<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: filevault]]></title>
    <link>http://securityratty.com/tag/filevault</link>
    <description></description>
    <pubDate>Thu, 21 Feb 2008 10:29:18 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Black Hat Talks Pulled After Industry Pressure]]></title>
      <link>http://securityratty.com/article/c3044e32c6768e8b02d36302280ca590</link>
      <guid>http://securityratty.com/article/c3044e32c6768e8b02d36302280ca590</guid>
      <description><![CDATA[A few Apple-related talks scheduled for next weeks Black Hat conference have been cut from the line-up, presumably because they would reveal too much insider information about vulnerabilities
Brian...]]></description>
      <content:encoded><![CDATA[<p>A few Apple-related talks scheduled for next week&#8217;s Black Hat conference have been cut from the line-up, presumably because they would reveal too much insider information about vulnerabilities.</p>
<p>Brian Krebs has the details&#8211;</p>
<blockquote><p>
Charles Edge, a researcher from Georgia, had been slated to discuss his research on a weakness that could be used to defeat FileVault encryption on the Mac. But sometime last week, Black Hat organizers pulled his name and presentation listing from its schedule of talks.</p>
<p>Contacted via cell phone, Edge said he signed confidentiality agreements with Apple, which prevents him from speaking on the topic and from discussing the matter further.</p>
<p>Almost every year, much of the drama leading up to and during Black Hat seems to revolve around talks that are canceled or censored at the last minute for various legal reasons. </p></blockquote>
<p>Read the full article <a rel="nofollow" target="_blank" href="http://voices.washingtonpost.com/securityfix/2008/07/black_hat_talk_on_apple_encryp_1.html">here.</a></p>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 08:39:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/black hat">black hat</category>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <category domain="http://securityratty.com/tag/black hat organizers">black hat organizers</category>
      <category domain="http://securityratty.com/tag/charles edge">charles edge</category>
      <category domain="http://securityratty.com/tag/defeat filevault encryption">defeat filevault encryption</category>
      <category domain="http://securityratty.com/tag/edge">edge</category>
      <category domain="http://securityratty.com/tag/insider information">insider information</category>
      <category domain="http://securityratty.com/tag/cell phone">cell phone</category>
      <category domain="http://securityratty.com/tag/confidentiality agreements">confidentiality agreements</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/357716132/">Black Hat Talks Pulled After Industry Pressure</source>
    </item>
    <item>
      <title><![CDATA[Full disk encryption for all!]]></title>
      <link>http://securityratty.com/article/3103fffefb521ff2d5964841dda0b827</link>
      <guid>http://securityratty.com/article/3103fffefb521ff2d5964841dda0b827</guid>
      <description><![CDATA[To echo Bruce Schneier's comments , it's important to encrypt the data on your laptops. Yes, the laptops get stolen, they get lost and your private data is on them. So if you scramble up that data...]]></description>
      <content:encoded><![CDATA[To echo <a href="http://www.schneier.com/blog/archives/2007/12/how_to_secure_y.html">Bruce Schneier's comments</a>, it's important to encrypt the data on your laptops. Yes, the laptops get stolen, they get lost and your private data is on them. So if you scramble up that data (using an encryption product), then you are somewhat insulating yourself from having that data stolen.<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_hafMI9V8sC8/R87BTRz3bLI/AAAAAAAAAGM/1RoC-cuwCAg/s1600-h/FileVault.jpg"><img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://bp0.blogger.com/_hafMI9V8sC8/R87BTRz3bLI/AAAAAAAAAGM/1RoC-cuwCAg/s200/FileVault.jpg" alt="" id="BLOGGER_PHOTO_ID_5174285558837898418" border="0" /></a><br /><br />A <a href="http://citp.princeton.edu/memory/">new attack was introduced by Ed Felten</a> and his band of merry Princeton grad students a week ago, which showed how to steal the encryption key and gain access to hard drive data, even if the data is encrypted. Let's just say, this is not an attack that most of you need to worry about. You are still much better off encrypting your data, than not encrypting your data.<br /><br />I personally use the FileVault capability within Mac OS X. There are a bunch of 3rd party utilities, but FileVault works fine for me. I don't see any reason to make it harder than it needs to be.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/SecurityMike?a=c4Xwy3F"><img src="http://feeds.feedburner.com/~f/SecurityMike?i=c4Xwy3F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/SecurityMike?a=l1rev6f"><img src="http://feeds.feedburner.com/~f/SecurityMike?i=l1rev6f" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/SecurityMike?a=K6jGfXf"><img src="http://feeds.feedburner.com/~f/SecurityMike?i=K6jGfXf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/SecurityMike/~4/246194801" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 05 Mar 2008 07:32:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/hard drive data">hard drive data</category>
      <category domain="http://securityratty.com/tag/filevault capability">filevault capability</category>
      <category domain="http://securityratty.com/tag/echo bruce schneier">echo bruce schneier</category>
      <category domain="http://securityratty.com/tag/filevault">filevault</category>
      <category domain="http://securityratty.com/tag/3rd party utilities">3rd party utilities</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/gain access">gain access</category>
      <category domain="http://securityratty.com/tag/laptops">laptops</category>
      <source url="http://feeds.feedburner.com/~r/SecurityMike/~3/246194801/full-disk-encryption-for-all.html">Full disk encryption for all!</source>
    </item>
    <item>
      <title><![CDATA[Encryption defeated, still an advocate?]]></title>
      <link>http://securityratty.com/article/f32a86ae68fb4bff0a71ce361e16c5c5</link>
      <guid>http://securityratty.com/article/f32a86ae68fb4bff0a71ce361e16c5c5</guid>
      <description><![CDATA[Technorati Tag: Encryption

