All the latest UK technology news, reviews and analysis

Encryption firms speak up on DRam attack

by Shaun Nichols

More from this author

29 Feb 2008

Be the first to comment

  • Tweet this
Hacker
Microsoft and PGP have issued statements on the disk encryption report

Software vendors are defending their products and looking to ease public fears following a recent report on vulnerabilities in disk encryption.

Microsoft and PGP were among the firms to issue statements on the report, which detailed ways in which an attacker could recover encryption keys by accessing the memory on a recently shut-down compouter.

The report states that even after the computer has been powered off an attacker could partially boot up the system, retrieve the contents of the DRam chips, and use the information to thwart disk encryption tools.

"While the report's authors did not attempt to breach any PGP Corporation products, the technique could theoretically be used to attack all current-generation full disk encryption products," PGP said in an official statement.

"In practical use, however, it is unlikely that most users would be subject to this type of attack."

The company urged users to employ an encrypted virtual disk volume which is un-mounted when not in use.

Check Point Software issued its own release which noted the difficulty surrounding a theoretical "cold boot" attack.

"First, the attacker must gain physical possession of the computer either while it is running or within a few minutes of shutting down," said the company.

"Then the memory must be dramatically cooled down in order to sustain the contents for any meaningful length of time so it can be copied in its entirety. "

Mic rosoft's Vista security product manager Russ Humphries defended the company's BitLocker software on a company blog.

"The thing to keep in mind here is the old adage of balancing security, usability and risk," said Humphries.

"Quality security research helps our customers and the industry in general raise the security bar and I applaud it.

"But let's also keep in mind that technologies like BitLocker provide a very valuable service to users and helps them protect data on their PCs."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Infrastructure Technical Lead

Position: Infrastructure Technical Lead Experience...

Channel Manager / Sales Manager / Software - 40k to 45k ote 20k

Channel Manager / Sales Manager /Software solutions...

BUSINESS SALES / SOFTWARE SALES / BUSINESS CONSULTANT 60K + BONUS

BUSINESS SALES / IT SALES / BUSINESS CONSULTANT / LONDON...

Technical Sales / Direct Sales / Software / London 45K OTE 90K

TECHNICAL SALES / ACCOUNT EXECUTIVE / SOFTWARE SALES...

To send to more than one email address, simply separate each address with a comma.