Study: Disk Encryption Not Secure, Particularly With Laptops

SAN FRANCISCO — A team of researchers has found a major security flaw in several popular disk-encryption technologies that leaves encrypted data vulnerable to attack and exposure, particularly when laptops are in sleep mode.

Researchers from the Electronic Frontier Foundation and Princeton University have cracked several widely used disk encryption technologies, including Microsoft's BitLocker, Apple's FileVault, TrueCrypt and dm-crypt.

Those disc encryption systems are designed to protect sensitive information if a computer is stolen or otherwise accessed, but researchers said data is still vulnerable because encryption keys and passwords stored in a computer's temporary memory, or RAM, don’t disappear immediately after losing power.

"People trust encryption to protect sensitive data when their computer is out of their immediate control," EFF spokesman Seth Schoen said. "But this new class of vulnerabilities shows it is not a sure thing.

“Whether your laptop is stolen or you simply lose track of it for a few minutes at airport security, the information inside can still be read by a clever attacker," he said.

Laptops are particularly vulnerable to attack when they are turned on but locked, or in sleep or hibernation mode entered when the laptop's cover is shut, the EFF said.

Researchers said that even though the machines require a password to unlock the screen, the encryption keys are already located in the RAM, which provides an opportunity for attackers with malicious intent.

For the full paper, "Lest We Remember: Cold Boot Attacks on Encryption Keys," a demonstration video and other background information, click here.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Wisconsin Governor Vetoes Age Verification Bill

Gov. Tony Evers on Friday vetoed AB 105, an age verification bill that would have allowed anyone to sue adult content providers for damages over alleged failure to age-verify users in Wisconsin, with penalties of up to $10,000 per violation.

FSC Releases Statement on Wisconsin Governor Vetoing AV Bill

The Free Speech Coalition has released a statement on Wisconsin Governor Tony Evers' veto of the state's age verification legislation.

AV Bulletin: West Virginia Enacts AV Law, Ohio 'Innocence Act' Advances

This roundup provides an update on the latest news and developments on the age verification front as it impacts the adult industry.

Woodhull Survey Reveals Concern Among Sex Educators Over AV Laws' Impact on Access

A national survey of sex educators by the Woodhull Freedom Foundation found that a majority of sex educators and sexual health professionals are concerned that age verification (AV) laws will negatively impact access to information and resources.

Clips4Sale Wins Trademark Infringement Case Against Fraudulent Domain

The World Intellectual Property Organization (WIPO) has ruled in favor of content platform Clips4Sale in a case against a website using a similar domain to impersonate the site.

Pineapple Support, SextPanther to Host Stress Management Support Group

Pineapple Support and SextPanther are hosting a free online support group focused on stress management for performers.

Goddess Tangent Launches New Site Through Grooby's Blue.xxx

Goddess Tangent has launched her new membership site, TangentOD.com, through Grooby's website management company Blue.xxx.

Keiran Lee Guests on Chaturbate's 'Sex Tales' Podcast

Keiran Lee is the latest guest on Chaturbate’s “Sex Tales” podcast, hosted by Melissa Stratton and Vanniall, and streaming on the company’s “Camming Life” YouTube channel.

FSC Talks Age Verification on Capitol Hill

The Free Speech Coalition (FSC) has published a blog post detailing the organization's talks on age verification on Capitol Hill in Washington.

Show More