https://news.ycombinator.com/item?id=7113788
A couple years ago, I chased down and tackled a guy who snatched my laptop on the Blue Line in Chicago. The threat of laptop theft is real and I'd like to mitigate the damage that would result without compromising my ability to work.
If other ports are exposed that offer DMA capabilities, then they need to be disabled. Don't load the drivers/epoxy the physical ports.
I was not aware that a new connector would reopen such a massive vulnerability. (Docking ports may also have some issue, but since they're proprietary it wouldn't matter.)
That said, I think my assessment is still accurate. If you're just worried about a theft, it seems very unlikely they'd run these kinds of tools before restarting. And even then, why bother? Why not just reformat the machine, if it's just a theft? If you have actual enemies "then keep your laptop physically secured and powered off. And don't use it after breaking chain of custody."
The really shitty thing is that some new laptops (W540) apparently don't ship DisplayPort or other digital video, but just Thunderbolt.
And yes, me, a not particularly security-oriented guy, did this fairly quickly as a demonstration for coworkers. It required only marginally more than script kiddie levels of knowledge.
I suspect without a Yubikey or Microsoft TPM, effectively storing the key outside of RAM, there's not much that can be done to fight this. And of course, physical access means you've got the TPM or Yubikey in front of you. And unencrypted data in RAM. So.... Yeah.
Not sure why these techniques aren't mainstream yet.
As most (if not all) disk encryption programs store an expanded version of the key in memory, there is significant redundancy to recover from the partially lost data.
Has anybody ever did this to someone?
Outside of Bond movies?
A few years ago, I tried this on my own laptop. I didn't have any sort of full disk encryption to test against, so I simply checked the RAM dump for plaintext looking things. Without having cooled the RAM (or opened the computer at all), there was a significant amount of meaningful plain-text. If you are interested in actual data about how effective this is, you should probably ignore my antecedent and look at the research paper in the above link.
Given how easy this attack is for its effectiveness, I would be suprised if it is not used.