The PuritanBoard  

Go Back   The PuritanBoard > General Forums > Computers & Technology

Computers & Technology Bible software, computer support questions and other helpful technology matters

Remember the Sabbath day, to keep it holy. Six days you shall labor and do all your work, but the seventh day is the Sabbath of the LORD your God.

» Online Users: 84
22 members and 62 guests
Backwoods Presbyterian, BobVigneault, Brad, caoclan, Davidius, Grace Alone, NaphtaliPress, Pergamum, Pilgrim72, PuritanBouncer, Seb, smhbbag, Southern Presbyterian, Superstu, Zenas
Most users ever online was 856, 07-06-2007 at 12:19 AM.
Closed Thread
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-22-2008, 11:49 AM
Puritanboard Sophomore
 
Join Date: Mar 2003
Location: Germantown, TN
Posts: 630
Thanks: 5
Thanked 26 Times in 19 Posts
New way to break disk encryption

A way to break disk encription works on PC's and Mac's.
__________________
Soli Deo Gloria

John Schultz
Member, Riveroaks Reformed Presbyterian Church (PCA)
Germantown, TN

"The reason why we worship God in a slight way is because we do not see God in His glory"
Jeremiah Burroughs
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #2 (permalink)  
Old 02-22-2008, 01:13 PM
victorbravo's Avatar
Moderator
 
Join Date: Aug 2005
Location: Tacoma, WA
Posts: 3,485
Blog Entries: 1
Thanks: 106
Thanked 624 Times in 377 Posts
Quote:
Originally Posted by jfschultz View Post
A way to break disk encription works on PC's and Mac's.
Well that's nice to know. Reaffirms my decision to ecrypt my old hard drives with a sledgehammer.

It is a good reminder to shut down when not in use. Maybe a bit inconvenient, but good practice.
__________________
R.Vic Bottomly
Providence Reformed Baptist Church, Tacoma, WA

Click to get: Board Rules -- Signature Requirements -- Suggestions?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #3 (permalink)  
Old 02-22-2008, 01:57 PM
larryjf's Avatar
Puritanboard Junior
 
Join Date: Dec 2004
Location: Boothwyn, PA
Posts: 1,222
Blog Entries: 1
Thanks: 59
Thanked 224 Times in 136 Posts
That's ok...when quantum computing is fully developed most current methodologies of cryptography will be useless anyway...except for the advances being made in quantum cryptography.
__________________
Larry Bray
Training for Elder - Reformed Presbyterian Church of Boothwyn, PCA
Boothwyn, PA - http://www.rpcb.org/

Free Online Reformed Seminary - http://www.tnars.net

-----------------------------------------------------
"The best Christian is still a poor Christian" - R.B. Kuiper
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #4 (permalink)  
Old 02-22-2008, 02:07 PM
larryjf's Avatar
Puritanboard Junior
 
Join Date: Dec 2004
Location: Boothwyn, PA
Posts: 1,222
Blog Entries: 1
Thanks: 59
Thanked 224 Times in 136 Posts
I believe "Loop AES" encryption uses key scrubbing and such to counteract this kind of attack.

I wonder if any encryption systems use SRAM instead of DRAM.
__________________
Larry Bray
Training for Elder - Reformed Presbyterian Church of Boothwyn, PCA
Boothwyn, PA - http://www.rpcb.org/

Free Online Reformed Seminary - http://www.tnars.net

-----------------------------------------------------
"The best Christian is still a poor Christian" - R.B. Kuiper
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #5 (permalink)  
Old 02-22-2008, 02:52 PM
Civbert's Avatar
Puritanboard Junior
 
Join Date: Nov 2005
Location: State of Franklin
Posts: 1,876
Thanks: 110
Thanked 67 Times in 47 Posts
Once someone has your machine - they own it. It's just a matter of time. This only demonstrates that there are tools now that make it even easier and faster to crack your PC, even if your encrypt your your files.

If you merely have password protection, there are other tools that look for your encrypted password on your drive. This is a "known" location. Then they use cracking programs, some use"rainbow tables" and even some web based tools, that can break most passwords in a matter of hours - or at most a couple days.

However, if you encrypt a whole drive or directory, it isn't enough to crack the user password. That will only get access to the OS and any un-encrypt files. But with this method, they get your encryption key right out of your RAM. And they don't even need your user password first! Brilliant!

This will save the cracker hours and days of work. I'm really impressed on how easy their method is. However, the cracker needs to grab your machine while it's still hot, and work fast. And it seems that an easy solution would be to over-write the ram with random bits at shut down. I'd think this would be easy to do by software, and even better would be ram that does this automatically.

