Stealing Disk Encryption Keys From RAM
Fascinating.
You can read more here.
Fascinating.
You can read more here.
This entry was posted on Thursday, February 21st, 2008 at 5:40 am by Anil Polat and is filed under data theft. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

February 21st, 2008 at 6:55 pm
I heard Nicko Van Someren talk about finding keys in memory at RSA Europe in 2000, but when he spoke the ability steal RAM from a sleeping computer was unknown. Fascinating demonstration of the exploit. This is why cryptomodules must provide the ability to zeroize keys, regardless of where they are stored.
From what I’ve heard, RAM need not be overwritten more than once like magnetic media must, but perhaps that is a commonly held mistaken impression also.
February 21st, 2008 at 8:37 pm
Nice, I think I’m going to go home and experiment a little…
http://citp.princeton.edu/memory/exp/