Originally I was not going to write about this because it is not a breach (incident), but

Yesterday, researchers from Princeton University, the Electronic Frontier...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/encryption" rel="tag">Encryption</a><br><br>
<img src="http://breachblog.com/images/95781-88451/citp.jpg" align="right" height="50" width="201"><font size="2">Originally I was not going to write about this because it is not a breach (incident), but...<br><br>Yesterday,
researchers from Princeton University, the Electronic Frontier
Foundation, and Wind River Systems released an eye-opening report
labeled "<a target="_blank" href="http://citp.princeton.edu.nyud.net/pub/coldboot.pdf">Lest We Remember: Cold Boot Attacks on Encryption Keys</a>" in
which they "present a suite of attacks that exploit DRAM remanence [<span style="font-style: italic;">sic</span>]
effects to recover cryptographic keys held in memory".<br><br>OK.&nbsp; What does this mean to the non-geek?&nbsp; It means that there are now successful attacks against many encryption implementations, including those most commonly used on mobile devices (laptop, thumb drive, etc.).&nbsp; Here
at <span style="font-style: italic;">The Breach Blog</span> I have advocated the use of hard drive encryption in
many posts and pointed out the fact that storing confidential
information on unencrypted laptops is bad security and poor business.&nbsp; So, what does this all mean?<br><br></font><font size="2"><span style="font-weight: bold;">From <a target="_blank" href="http://citp.princeton.edu/memory/faq/">Princeton University's Center for Information Technology Policy FAQs</a>:</span><br><br><strong>Q. What encryption software is vulnerable to these attacks?</strong><br><strong>A. </strong>We have demonstrated practical attacks against
several popular disk encryption systems: BitLocker (a feature of
Windows Vista), FileVault (a feature of Mac OS X), dm-crypt (a feature
of Linux), and TrueCrypt (a third-party application for Windows, Linux,
and Mac OS X). Since these problems result from common design
limitations of these systems rather than specific bugs, most similar
disk encryption applications, including many running on servers, are
probably also vulnerable.<br><br><strong>Q. What can users do to protect themselves?<br>
A. </strong>The
most effective way for users to protect themselves is to fully shut
down their computers several minutes before any situation in which the
computers’ physical security could be compromised. On most systems,
locking the screen or switching to “suspend” or “hibernate” mode does
not provide adequate protection. (Exceptions exist; some systems may
not be protected even when powered off. Check with the developer of
your disk encryption software for further guidance.)<br><br><strong>Q. Isn’t your attack difficult to carry out?  Don’t you need materials like liquid nitrogen?<br>
A. </strong>We
found that information in most computers’ RAMs will persist from
several seconds to a minute even at room temperature. We also found a
cheap and widely available product — “canned air” spray dusters — can
be used to produce temperatures cold enough to make RAM contents last
for a long time even when the memory chips are physically removed from
the computer. The other components of our attack are easy to automate
and require nothing more unusual than a laptop and an Ethernet cable,
or a USB Flash drive. With only these supplies, someone could carry out
