<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
<channel>
<title>Engadget</title>
<link>http://www.engadget.com</link>
<description>Engadget</description>
<image>
<url>http://www.blogsmithmedia.com/www.engadget.com/media/feedlogo.gif</url>
<title>Engadget</title>
<link>http://www.engadget.com</link>
</image>
<language>en-us</language>
<copyright>Copyright 2012 Weblogs, Inc. The contents of this feed are available for non-commercial use only.</copyright>
<generator>Blogsmith http://www.blogsmith.com/</generator><item><title><![CDATA[Bootable flash key makes disk encryption attacks super-simple]]></title><link>http://www.engadget.com/2008/03/04/bootable-flash-key-makes-disk-encryption-attacks-super-simple/</link><guid isPermaLink="true">http://www.engadget.com/2008/03/04/bootable-flash-key-makes-disk-encryption-attacks-super-simple/</guid><comments>http://www.engadget.com/2008/03/04/bootable-flash-key-makes-disk-encryption-attacks-super-simple/#comments</comments><description><![CDATA[<div align="center"><a href="http://mcgrewsecurity.com/projects/msramdmp/"><img vspace="4" hspace="4" border="0" alt="" src="http://www.blogcdn.com/www.engadget.com/media/2008/03/3-3-08-mcgrew.jpg" /></a><br /></div>
Ruh roh, Shaggy -- you remember that <a href="http://www.engadget.com/2008/02/21/cold-boot-disk-encryption-attack-is-shockingly-effective/">disk encryption attack</a> that involved cooling off your target's RAM and yanking it to get a bitdump before the contents faded? Well, it looks like things just got a lot simpler for would-be attackers -- check out this USB flash key designed by security researcher Robert Wesley McGrew, which can boot your machine and dump the RAM to itself without altering its contents. That means you no longer need to actually pull the DIMMs or carry around an air duster; all an attacker needs is enough time to reboot your machine and copy the contents of your RAM. Of course, that takes time -- McGrew says things are running quite slowly right now, but he suspects his test machine is dropping down to USB 1.0 speeds. That's still not too reassuring -- looks like we'll be spending even more time with our machines from now on.<br /><br />[Via <a href="http://www.hackaday.com/2008/03/03/bootable-usb-ram-capture/">Hack a Day</a>]<p>Filed under: <a href="http://www.engadget.com/category/desktops/" rel="tag">Desktops</a>, <a href="http://www.engadget.com/category/laptops/" rel="tag">Laptops</a>, <a href="http://www.engadget.com/category/storage/" rel="tag">Storage</a></p><p style="padding:5px;background:#ddd;border:1px solid #ccc;clear:both;"><a href="http://www.engadget.com/2008/03/04/bootable-flash-key-makes-disk-encryption-attacks-super-simple/">Bootable flash key makes disk encryption attacks super-simple</a> originally appeared on <a href="http://www.engadget.com">Engadget</a> on Tue, 04 Mar 2008 06:58:00 EST.  Please see our <a href="http://www.weblogsinc.com/feed-terms/">terms for use of feeds</a>.</p><h6 style="clear: both; padding: 8px 0 0 0; height: 2px; font-size: 1px; border: 0; margin: 0; padding: 0;"></h6><a href=http://mcgrewsecurity.com/projects/msramdmp/>Read</a>&nbsp;|&nbsp;<a href="http://www.engadget.com/2008/03/04/bootable-flash-key-makes-disk-encryption-attacks-super-simple/" rel="bookmark" title="Permanent link to this entry">Permalink</a>&nbsp;|&nbsp;<a href="http://www.engadget.com/forward/1130744/" title="Send this entry to a friend via email">Email this</a>&nbsp;|&nbsp;<a href="http://www.engadget.com/2008/03/04/bootable-flash-key-makes-disk-encryption-attacks-super-simple/#comments" title="View reader comments on this entry">Comments</a>]]></description><category>disk