Hacker
Microsoft and PGP have issued statements on the disk encryption report
R E L A T E D   C O N T E N T
ADVERTISEMENT

Encryption firms speak up on DRam attack

Security vendors note difficulty of real-world attack

Shaun Nichols in California, vnunet.com 29 Feb 2008
ADVERTISEMENT

Software vendors are defending their products and looking to ease public fears following a recent report on vulnerabilities in disk encryption.

Microsoft and PGP were among the firms to issue statements on the report, which detailed ways in which an attacker could recover encryption keys by accessing the memory on a recently shut-down compouter.

The report states that even after the computer has been powered off an attacker could partially boot up the system, retrieve the contents of the DRam chips, and use the information to thwart disk encryption tools.

"While the report's authors did not attempt to breach any PGP Corporation products, the technique could theoretically be used to attack all current-generation full disk encryption products," PGP said in an official statement.

"In practical use, however, it is unlikely that most users would be subject to this type of attack."

The company urged users to employ an encrypted virtual disk volume which is un-mounted when not in use.

Check Point Software issued its own release which noted the difficulty surrounding a theoretical "cold boot" attack.

"First, the attacker must gain physical possession of the computer either while it is running or within a few minutes of shutting down," said the company.

"Then the memory must be dramatically cooled down in order to sustain the contents for any meaningful length of time so it can be copied in its entirety. "

Mic rosoft's Vista security product manager Russ Humphries defended the company's BitLocker software on a company blog.

"The thing to keep in mind here is the old adage of balancing security, usability and risk," said Humphries.

"Quality security research helps our customers and the industry in general raise the security bar and I applaud it.

"But let's also keep in mind that technologies like BitLocker provide a very valuable service to users and helps them protect data on their PCs."

Global revenue down 19 per cent in last quarter of 2007  04 Feb 2008
Good news for buyers  21 Jan 2008
Gartner predicts drop of 9.9 per cent  21 Dec 2007
Contract chips, DRam and Flash drive growth  04 Dec 2007

All Hacking
Tags: Security

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
United Kingdom | VOSA
Management Information Analyst - Up to £30,231 plus benefits - South West This is an excellent opportunity for an experienced Business Analyst or an ambitious Information Analyst to influence a national organisation and contribute to ... more >
Isle of Man, United Kingdom | PDMS
Experienced Developer (C#/.NET) - Isle of Man - £30,000 - £55,000 PDMS is a growing and dynamic software house with offices in the Isle of Man and London. We work with a wide variety of ... more >
Central London, United Kingdom | Royal Academy of Music
Head of Technology - London - Competitive salary & benefits The Head of Technology will lead and direct the Academy's Technology department, working with Senior Management to define and implement the IT strategy. The postholder ... more >
United Kingdom | Ofgem
IT Network and Security Engineer £40,000 per annum The Office of Gas and Electricity Markets (Ofgem) is the regulator for Britain's gas and electricity industries. Our role is to protect consumers and enable them to ... more >
More job opportunities