Error » Microsoft Error! » Microsoft Operating Systems Error » Microsoft windows vista error » Microsoft Downplays Windows Vista Encryption Cracks

Microsoft windows vista error all errors related to microsoft windows vista

Post New Thread Reply
  Microsoft Downplays Windows Vista Encryption Cracks
LinkBack Thread Tools Display Modes
Old 03-Mar-2008, 01:08 AM   #1 (permalink)
Administrator
 
Anilrgowda's Avatar

Posts: 18,762
Join Date: Jan 2006
Rep Power: 10 Anilrgowda is on a distinguished road

IM:
Default Microsoft Downplays Windows Vista Encryption Cracks



The concept behind Cold-Boot attacks on encryption keys stored in the computer's DRAM is not new. The implications of physical memory attacks, in the context of Windows Vista BitLocker Drive Encryption, were discussed at Hack in the Box 2006 by Douglas MacIver, Penetration Engineer, Microsoft Penetration Team.Although the Cold-Boot attack was a strategy all too familiar among the members of the security industry and of the security team over at Redmond, a demonstration of the encryption keys cracks, put together by Princeton researchers, brought the concept to reality, retrieving cryptographic key material from frozen (literally) DRAM.

But not only Vista's BitLocker technology is susceptible to Cold-Boot attacks, FileVault, dm-crypt, and TrueCrypt encryption keys are also stored in physical memory and can be retrieved by an attacker with physical access and the right algorithms designed for finding cryptographic keys in memory images. Robert Hensing, Technical Lead - Microsoft Product Support Services, stressed the fact that an eventual attacker needs to freeze the physical system memory as fast as possible in order to ensure that the RAM will retain the contents. And even if this happens, there is a certain level of decay of the gost image stored in RAM.

"I'd like to take a step back and, from a BitLocker perspective, detail some of the assumptions that have to be made for this attack to be successful: physical access to the machine; the user's laptop would likely have to be in sleep mode, rather than hibernate mode or powered off; the user would have chosen not to implement multi-factor pre-boot authentication and the person who finds/steals the laptop must be knowledgeable and interested enough to execute this attack on the laptop they just stole. I would posit that the opportunistic laptop thief is somewhat unlikely to carry a separate laptop on which they will have installed tools that allow them to reconstruct cryptographic keys - or for that matter have a can of compressed air handy," argued Microsoft senior product manager for Windows Vista security Russell Humphries.

With Windows Vista SP1, Microsoft has enhanced the protection level offered by BitLocker, in the sense that users are now enabled not only to enter a PIN or insert a USB stick with a secret key, but do both in order to make the operating system boot or resume from hibernate mode. "Quality security research helps our customers and the industry in general raise the security bar, and I applaud it; but let's also keep in mind that technologies like BitLocker provide a very valuable service to users and helps them protect data on their PCs. BitLocker's range of deployment options, ranging from single-factor authentication with sleep mode to TPM+PIN+USB with hibernation only, allow customers to find the right balance of security and convenience for their data," Humphries added.

source: news.softpedia.com


------------------


Anilrgowda is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump


All times are GMT -8. The time now is 03:44 PM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231