Study: Disk Encryption Not Secure, Particularly With Laptops

SAN FRANCISCO — A team of researchers has found a major security flaw in several popular disk-encryption technologies that leaves encrypted data vulnerable to attack and exposure, particularly when laptops are in sleep mode.

Researchers from the Electronic Frontier Foundation and Princeton University have cracked several widely used disk encryption technologies, including Microsoft's BitLocker, Apple's FileVault, TrueCrypt and dm-crypt.

Those disc encryption systems are designed to protect sensitive information if a computer is stolen or otherwise accessed, but researchers said data is still vulnerable because encryption keys and passwords stored in a computer's temporary memory, or RAM, don’t disappear immediately after losing power.

"People trust encryption to protect sensitive data when their computer is out of their immediate control," EFF spokesman Seth Schoen said. "But this new class of vulnerabilities shows it is not a sure thing.

“Whether your laptop is stolen or you simply lose track of it for a few minutes at airport security, the information inside can still be read by a clever attacker," he said.

Laptops are particularly vulnerable to attack when they are turned on but locked, or in sleep or hibernation mode entered when the laptop's cover is shut, the EFF said.

Researchers said that even though the machines require a password to unlock the screen, the encryption keys are already located in the RAM, which provides an opportunity for attackers with malicious intent.

For the full paper, "Lest We Remember: Cold Boot Attacks on Encryption Keys," a demonstration video and other background information, click here.

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Fanso.io Expands Payment Options With Centrobill Partnership

Payment services provider Centrobill and turnkey subscription platform builder Fanso have partnered to enhance payment options for online marketplace businesses using the Fanso script.

Sara Jay, Dan Leal to Co-Host Heineken Brewery Tour, XBIZ Amsterdam 'Performers' Rights' Panel

Sara Jay and "Porno" Dan Leal will co-host a tour of the historic Heineken brewing factory on Tuesday, Sept. 3 at 1 p.m., during the XBIZ Amsterdam conference.

Vixen, Julmodels to Host 'Club Vixen' Party at XBIZ Amsterdam

Vixen Media Group and premier European talent agency Julmodels will once again team up to host a lavish party at XBIZ Amsterdam: Club Vixen, set to take place the evening of Sept. 4.

Cherie DeVille Lambasts Laila Mickelwait's Anti-Pornhub Book in New Op-Ed

2023 XBIZ Performer of the Year Cherie DeVille has penned a new opinion piece for The Daily Beast, about a new book by religiously motivated anti-Pornhub crusader Laila Mickelwait.

TheArtemiXXX Launches Through YourPaysitePartner

Content creator Artemis Spiegel has launched his new site, TheArtemiXXX.com, through YourPaysitePartner (YPP).

Federal Prosecutors Seek 20-Year Sentences for Remaining Backpage Defendants

Federal prosecutors asked on Monday that the three remaining defendants in the protracted Backpage.com case in Arizona be sentenced to 20 years in prison each.

AI-Powered Chat Service 'Fanalytics' Launches

AI-powered chat service Fanalytics has debuted, aimed at OnlyFans content creators and agencies.

AEBN Publishes Popular Searches by Country for June, July

AEBN has released the popular searches from its straight and gay theaters in more than three dozen countries during June and July.

Sansyl to Host 'All Out' Opening Night Bash at XBIZ Amsterdam

The Sansyl Group, the Dutch parent company of PayBig, has signed on to sponsor the official opening night party of XBIZ Amsterdam.

FSC: California's Porn Age Verification Bill Defeated Over Budget Concerns

The California legislature’s age verification bill, one of numerous AV bills being sponsored around the country by anti-porn activists, will not be moving forward, Free Speech Coalition reported Tuesday.

Show More