Study: Disk Encryption Not Secure, Particularly With Laptops

SAN FRANCISCO — A team of researchers has found a major security flaw in several popular disk-encryption technologies that leaves encrypted data vulnerable to attack and exposure, particularly when laptops are in sleep mode.

Researchers from the Electronic Frontier Foundation and Princeton University have cracked several widely used disk encryption technologies, including Microsoft's BitLocker, Apple's FileVault, TrueCrypt and dm-crypt.

Those disc encryption systems are designed to protect sensitive information if a computer is stolen or otherwise accessed, but researchers said data is still vulnerable because encryption keys and passwords stored in a computer's temporary memory, or RAM, don’t disappear immediately after losing power.

"People trust encryption to protect sensitive data when their computer is out of their immediate control," EFF spokesman Seth Schoen said. "But this new class of vulnerabilities shows it is not a sure thing.

“Whether your laptop is stolen or you simply lose track of it for a few minutes at airport security, the information inside can still be read by a clever attacker," he said.

Laptops are particularly vulnerable to attack when they are turned on but locked, or in sleep or hibernation mode entered when the laptop's cover is shut, the EFF said.

Researchers said that even though the machines require a password to unlock the screen, the encryption keys are already located in the RAM, which provides an opportunity for attackers with malicious intent.

For the full paper, "Lest We Remember: Cold Boot Attacks on Encryption Keys," a demonstration video and other background information, click here.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

New Kickstarter Rules Ban Fundraising for Adult Content, Products

Crowdfunding platform Kickstarter has posted new “Mature Content” rules banning projects that involve adult content and sextech.

WebGroup Czech Republic Settles Florida AV Suit, Will Pay $1.2 Million

WebGroup Czech Republic (WGCZ), the parent company of XVideos, XNXX, BangBros and GirlsGoneWild, has settled a lawsuit filed by the state of Florida over those sites’ alleged failure to age-verify Florida users before allowing access to adult content.

AEBN Publishes Popular Searches for March, April

AEBN has published the top search terms for March and April from its straight and gay theaters in all 50 states and the District of Columbia.

Ofcom Investigates Two Sites Over Possible AV Violations

U.K. media regulator Ofcom on Wednesday launched investigations into two adult sites as part of its age assurance enforcement program under the Online Safety Act (OSA).

Brazzers Launches Model Management Division 'Brazzers Creator'

Brazzers has launched its new full-service model management division, Brazzers Creator, offering content management services across multiple platforms.

FTC Promises 'Vigorous' TAKE IT DOWN Act Enforcement

The Federal Trade Commission is warning platforms that the agency will strongly enforce the notice-and-removal requirements of the TAKE IT DOWN Act, which go into effect next week on May 19.

STD Hero Joins Pineapple Support as Sponsor

Better Life Science brand STD Hero has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

2026 XBIZ Miami Speaker, Open-Floor Conversation Guide Lineup Announced

XBIZ is pleased to announce the release of the full speaker lineup for XBIZ Miami, the latest edition of the adult industry’s premier summer conference, set to take place May 11-14 at the Goodtime Hotel in Miami Beach.

2026 XBIZ Miami Conference Schedule Announced

XBIZ is pleased to announce the release of the full show schedule for XBIZ Miami, set to take place May 11-14 at the Goodtime Hotel in South Beach.

UPDATED: Utah VPN Rule Enforcement Paused in Aylo Lawsuit

Provisions of a new Utah law making adult websites liable if minors in the state circumvent geolocation efforts to bypass age verification, which were set to come into force on Wednesday, have been put on hold until Sept. 3 in the case of Aylo, which filed suit in the matter.

Show More