We’ll need eatable DRAMs

The new was released one month ago, but the vulnerability will remain without solution the next months/years. A team of the University of Princeton developed an attack against all the crypto filesystems. The attack exploits a discovery about most DRAMs in the market: the information doesn’t dissapear inmediately after powering off the machine. It remains some seconds, and, if you cold the machine with a simple cold spray, you have until 10 minutes around to reboot the machine with a program and recover the crypto keys from the memory. So, if anybody has phisical access to the machine (it is the main target to use crypto fs’s), they will be able to decrypt the information with some software and cheap hardware.

The cold boot attack paper

Some reactions:

This entry was posted in Free Software, Sec, crypto, forensics and priv. Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>