_3-57583843-38/apple-deluged-...
[3] http://www.informationweek.com/security/encryption/apple-iph...
Edit : the site seems to have some difficulties, here's the google cache http://webcache.googleusercontent.com/search?q=cache:JZEtYXR... The description of the decryption suite is in the module tab.
You can find the Torrent at Wikileaks: https://wikileaks.org/wiki/Microsoft_COFEE_%28Computer_Onlin...
[1] https://en.wikipedia.org/wiki/Computer_Online_Forensic_Evide...
2) It provides Apple a fallback when some idiot loses 6 figures worth of IP. “We understand sir, you see, if you had chosen to backup your recovery key with us we would be able to help you”
* or would be, if the NSA wasn't spying on everything.
And if you want to be safe from the government, just select "No".