On CHOW: Does drinking ice water burn calories?

Images: How to bypass FileVault, BitLocker security

Tags: news, security, filevault, bitlocker, encryption

  • Save
  • Digg This
  • 7
Step 6: Testing

Step 6: Testing
How can we tell whether Applebaum is actually able to glean the encryption key from the MacBook?

The answer is simple: an Apple utility called "hdiutil" can display the AES key for a FileVault volume as long as the passphrase is typed in first. If Applebaum's able to find it on his own, he's discovered a way to bypass FileVault--at least when the computer is turned on or is in sleep mode.

To use hdiutil, I logged out of the Breakme account, meaning the FileVault volume would be automatically unmounted. Then I made a copy of the breakme.sparseimage file and extracted the AES key by running hdiutil and typing in the passphrase. The key turned out to be: dd6a242a3a90ee1f60a8c53db59a4133.

The length of the AES key in OS X Tiger is 32 hexadecimal characters, or 128 bits. While FileVault in OS X Leopard can use a 256-bit AES key, the extraction process would be the same.

                 

Print/View all Posts Comments on this gallery

Interesting but "old news"!techrepublic@...  | 02/26/08
I also thought it was public domain knowledge alreadylouis.slabbert@...  | 02/26/08
This whole 'news' story is totally blown out of proportionrobo_dev  | 02/26/08
Who needs the Car keys... ?louis.slabbert@...  | 02/29/08
RE: (Images: How to bypass FileVault, BitLocker security)arountree@...  | 02/26/08
RE: (Images: How to bypass FileVault, BitLocker security)azadb@...  | 02/26/08
Life?shazardy2000@...  | 03/04/08
Apparently the author does not know how to configure TrueCryptJames Brown  | 03/15/08
Your right... all the stories ive seen unfairly dog truecryptpcguy777  | 03/15/08

What do you think?

TechRepublic Featured Jobs

Job Title/Location Posted
  • Powered by: Simply Hired
  • .

The Green Enterprise

advertisement
Click Here