Evil Maid goes after TrueCrypt
theinvisiblethings.blogspot.com
theinvisiblethings.blogspot.com
Sure, there are plenty of other attack vectors, but this takes the problem out of the evil maid category.
"somebody who can get access to my Disk Hasher USB (e.g. when I’m in a swimming pool), can infect it"
TrueCrypt is about the guy with the cinderblock, not about stopping Joanna Rutkowska from installing a keylogger.
Frankly, most people's data is really not that important and the cinderblock attack is what truecrypt and similar crypto systems prevent. Every time you see a news item about "a million social security numbers have been compromised " - its always due to the cinderblock attack.
The "only" way to secure your data is to put your computer it in a vault (unplugged from AC outlet and no network access) with multiple physical security and surrounded by people with guns. If your data is that important and you can afford this sort of security...then the evil maid attack is irrelevant.
On the flipside it's easier to keep a netbook always on your possession than it is even a 12" laptop. So yea, smaller computing devices could be 'easier to pick-pocket' or it could mean 'harder to separate from the user.'
At that point, you only have to worry about the strength of the BIOS's password-protection. Any other attempt at circumvention would be self-evident thanks to the destroyed case or epoxy.
To protect against trojan horses you need an external validation mechanism or a physical protection (be that a safebox or TPM, by the way the Truecrypt team is wrong about TPM, it's much more difficult to temper than bytes on a hard disk).
Sigh - privacy in the age of information seems to be an impossible dream.
Addendum: "Provided it's implemented well".
Of course as the strip also points out "Actual actual reality: nobody cares about his secrets"
And finally how do you know they haven't done exactly the same trick but replaced your bios with one that includes a keylogger?
Well, it's better than before: Non-electronic documents are arguably much easier to steal. At least with encryption, breaking into your house isn't necessarily enough to get your data.
That even bypasses physical (lockbox) security.
(I liked the article but I think she waffled on a bit long about physical security, which TC developers made a good point about, and TPM)
If you really want to cut it in half, just kidnap him and hit him with this $5 wrench until he tells us the password. We're breaking laws, but hey, whose counting?
Joanna Rutkowska: If I could arrange for a proper lock or an impenetrable strongbox, than why in the world should I need encryption?
TrueCrypt Developer: Your question was: "And how can you determine that the attacker has or has not worked with your hardware?" My answer was a good safety case or strongbox with a good lock. If you use it, then you will notice that the attacker has accessed your notebook inside (as the case or strongbox will be damaged and it cannot be replaced because you had the correct key with you). If the safety case or strongbox can be opened without getting damaged & unusable, then it's not a good safety case or strongbox. ;-)
Edit: still there are a few tricks that can be done in theory. For instance to flash a new bios modified in order to write some data in a given sector of the disk if after the power up you don't press a special sequence of keys. This makes the owner able to detect if there was access to the PC, and because it's done in the BIOS even starting a different operating system from the CD will not avoid the detection.
This is security by obscurity, but can work against Maids.
Another simpler, less effective, but still better than nothing approach is to set a password in the BIOS. Unfortunately if I remember correctly a lot of BIOSes used to have backdoors.
In case the attacker steals your laptop and decides to keep it, for example.
The attacker has complete physical access to a laptop with an encrypted hard drive for an indefinite period of time.
Forgive my ignorance on the matter, but what good would encryption do you there? Other than slow them down, of course.If your laptop is encrypted, contains PI, and is stolen, you probably don't need to disclose the loss.
No matter what Joanna Rutkowska does with her (very slick) USB key, things like TrueCrypt are very cheap, very very effective insurance.
Thanks for clarifying, though.
This is a good point with regard to the Maid scenario, so I don't think the developers of TC were running away from the question at all.
And from the article: "After some 1-2 minutes, the target's laptop gets infected with Evil Maid Sniffer that will record the disk encryption passphrase when the user enters it next time." -- so the attacker is depending on the user reentering the system, and they are depending on confiscating the system afterwards. Loss and theft scenarios where an attacker has not utilized EMS, or is just out to steal the laptop, still protects the data.
So in summation, you need encryption to protect against loss or theft, which may be sufficient for your vulnerability level (maybe you don't travel a lot but one day you simply lost your laptop), but you need to go further to protect against what looks to me to be a more advanced version of a keylogger (EMS - frequent traveler with sensitive information).
Phishing scams and virus emails are social engineering in that they are conning the user into taking an action. You're not 'conning' the user into entering their password, you are just making it look like the system is normal and the user is entering their password on their own (because they are looking for access to the system). It would no more be a social engineering hack if you were to make a duplicate laptop with only a keylogger on it, and then burst into the room guns-blazing once they tried to log in with the password.
Maybe I'm off here but most social engineering has to do with convincing the user to trust 'you' where 'you' can be an unsolicited email telling them to send money to Nigeria, or a person on the phone claiming to need their password to 'reset their account.' In the case of this attack (or a keylogger), they are trusting something that they already trust, their laptop. You're not 'convincing' them to trust their laptop. You're just covering up the fact that it's been compromised.
The victim trusts the hotel, the social engineering I saw here is getting into the position of being a maid (who is trusted to not mess with your stuff (well, not by me but apparently by some)). Just like you can social engineer yourself into any company in order to get at the machines and install a keylogger.
In my original statement I did not do a very good job at how I am dismissing the interestingness of the original blog post, but a keylogger insertion (either software or hardware based) is a time tested technique,there is nothing new here with the attack "payload."
So all I see is "how did the attacker get physical access" but did not flesh this viewpoint out at all, and I apologize.
Think of it in terms of remote exploits and their payloads. Why discuss the subtle differences between rootkit #1 vs. rootkit #2 and how each will screw you: the problem is actually in the attack vector, not the payload. Once you're in, the details are somewhat boring (relatively speaking).