our attacks against a target computer in a matter of minutes.<br><br style="font-weight: bold;"><span style="font-weight: bold;">And from "</span><a style="font-weight: bold;" target="_blank" href="http://citp.princeton.edu.nyud.net/pub/coldboot.pdf">Lest We Remember: Cold Boot Attacks on Encryption Keys</a><span style="font-weight: bold;">" Conclusion:</span><br>"There seems to be no easy remedy for these vulnerabilities. Simple software changes are likely to be ineffective; hardware changes are possible but will require time and expense; and today’s Trusted Computing technologies appear to be of little help because they cannot protect keys that are already in memory. The risk seems highest for laptops, which are often taken out in public in states that are vulnerable to our attacks. These risks imply that disk encryption on laptops may do less good than widely believed."<br><br><span style="font-style: italic;">[Evan]&nbsp; Well, if this ain't a shot to the gut!&nbsp; On the surface I am miffed by research that leaves me wondering what in the world am I supposed to do now?&nbsp; When I think about it more, I am extremely grateful for the work these people do and I'm not really surprised by the findings.&nbsp; People that have been in the information security field for a while, understand some of the concepts that (we think) make us effective in what we do.&nbsp; Nobody can rightfully claim that full disk encryption or any other single technology is the one that protects against everything.&nbsp; We are never 100% secure will all technologies, let alone one.&nbsp; Security is a holistic discipline that is about defense in depth, continual analysis and improvement, systems and backup systems, threats, countermeasures, etc. etc.&nbsp; This is just another attack vector that wasn't widely known or accepted until now.</span><br style="font-style: italic;"><br style="font-style: italic;"><span style="font-weight: bold; font-style: italic;">I am still an advocate for using full disk encryption</span><span style="font-style: italic;"> (and encryption in general) as good information security practice.&nbsp; It is another essential cog in the bigger information security machine.&nbsp; Recognize the technology for what it is and understand that it's use does reduce risk when compared to the alternative of using clear-text.&nbsp; Obtaining the encryption keys is obviously very possible, but obtaining clear text information is completely trivial.&nbsp; Long-term this is a great problem to have.&nbsp; I have seen many, many good "out of the box" ideas being kicked around by information security professionals, debating possible solutions.&nbsp; It's the out of the box thinking that spurs creative solutions.</span><br><br><span style="font-weight: bold;">Other News Sources:</span><br><a target="_blank" href="http://www.news.com/8301-13578_3-9876060-38.html?tag=nefd.pop">CNET.com News story</a><br><a target="_blank" href="http://www.nytimes.com/2008/02/22/technology/22chip.html?em&amp;ex=1203829200&amp;en=fcb9fd1d351c8d5e&amp;ei=5087">The New York Times story</a><br><a target="_blank" href="http://www.securityfocus.com/brief/686">SecurityFocus story</a><br><a target="_blank" href="http://www.informationweek.com/news/showArticle.jhtml?articleID=206801184">InformationWeek story</a></font>
<br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/22/encrypt.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 22 Feb 2008 13:15:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/encryption">encryption</category>
      <category domain="http://securityratty.com/tag/disk encryption software">disk encryption software</category>
      <category domain="http://securityratty.com/tag/encryption software">encryption software</category>
      <category domain="http://securityratty.com/tag/information security field">information security field</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/hard drive encryption">hard drive encryption</category>
      <category domain="http://securityratty.com/tag/disk encryption">disk encryption</category>
      <category domain="http://securityratty.com/tag/text information">text information</category>
      <category domain="http://securityratty.com/tag/encryption keys">encryption keys</category>