But the trend now is to make your ram more permanent so you PC will always stay semi-booted - with much of the OS permanently loaded. This will produce "instant-on" PCs. No more waiting for your PC to boot up. But it sounds like this will leave you even more vulnerable to this kind of attack. Someone could get your PC hours or days after you shut down, and steal vital information from it. Hmmm.

So just remember this rule, if someone steals your computer, they "own" it. Don't count on a user password to protect your PC if it's stolen. Disk encryption is still the best way to protect your data. Now you just need to find a what to wipe the ram when you shut down.
__________________
R. Anthony Coletti
Midway Presbyterian Church (PCA)
Jonesborough, TN
[i]et venite et arguite me dicit Dominus[/i]
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #6 (permalink)  
Old 02-22-2008, 03:33 PM
victorbravo's Avatar
Moderator
 
Join Date: Aug 2005
Location: Tacoma, WA
Posts: 3,485
Blog Entries: 1
Thanks: 106
Thanked 624 Times in 377 Posts
Quote:
Originally Posted by Civbert View Post
Now you just need to find a what to wipe the ram when you shut down.
You suppose taking out the RAM and wiping it real fast with a piece of staticy wool will do it?

I'm only half joking.
__________________
R.Vic Bottomly
Providence Reformed Baptist Church, Tacoma, WA

Click to get: Board Rules -- Signature Requirements -- Suggestions?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #7 (permalink)  
Old 02-22-2008, 03:52 PM
Coram Deo's Avatar
Puritanboard Junior
 
Join Date: Jan 2006
Location: Denton, Maryland America
Posts: 1,792
Thanks: 315
Thanked 147 Times in 103 Posts
Run your OS and Store all your Files from a Thumb Drive....

They can get your computer if they want but they can get no information or data but only an empty shell without having the thumb drive....
__________________
Michael Daniels
Reformed, RPCNA
Denton, Maryland

[i][b]As For Me And My House, We Will Serve The Lord[/i][/b]

[SIZE="1"][I][FONT="Century Gothic"]Unum Deum in Trinitate: Pater, Filius, et Spiritus Sanctus [RIGHT]Sola scriptura - Sola gratia - Sola fide - Solus Christus - Soli Deo gloria - Solum psalterium - Lex talionis[/RIGHT][/FONT][/I][/SIZE]
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #8 (permalink)  
Old 02-22-2008, 06:31 PM
Puritanboard Freshman
 
Join Date: Mar 2006
Location: Cottonwood, AZ
Posts: 190
Thanks: 77
Thanked 22 Times in 18 Posts
I feel like i walked into a ultra secret spy site. Most computer user won't ever have anything worth breaking into a home or office with a can of liquid nitrogen, tear apart your computer, freeze your ram.. all within minutes of you walking out the door. Generally speaking if they have physical access to your computer it would be sooo much easier to put a keystroke logger on it an have it email you the results (you could use a usb flashdrive with a small OS on it as well), rather than perform some kind of mission impossible for your data. Your best security for this kind of attack is a mean dog who doesn't like strangers..
__________________
Josh Taylor
Verde Valley Reformed Chapel, OPC
Cottonwood, AZ
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #9 (permalink)  
Old 02-22-2008, 10:54 PM
larryjf's Avatar
Puritanboard Junior
 
Join Date: Dec 2004
Location: Boothwyn, PA
Posts: 1,222
Blog Entries: 1
Thanks: 59
Thanked 224 Times in 136 Posts
Another way to stay safe is just to not let folks know you have a computer. Get one of them new Apple laptops that fit in a manila envelope. When you're done using it, put it in an envelope and file it...nobody will be the wiser.

__________________
Larry Bray
Training for Elder - Reformed Presbyterian Church of Boothwyn, PCA
Boothwyn, PA - http://www.rpcb.org/

Free Online Reformed Seminary - http://www.tnars.net

-----------------------------------------------------
"The best Christian is still a poor Christian" - R.B. Kuiper
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #10 (permalink)  
Old 02-23-2008, 06:53 AM
Puritanboard Freshman
 
Join Date: Mar 2006
Location: Cottonwood, AZ
Posts: 190
Thanks: 77
Thanked 22 Times in 18 Posts
Here is what the site recommends for you to protect yourself from this exploit.

Quote:
Q. What can users do to protect themselves?
A. The most effective way for users to protect themselves is to fully shut down their computers several minutes before any situation in which the computers’ physical security could be compromised.
__________________
Josh Taylor
Verde Valley Reformed Chapel, OPC
Cottonwood, AZ
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Powered by vBadvanced CMPS v3.0.1

All times are GMT -4. The time now is 08:58 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.
Copyright © 2002-2008 PuritanBoard.com
Hosted by WebsiteMaven - helping ministries with web hosting advice, reviews, and design.
Westminster Abbey © Confessional Presbyterian Presses - used with permission.
Add Our Custom Button to your Google Toolbar

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64