Security Flaw in Popular Disk Encryption Technologies

Martin Laabs martin.laabs at mailbox.tu-dresden.de
Tue Feb 26 18:46:29 UTC 2008


Hi,

Maybe someone could implement a memory section
that is overwritten by the bios after reboot.
Then all the sensitive keys could be stored there.

This would prevent an attack that just boots from
another media and dump the whole memory out of i.e.
an USB-stick.

Preventing the physical access to the memory modules
could be done with a light sensor or a simple switch
at the computer case. If you implement also a temperature-
sensor near the memory-modules you could prevent cooling
them down before removal. (You'd just overwrite the keys
if the temperature falls i.e. below 10°C)

Greets,
   Martin L.


More information about the freebsd-hackers mailing list