      <source url="http://breachblog.com/2008/02/22/citp.aspx">Encryption defeated, still an advocate?</source>
    </item>
    <item>
      <title><![CDATA[Disk encryption not enough?]]></title>
      <link>http://securityratty.com/article/a9ff6be5b76c34e582e49001fa6c00ec</link>
      <guid>http://securityratty.com/article/a9ff6be5b76c34e582e49001fa6c00ec</guid>
      <description><![CDATA[Just saw this come off the wire - from news.com on how disk encryption from Bitlocker and Apple's FileVault has been circumvented by a few researchers. If this is as simple as they make it sound, this...]]></description>
      <content:encoded><![CDATA[Just saw this come off the wire - from <a href="http://www.news.com/8301-13578_3-9876060-38.html">news.com </a>on how disk encryption from Bitlocker and Apple's FileVault has been circumvented by a few researchers. If this is as simple as they make it sound, this is a bit worrisome. However, I am not ready to buy this fully, till I understand this a bit more.<br /><br />For one, I was under the impression that Bitlocker protected against booting via an alternative OS (especially a system with a TPM chip on it) because it can perform bootup integrity checks. The article seems to claim this is one of the ways in... Hmm, not so sure...<br /><br />Further questions:<br />Is this attack valid for all authentication scenarios such as TPM+Pin?<br />How easy is it to scan the RAM on a locked system?<br /><br />There was another <a href="http://www.eweek.com/c/a/Security/FullDisk-Encryption-Is-Partial-Protection-Analysts-Say/">article recently in eWeek </a>that talked about FDE not being sufficient protection. I personally think that we need defense against multiple scenarios - not sure if the defense-in-depth term can be used, but seems to fit the best...<br /><br /> Looking forward to understanding this a bit more...<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=ctHJe5E"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=ctHJe5E" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=175A0Xe"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=175A0Xe" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=E29dkfE"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=E29dkfE" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/238916815" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 21 Feb 2008 14:14:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bit">bit</category>
      <category domain="http://securityratty.com/tag/disk encryption">disk encryption</category>
      <category domain="http://securityratty.com/tag/bit worrisome">bit worrisome</category>
      <category domain="http://securityratty.com/tag/article recently">article recently</category>
      <category domain="http://securityratty.com/tag/article">article</category>
      <category domain="http://securityratty.com/tag/sufficient protection">sufficient protection</category>
      <category domain="http://securityratty.com/tag/bitlocker">bitlocker</category>
      <category domain="http://securityratty.com/tag/multiple scenarios">multiple scenarios</category>
      <category domain="http://securityratty.com/tag/tpm chip">tpm chip</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/238916815/disk-encryption-not-enough.html">Disk encryption not enough?</source>
    </item>
    <item>
      <title><![CDATA[Cold Boot Attacks Against Disk Encryption]]></title>
      <link>http://securityratty.com/article/1e75222801d309c379e8b36bfac65757</link>
      <guid>http://securityratty.com/article/1e75222801d309c379e8b36bfac65757</guid>
      <description><![CDATA[Nice piece of research : We show that disk encryption, the standard approach to protecting sensitive data on laptops, can be defeated by relatively simple methods. We demonstrate our methods by using...]]></description>
      <content:encoded><![CDATA[<p>Nice <a href="http://www.freedom-to-tinker.com/?p=1257">piece of research</a>:</p>