encryption</category><category>DiskEncryption</category><category>encryption</category><category>ram</category><category>security</category><dc:creator><![CDATA[Nilay Patel]]></dc:creator><pubDate>Tue, 04 Mar 2008 06:58:00 EST</pubDate></item><item><title><![CDATA[Cold boot disk encryption attack is shockingly effective]]></title><link>http://www.engadget.com/2008/02/21/cold-boot-disk-encryption-attack-is-shockingly-effective/</link><guid isPermaLink="true">http://www.engadget.com/2008/02/21/cold-boot-disk-encryption-attack-is-shockingly-effective/</guid><comments>http://www.engadget.com/2008/02/21/cold-boot-disk-encryption-attack-is-shockingly-effective/#comments</comments><description><![CDATA[<div align="center"><a href="http://citp.princeton.edu/memory/"><img vspace="4" hspace="4" border="1" src="http://www.blogcdn.com/www.engadget.com/media/2008/02/2-21-08-laptop-ram.jpg" alt="" /></a><br /></div>
It's an old adage that no security measure is worth anything if an attacker has physical access to the machine, but things like heavy-duty disk <a href="http://engadget.com/tag/encryption">encryption</a> are supposed to at least slow things down. Sadly, that may not actually be the case, as a group of Princeton researchers has just published a paper detailing an exploit that requires little more than a spray duster and a screwdriver. Since the encryption key for systems like BitLocker and FileVault lives in RAM, all an attacker has to do to get it is cool the RAM modules with the air duster held upside down, yank the DIMM, and insert it into another machine, where it can then be read to access the key. Of course, this assumes that you've already typed in your password, but check the video after the break to see how long bits in RAM stay written -- even if you've turned off your computer, there's a chance the key can still be read. Looks like there's an actual benefit to MacBook Air's soldered-in RAM after all, eh?<p><a href="http://www.engadget.com/2008/02/21/cold-boot-disk-encryption-attack-is-shockingly-effective/" rel="bookmark">Continue reading <em>Cold boot disk encryption attack is shockingly effective</em></a></p><p>Filed under: <a href="http://www.engadget.com/category/desktops/" rel="tag">Desktops</a>, <a href="http://www.engadget.com/category/laptops/" rel="tag">Laptops</a>, <a href="http://www.engadget.com/category/storage/" rel="tag">Storage</a></p><p style="padding:5px;background:#ddd;border:1px solid #ccc;clear:both;"><a href="http://www.engadget.com/2008/02/21/cold-boot-disk-encryption-attack-is-shockingly-effective/">Cold boot disk encryption attack is shockingly effective</a> originally appeared on <a href="http://www.engadget.com">Engadget</a> on Thu, 21 Feb 2008 18:18:00 EST.  Please see our <a href="http://www.weblogsinc.com/feed-terms/">terms for use of feeds</a>.</p><h6 style="clear: both; padding: 8px 0 0 0; height: 2px; font-size: 1px; border: 0; margin: 0; padding: 0;"></h6><a href=http://citp.princeton.edu/memory/>Read</a>&nbsp;|&nbsp;<a href="http://www.engadget.com/2008/02/21/cold-boot-disk-encryption-attack-is-shockingly-effective/" rel="bookmark" title="Permanent link to this entry">Permalink</a>&nbsp;|&nbsp;<a href="http://www.engadget.com/forward/1121416/" title="Send this entry to a friend via email">Email this</a>&nbsp;|&nbsp;<a href="http://www.engadget.com/2008/02/21/cold-boot-disk-encryption-attack-is-shockingly-effective/#comments" title="View reader comments on this entry">Comments</a>]]></description><category>disk encryption</category><category>DiskEncryption</category><category>encryption</category><category>security</category><dc:creator><![CDATA[Nilay Patel]]></dc:creator><pubDate>Thu, 21 Feb 2008 18:18:00 EST</pubDate></item></channel></rss>
