Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Icy encryption tool protects laptops from "cold boot" attack, vendor says

Vulnerable encryption keys erased by HyBlue's IceLock
By Jon Brodkin , Network World , 05/13/2008

The vendor HyBlue says it can prevent the "cold boot" encryption hack discovered by Princeton researchers with a laptop  security product announced Tuesday.

The cold boot vulnerability allows hackers to steal encryption keys from dynamic RAM (DRAM) memory in laptops that have been recently powered down. While Microsoft says such an attack is unlikely, Princeton researchers in February said it is possible because data previously thought to disappear immediately from DRAM persists for a while after the computer has been shut off.

HyBlue's IceLock technology automatically deletes those keys out of memory and overwrites them with random data when there is a state change, such as screen saver activation, hibernation, or a user logging off or powering the computer down. (Compare security products.)  When the user turns the computer back on, the normal password/login process ensues.

"They're the first ones I've seen that [erase the keys from DRAM]," says analyst Michael Santarcangelo of the Security Catalyst. "I think it's pretty clever."

The problem with similar products is they don't "have an awareness of their environment. They assume when you go to sleep or turn off the computer, that RAM is erased," says HyBlue CEO Matthew Sutton.

The cold boot attack is so named because it requires hackers to cool a computer's memory to -58 degrees Fahrenheit (-50 degrees Celsius), giving them as much as 10 minutes to examine the contents.

IceLock is available immediately on Windows XP and Vista for a discounted rate of $49.95 per computer per year until July 1, 2008. After that, the price goes up to $99.95 per computer per year. A Macintosh OSX version will be released later this year, and HyBlue intends to offer a similar product for smartphones this year.

While IceLock requires software to be downloaded onto each computer, the product's management tools are delivered over the Web in the software-as-a-service (SaaS) model. These tools include a Web-based central policy management and key recovery system, and ability to remotely wipe data from stolen or missing computers – assuming the computer is connected to the Internet.

Santarcangelo credited HyBlue for not placing undue burdens on users. A user just needs a Windows login password and a second password to access a partitioned area that contains files protected by IceLock encryption, he notes.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Save The Date!
What They Are Saying

Investment of a Technology should be 'held off' because there hasn't been enough investment in it yet? Is...- Anonymous

Join the Discussion