<blockquote>We show that disk encryption, the standard approach to protecting sensitive data on laptops, can be defeated by relatively simple methods. We demonstrate our methods by using them to defeat three popular disk encryption products: BitLocker, which comes with Windows Vista; FileVault, which comes with MacOS X; and dm-crypt, which is used with Linux.

<p>[...]</p>

<p>The root of the problem lies in an unexpected property of today’s DRAM memories. DRAMs are the main memory chips used to store data while the system is running. Virtually everybody, including experts, will tell you that DRAM contents are lost when you turn off the power. But this isn’t so. Our research shows that data in DRAM actually fades out gradually over a period of seconds to minutes, enabling an attacker to read the full contents of memory by cutting power and then rebooting into a malicious operating system.</p>

<p>Interestingly, if you cool the DRAM chips, for example by spraying inverted cans of “canned air” dusting spray on them, the chips will retain their contents for much longer. At these temperatures (around -50 °C) you can remove the chips from the computer and let them sit on the table for ten minutes or more, without appreciable loss of data. Cool the chips in liquid nitrogen (-196 °C) and they hold their state for hours at least, without any power. Just put the chips back into a machine and you can read out their contents.</p>

<p>This is deadly for disk encryption products because they rely on keeping master decryption keys in DRAM. This was thought to be safe because the operating system would keep any malicious programs from accessing the keys in memory, and there was no way to get rid of the operating system without cutting power to the machine, which “everybody knew” would cause the keys to be erased.</p>

<p>Our results show that an attacker can cut power to the computer, then power it back up and boot a malicious operating system (from, say, a thumb drive) that copies the contents of memory. Having done that, the attacker can search through the captured memory contents, find any crypto keys that might be there, and use them to start decrypting hard disk contents. We show very effective methods for finding and extracting keys from memory, even if the contents of memory have faded somewhat (i.e., even if some bits of memory were flipped during the power-off interval). If the attacker is worried that memory will fade too quickly, he can chill the DRAM chips before cutting power.</p>

<p>There seems to be no easy fix for these problems. Fundamentally, disk encryption programs now have nowhere safe to store their keys. Today’s Trusted Computing hardware does not seem to help; for example, we can defeat BitLocker despite its use of a Trusted Platform Module.</blockquote></p>

<p>The paper is <a href="http://citp.princeton.edu.nyud.net/pub/coldboot.pdf">here</a>; more info is <a href="http://citp.princeton.edu/memory/">here</a>.  <a href="http://www.news.com/8301-13578_3-9876060-38.html">Articles</a> <a href="http://blog.wired.com/27bstroke6/2008/02/researchers-dis.html">here</a>.</p>

<p>There is a general security problem illustrated here: it is very difficult to secure data when the attacker has physical control of the machine the data is stored on.  I talk about the general problem <a href="http://www.schneier.com/essay-142.html">here</a>, and it's a hard problem.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=SGcGWEE"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=SGcGWEE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=jXdC1UE"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=jXdC1UE" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 21 Feb 2008 10:29:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/main memory chips">main memory chips</category>
      <category domain="http://securityratty.com/tag/memory">memory</category>
      <category domain="http://securityratty.com/tag/todays dram memories">todays dram memories</category>
      <category domain="http://securityratty.com/tag/dram">dram</category>
      <category domain="http://securityratty.com/tag/dram contents">dram contents</category>
      <category domain="http://securityratty.com/tag/memory contents">memory contents</category>
      <category domain="http://securityratty.com/tag/disk encryption">disk encryption</category>
      <category domain="http://securityratty.com/tag/hard">hard</category>
      <category domain="http://securityratty.com/tag/hard disk contents">hard disk contents</category>
      <source url="http://www.schneier.com/blog/archives/2008/02/cold_boot_attac.html">Cold Boot Attacks Against Disk Encryption</source>
    </item>
  </channel>
</rss>
