Readers: 44 | Updated: 02-22

Update: Hard drive encryption has Achilles heel, say researchers

Translate Into:

If you think that encrypting your laptop's hard drive will keep your data safe from prying eyes, you may want to think again, according to researchers at Princeton University.

They've discovered a way to steal the hard drive encryption key used by products such as Windows Vista's BitLocker or Apple's FileVault. With that key, hackers could get access to all of the data stored on an encrypted hard drive.

That's because of a physical property of the computer's memory chips. Data in these DRAM processors disappears when the computer is turned off, but it turns out that this doesn't happen right away, according to Alex Halderman, a Princeton graduate student who worked on the paper.

In fact, it can take minutes before that data disappears, giving hackers a way to sniff out encryption keys.

For the attack to work, the computer would have to first be running or in standby mode. It wouldn't work against a computer that had been shut off for a few minutes because the data in DRAM would have disappeared by then.

The attacker simply turns the computer off for a second or two and then reboots the system from a portable hard disk, which includes software that can examine the contents of the memory chips. This gives an attacker a way around the operating system protection that keeps the encryption keys hidden in memory.

"This enables a whole new class of attacks against security products like disk encryption systems that have depended on the operating system to protect their private keys," Halderman said. "An attacker could steal someone's laptop where they were using disk encryption and reboot the machine ... and then capture what was in memory before the power was cut."

Some computers wipe the memory when they boot up, but even these systems can be vulnerable, Halderman said. Researchers found that if they cooled down the memory chips by spraying canned air on them, they could slow down the rate at which memory disappeared. Cooling chips down to about -58 degrees Fahrenheit (-50 degrees Celsius) gave researchers time to power down the computer and then install the memory in another PC that would boot without wiping out the data. "By cooling the chips, we were able to recover data perfectly after 10 minutes or more," Halderman said.

Led by Princeton University, the team included researchers from the Electronic Frontier Foundation and Wind River Systems.

U.S. states have enacted a series of tough data disclosure laws over the past five years that force companies to notify residents whenever they lose sensitive information. Under these laws, a missing laptop can cost a company millions of dollars as well as public embarrassment as it is forced to track down and notify those whose data was lost.

However, many state laws, such as California's SB 1386, make an exception for encrypted PCs. So if a company or government agency loses an encrypted laptop containing sensitive data, they are not compelled to notify those affected.

The team's research may spur legislators to rethink that approach, Halderman said. "Maybe that law is placing too much faith in disk encryption technologies," he said. "It may be that we're not hearing bout thefts of encrypted machines where that data could still be at risk."

Laws like SB 1386 treat encryption as if it's a "magic spell" and ignore the fact that there's such a thing as bad encryption, said encryption expert Bruce Schneier, who is CTO with BT Counterpane.

The underlying problem is that if someone gains access to your machine, it is very difficult to protect the data on your hard drive, Schneier said. "That's an extremely hard problem for a lot of reasons, and this is one example of that."

Hardware-based encryption would probably reduce the risk, Halderman said, but he agreed that "it's a difficult problem."

Hard-drive makers Seagate and Hitachi both offer hardware-based disk encryption options with their hard drives, although these options come with a premium price tag.

This story was updated on February 21, 2007



From The Blogs

Coolbuzz

01-27
High heel shoe chair in hot pink and Zebra stripes
Asmita: What a tribute to the toe-killers of the 1980s and 1990s! I cannot believe how just one look at this Zebra & Hot Pink High Heel Shoe Chair brings back memories of big hair, splattered make-up,... 查看全文

Life, Health, Furnishings

06-05
What age is appropriate for wearing high heels?
The approipriate high heels for young girls can move the heart of the body forward and swell out your chest and pull your stomach and add great physical beauty .Besides, the appropriate high heels you... 查看全文

Beauty & Style - Channel Feed

06-20
Marc Jacobs Cut Out Heel Boots
We saw a bunch of spring and summer sandals with cut-out heels and it looks like that trend will continue into fall with boots. These Marc Jacobs tall boots feature a small cut-out detail at the top o... 查看全文

Popgadget: Personal Tech for Women

06-25
Heelarious High Heel Crib Shoes - for babies who don't walk
Why do we put real shoes on just born infants who can't even hold their heads up, let alone walk?Newborns' feet are like mush; they just dangle like a pair of earrings.Yet, we jcan't help ourselves, c... 查看全文

Latest postings for The Lounge

07-17
Pathologists Believe They Have Pinpointed Achilles Heel Of HIV
Good read![^] There are II kinds of people in the world, those who understand binary and those who understand Roman numerals. Web - Blog - RSS - Math 查看全文

Technology - Channel Feed

07-18
The “Mainstream” Deception Is Google’s Achille’s Heel
Marshall Kirkpatrick comments on a recent Hitwise study, remarking that a whole load of people *still* type in the URL not in the Address Bar, but directly into a search engine, to find their site.  M... 查看全文

b5media Technology Channel Feed

07-18
The “Mainstream” Deception Is Google’s Achille’s Heel
Marshall Kirkpatrick comments on a recent Hitwise study, remarking that a whole load of people *still* type in the URL not in the Address Bar, but directly into a search engine, to find their site.  M... 查看全文

Deadspin

11-21
A North Carolina Tar Heel named Tyler is ...
A North Carolina Tar Heel named Tyler is out for the season with a broken wrist. The Kryptonite is working. [ESPN] 查看全文

Deadspin

03-31
I Can't Even Think About Doing This Without Falling Down [Heel Turn]
Cristiano Ronaldo had an impressive back-heel goal in Man U's 4-0 rout of Aston Villa yesterday. In other news, I just tripped over my mouse. In even further developments, I don't speak Portuguese Ara... 查看全文

爱...稀奇~{新鲜:科技:创意:有趣}

04-09
欧宝高跟鞋(Opel Agila High-Heel Shoes)
4月2日,作为迷你型轿车Agila在荷兰上市活动的一部分,欧宝在阿姆斯特丹的Shoebaloo发布了一款非常“不务正业”的东东——Agila高跟鞋…… Agila高跟鞋由Luca Stappers设计... 查看全文
More Articles