DRam
Data can remain in stored in memory even after the system is shut down

DRam crack breaks encryption software

Researchers find way to foil disk encryption

Shaun Nichols in California

Disk encryption software used on many systems can be circumvented using what researchers referred to as "simple non-destructive techniques".

A report from researchers at the Electronic Frontier Foundation, Princeton University and Wind River Systems concluded that many current consumer disk encryption programs can be compromised via a computer's DRam.

Advertisement

The problem is that data can remain in stored in memory even after the system is shut down. By cold-booting the system, an attacker could access data from the DRam and retrieve encryption keys.

"Most experts assume that a computer's memory is erased almost immediately when it loses power, or that whatever data remains is difficult to retrieve without specialised equipment," said the researchers.

"Ordinary DRam typically loses its contents gradually over a period of seconds, even at standard operating temperatures.

"Even if the chips are removed from the motherboard, the data will persist for minutes or even hours if the chips are kept at low temperatures."

Most experts assume that a computer's memory is erased almost immediately when it loses power

Security researcher 

The researchers claimed that laptops are at particular risk because an attacker could use the tactic to break into a system even if screen locks are in place.

To counter the attacks, the researchers suggested that system builders take measures to make data on memory chips decay more rapidly or block the use of memory-dump software used to retrieve data from memory chips.

However, the researchers concluded that the problem will not be easy to solve.

"Unlike many security problems, this is not a minor flaw; it is a fundamental limitation in the way these systems were designed," said Princeton researcher J. Alex Halderman.

"We have broken disk encryption products in exactly the case when they seem to be most important these days."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

femtocell kit

Airvana unveils the 'Boyfriend-Buster'

Femtocells could be used to keep an eye on the kids

HTC Hero

Video: HTC Hero launch

Handset maker unveils its latest Android-based smartphone

IT white papers

Search white papers

Top categories

Poll

Poll: Should Twitter charge businesses?

Poll: Should Twitter charge businesses?

Would your firm consider paying for its Twitter account?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Firefox

Review: Mozilla Firefox 3.5

V3.co.uk gets hands on with Mozilla's latest web browser to...

Heads up: IE8 to be pushed out to enterprise users

Microsoft is set to make Internet Explorer 8 (IE8) available...

Palm Pre

O2 tipped as Palm Pre carrier in the UK

Operator looks likely to add the Palm smartphone to its...

Motorola logo

Motorola demos femtocell hardware

Device combines femtocell, SIP softphone and digital photoframe

Primary Navigation