TRESOR Runs Encryption Securely Outside RAM
www1.informatik.uni-erlangen.de
www1.informatik.uni-erlangen.de
The German government believes that the TPM is backdoored and a danger to security[2].
1: http://www.nytimes.com/interactive/2013/09/05/us/documents-r...
2: http://www.techweekeurope.co.uk/news/microsoft-seeks-calm-on...
Long term I suspect that this kind of thing will use Intel's Software Guard Extensions (SGX), which creates a trusted enclave of code and data that not even the kernel nor the hypervisor can access.
http://theinvisiblethings.blogspot.co.uk/2013/08/thoughts-on...
http://theinvisiblethings.blogspot.co.uk/2013/09/thoughts-on...
We're working on solving the malicious device and cold boot problem at PrivateCore. To do so, we're encrypting all of main memory and keeping plaintext state in the L3 cache.
Here's a resource page with links to the TRESOR paper and other resources: http://privatecore.com/resources-overview/physical-memory-at...
Or are you expecting us to trust your proprietary nonfree software without ever seeing it?
Good luck with that.
http://www1.cs.fau.de/filepool/projects/coldboot/fares_coldb...
Even with cooling they weren't able to recover. However, a warm reboot, would still work. Speculating, but some laptops might have a way to force a reboot like some machines have a reset button. That'd at least restart the system, although proper BIOS config should prevent that from being useful.
any idea if work has been done on cryogenic temperatures?
Also what happens if the scheduler moves the application out of running state?
We gave a talk on some of the vulnerabilities and mitigations at CanSecWest this year: http://cansecwest.com/slides/2013/PrivateCore%20CSW%202013.p...
The attacker/thief cools down the RAM with liquid nitrogen (to slow the discharge), inserts a bootable CD with a special tool to dump physical RAM on bootup, and quickly cycles the laptop battery (causing a cold boot).
Since the RAM is not zeroed on bootup, the "old" bits stay pretty much as they were (thanks to the cooling).
IIRC this allowed an attacker recovery of the key with a very high probability of success.
If someone is after me who is using this methodology then I have seriously pissed off the wrong people. While you could argue that it's only paranoia if the object of preparation is not possible, I would say that you're at least one leg over the fence into paranoia-land if you're prepping against a cold-boot and don't have any nation state or corporate espionage level enemies.
destroyfvkeyonstandby - Destroy File Vault Key when going
to standby mode. By default File vault keys are retained
even when system goes to standby. If the keys are
destroyed, user will be prompted to enter the password
while coming out of standby mode.(value: 1 - Destroy, 0 -
Retain)[0]http://www.nosuchcon.org/talks/D1_02_Alex_Ninjas_and_Harry_P...
Of course, since FileVault is not open source, we have no way of knowing if it does this. Is this paranoid? Perhaps, but if you are worried about cold boot attacks you should be worried about this as well.
You might also be worried about some strange design decisions in FileVault such as the fact that it uses public key cryptography[0] for what ought to just be symmetric disk encryption. While not a red flag,it is a bit strange.
[0]http://deimos3.apple.com/WebObjects/Core.woa/FeedEnclosure/u...
The idea that your full disk encryption is only safe so long as nobody manages to have such outlandishly difficult to acquire materials is rather disheartening.
Moreover, disk encryption systems aren't just designed for overly paranoid individuals who probably don't have anything more interesting on their drive than embarrassing porn, it's also targeted for people who have data they seriously want to keep from being divulged. A perfect example being a running, but locked, corporate laptop being stolen from an office building or even a public space (e.g. a coffee shop). Someone desiring to commit industrial espionage would have no difficulties whatsoever in pulling off a cold boot attack on a vulnerable system, even if liquid nitrogen was required (it's quite easy to obtain and fairly cheap).
The intersection of people vulnerable to cold boot attacks and people likely to be victims of cold boot attacks is hopefully the empty set.
The RAM can be accessed using a DMA malware from the GPU/NIC/Intel ME or other devices which have a (micro-)processor and can use DMA [1, just submitted].
I just wanted to say that keeping the decryption keys out of RAM and Disks is not that paranoid because there are techniques which allow extraction of data from the RAM: cold boot, ordinary malware/rootkits, DMA malware.
There are also some implementation vulnerabilities in specific OSes which are not yet publicly disclosed.
Error
The website encountered an unexpected error. Please try again later.
Error message
PDOException: SQLSTATE[HY000] [2002] Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (111) in lock_may_be_available() (line 167 of /var/www/i1/includes/lock.inc).
It looks as Drupal is not suited to stand a HN-DDoS, of 70 points (7000 visitors estimate) in 3 hours.