On BNET: How to improve your gas mileage

Images: How to bypass FileVault, BitLocker security

Tags: news, security, filevault, bitlocker, encryption

  • Save
  • Digg This
  • 7
Step 1: The test

Step 1: The test
A team of security researchers on Thursday reported serious vulnerabilities in disk encryption products including Microsoft's BitLocker, Apple's FileVault, and the open-source TrueCrypt. Because memory contents are not deleted when the computer is rebooted, someone can gain access to the contents of the encrypted volume by restarting it and extracting the encryption keys. Another way to extract the keys is to supercool the memory--a can of compressed air held upside-down works--and transfer the RAM to another computer where it can be read.

We decided to put their claims to the test. Because I'm an Apple user, I wanted to see if they could extract the AES encryption key from a MacBook running OS X Tiger. AES is, of course, the Advanced Encryption Standard used in innumerable security applications.

Step 1 involved creating a new password-protected account called "Breakme" with FileVault turned on and encrypted swap activated. I turned on the locking screensaver and presented Jacob Applebaum, one of the researchers on the team, with the FileVault-protected laptop. To pass the test, Applebaum needed to extract the 128-bit AES key used to encrypt the Breakme account.

Text by Declan McCullagh

                 

Print/View all Posts Comments on this gallery

Interesting but "old news"!techrepublic@...  | 02/26/08
I also thought it was public domain knowledge alreadylouis.slabbert@...  | 02/26/08
This whole 'news' story is totally blown out of proportionrobo_dev  | 02/26/08
Who needs the Car keys... ?louis.slabbert@...  | 02/29/08
RE: (Images: How to bypass FileVault, BitLocker security)arountree@...  | 02/26/08
RE: (Images: How to bypass FileVault, BitLocker security)azadb@...  | 02/26/08
Life?shazardy2000@...  | 03/04/08
Apparently the author does not know how to configure TrueCryptJames Brown  | 03/15/08
Your right... all the stories ive seen unfairly dog truecryptpcguy777  | 03/15/08

What do you think?


advertisement
Click Here