Breaking disk encryption with RAM dumps


If you haven't gotten a chance yet, do watch the video of this attack. It's does a good job explaining the problem. Full drive encryption stores the key in RAM while the computer is powered on. The RAM's stored data doesn't immediately disappear when powered off, but fades over time. To recover the keys, they powered off the computer and booted from a USB disk that created an image of the RAM. You can read more about the attack here.

How can you reduce this threat? You can turn off USB booting and then put a password on the BIOS to prevent the specific activity shown in the video. Also, you can encrypt your rarely used data in a folder on the disk. They could still decrypt the disk, but they won't get everything. I don't think this problem will truly be fixed unless there is a fundamental change in hardware design to erase the RAM and even then it would probably only help computers that are powered off, not suspended.

The potential for this attack has always been talked about and I'm glad to see someone pull it off. I'm hoping to see future research into dumping RAM data using a USB/ExpressCard with DMA access.

Recent Posts

Reader Comments

(Page 1)
Next 20 Comments

hack a day serves up a fresh hack each day, every day from around the web and a special how-to hack each week.

send us your hacks

have a hack you'd like to see here? tell us about it

Hacks
aibo hacks (1)
cellphones hacks (72)
cons (58)
contests (23)
daily (81)
digital audio hacks (7)
digital cameras hacks (70)
downloads hacks (10)
gameboy hacks (33)
google hacks (5)
gps hacks (35)
HackIt (18)
handhelds hacks (58)
home entertainment hacks (140)
home hacks (18)
how-to (13)
ipod hacks (74)
laptops hacks (48)
laser hacks (31)
macs hacks (40)
misc hacks (761)
news (126)
pcs hacks (139)
peripherals hacks (164)
playstation hacks (49)
podcasts (8)
portable audio hacks (43)
portable video hacks (25)
robots hacks (95)
roundup (2)
security hacks (21)
solar hacks (1)
tablet pcs hacks (6)
tivo hacks (6)
tool-hacks (8)
transportation hacks (85)
wii hacks (14)
wireless hacks (82)
xbox hacks (50)

resources

rss newsfeeds

Powered by Blogsmith