Hacker
Microsoft and PGP have issued statements on the disk encryption report

Encryption firms speak up on DRam attack

Security vendors note difficulty of real-world attack

Shaun Nichols in California

Software vendors are defending their products and looking to ease public fears following a recent report on vulnerabilities in disk encryption.

Microsoft and PGP were among the firms to issue statements on the report, which detailed ways in which an attacker could recover encryption keys by accessing the memory on a recently shut-down compouter.

Advertisement

The report states that even after the computer has been powered off an attacker could partially boot up the system, retrieve the contents of the DRam chips, and use the information to thwart disk encryption tools.

"While the report's authors did not attempt to breach any PGP Corporation products, the technique could theoretically be used to attack all current-generation full disk encryption products," PGP said in an official statement.

"In practical use, however, it is unlikely that most users would be subject to this type of attack."

The company urged users to employ an encrypted virtual disk volume which is un-mounted when not in use.

The thing to keep in mind here is the old adage of balancing security, usability and risk

Russ Humphries Security product manager, Microsoft Windows Vista

Check Point Software issued its own release which noted the difficulty surrounding a theoretical "cold boot" attack.

"First, the attacker must gain physical possession of the computer either while it is running or within a few minutes of shutting down," said the company.

"Then the memory must be dramatically cooled down in order to sustain the contents for any meaningful length of time so it can be copied in its entirety. "

Mic rosoft's Vista security product manager Russ Humphries defended the company's BitLocker software on a company blog.

"The thing to keep in mind here is the old adage of balancing security, usability and risk," said Humphries.

"Quality security research helps our customers and the industry in general raise the security bar and I applaud it.

"But let's also keep in mind that technologies like BitLocker provide a very valuable service to users and helps them protect data on their PCs."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

DRam

DRam crack breaks encryption software

Researchers find way to foil disk encryption

DRam makers suffer 'disastrous' revenue drop

Global revenue down 19 per cent in last quarter of 2007

Memory chip prices remain weak

Good news for buyers

Semiconductor spending to decline in 2008

Gartner predicts drop of 9.9 per cent

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

old computer

Government honours veterans of Bletchley Park at last

Surviving veterans of the code-breaking facility to receive badge of...

Motorola MC55 Enterprise Digital Assistant

Review: Motorola MC55 Enterprise Digital Assistant

A rugged Windows Mobile device for mobile workers

BT

BT promises 1.5m fibre connections by summer 2010

Telco begins major rollout in 69 locations across the UK

Primary Navigation