Hacker
Microsoft and PGP have issued statements on the disk encryption report

Encryption firms speak up on DRam attack

Security vendors note difficulty of real-world attack

Written by Shaun Nichols in California

Software vendors are defending their products and looking to ease public fears following a recent report on vulnerabilities in disk encryption.

Microsoft and PGP were among the firms to issue statements on the report, which detailed ways in which an attacker could recover encryption keys by accessing the memory on a recently shut-down compouter.

Advertisement

The report states that even after the computer has been powered off an attacker could partially boot up the system, retrieve the contents of the DRam chips, and use the information to thwart disk encryption tools.

"While the report's authors did not attempt to breach any PGP Corporation products, the technique could theoretically be used to attack all current-generation full disk encryption products," PGP said in an official statement.

"In practical use, however, it is unlikely that most users would be subject to this type of attack."

The company urged users to employ an encrypted virtual disk volume which is un-mounted when not in use.

The thing to keep in mind here is the old adage of balancing security, usability and risk

Russ Humphries Security product manager, Microsoft Windows Vista

Check Point Software issued its own release which noted the difficulty surrounding a theoretical "cold boot" attack.

"First, the attacker must gain physical possession of the computer either while it is running or within a few minutes of shutting down," said the company.

"Then the memory must be dramatically cooled down in order to sustain the contents for any meaningful length of time so it can be copied in its entirety. "

Mic rosoft's Vista security product manager Russ Humphries defended the company's BitLocker software on a company blog.

"The thing to keep in mind here is the old adage of balancing security, usability and risk," said Humphries.

"Quality security research helps our customers and the industry in general raise the security bar and I applaud it.

"But let's also keep in mind that technologies like BitLocker provide a very valuable service to users and helps them protect data on their PCs."

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols

19 Dec 2008

2.93 MBPodcast Special: Views from the Valley More...

Podcast image

18 Dec 2008

17.6 MBComputing podcast - the highlights of 2008 More...

Shaun Nichols and Iain Thomson

15 Dec 2008

4.98 MBPodcast Special: Views from the Valley More...

Poll

Communications super-database

Communications super-database

Should the government be allowed to track our emails and internet use?

Previous poll results

Spotlight

CES logo

CES 2009 preview

vnunet.com looks at what is in store for delegates at...  More...

Lotus Notes

IBM unveils Lotus Notes 8.5

Collaboration suite beefs up Mac support and cuts email storage...  More...

Asus Eee Top

Review: Asus Eee Top ET1602 PC

A compact, touchscreen desktop PC best suited for basic computing...  More...

Moto W233 Renew

Motorola launches eco-friendly mobile phone

Moto W233 Renew handset is made out of recycled water...  More...

Primary Navigation