Skip Links

Network World

  • Social Web 
  • Email 
  • Close

'Cold Boot' encryption hack unlikely, says Microsoft

By Gregg Keizer , Computerworld , 02/28/2008
  • Share/Email
  • Comment
  • Print

Users can keep thieves from stealing encrypted data by changing some settings in Windows, a Microsoft product manager said as he downplayed the threat posed by new research that shows how attackers can inspect a "ghost" of computer memory.

Russ Humphries, a senior product manager for Windows Vista security, reacted Friday to reports last week about a new low-tech technique that could be used to lift the encryption key used by Vista's BitLocker or Mac OS X's FileVault. Once an attacker has the key, of course, he could easily access the data locked away on an encrypted drive.

The method -- dubbed "Cold Boot" because criminals can boost their chances by cooling down the computer's memory with compressed gas or even liquid nitrogen -- relies on the fact that data doesn't disappear instantly when a system is turned off or enters "sleep" mode. Instead, the bits stored in memory chips decay slowly, relatively speaking.

Cooling down memory to -58 degrees Fahrenheit (-50 degrees Celsius) would give attackers as long as 10 minutes to examine the contents of memory, said the researchers from Princeton University, the Electronic Frontier Foundation and Wind River Systems Inc. And when they pushed the envelope and submersed the memory in liquid nitrogen to bring the temperature down to -310 degrees Fahrenheit (-190 degrees Celsius), researchers saw just 0.17% data decay after an hour.

The whole thing is unlikely, Humphries argued in a post to the Vista security team's blog. To make his case, he ticked off several preconditions:

-- The attacker would have to have physical access to the machine.

-- The laptop would likely have to be in "sleep" mode, rather than in "hibernate" mode or powered off.

-- The person who finds/steals the laptop must be knowledgeable and interested enough to execute the attack.

"I would posit that the opportunistic laptop thief is somewhat unlikely to carry a separate laptop on which they will have installed tools that allow them to reconstruct cryptographic keys, or for that matter have a can of compressed air handy," said Humphries.

Not everyone was buying that argument, however. "We just had two laptops stolen. Both were powered on and would be prime candidates for 'memory' based attacks," claimed a user identified as Doug who posted a comment to Humphries' blog. "So this is not as improbable as you make it sound."

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Windows Vista: Necessity and Opportunity

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...

Vulnerability Management For Dummies

Download this concise book "Vulnerability Management for Dummies," to learn about the simple steps...

Security Considerations When Deploying Remote Access Solutions

Effective network security is most successful when you use a layered approach, with multiple...

Webcasts

Migrating to Windows Vista: Necessity and Opportunity

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...

Turning information into a Competitive Advantage

Companies today are realizing that competitive advantage is harder to sustain when based solely on...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Special Reports

Unified Threat Management from CheckPoint

Discover why Unified Threat Management Firewalls are ready for the enterprise today. High...

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.