Wow. This is amazing and scary at the same time. Basically, some researchers figured out that in order to bypass harddrive encryption when you have physical control over the device, you can read the contents of the RAM chips to obtain the encryption key. This is not an attack on the encryption itself. It's like finding the key to the super-secure door under the welcome mat. Even if power is cut from the device, data stays in RAM for a certain amount of time (this time can be expanded by freezing the chips with a bottle of canned air). Booting the device to a special tool allows for the memory to be copied and analyzed. They can even remove the ram chip and put it in another laptop for analysis. The only secure way to protect yourself is to power the laptop down completely and guard it for a few minutes for the memory to finally clear.
Be sure to spend the 5 minutes watching the video in the article.
What's even more interesting is that most folks transport their laptops in a power saving mode, such as in standby or hibernation. Even I carry my laptop around in standby. All it takes is for someone to steal the laptop and the encryption won't matter.
This just proves that carrying information around is not safe. The approach I've been trying to take with my users is to give up the fat client laptops for a thin client laptop approach, such as offerings from Neoware or HP. The idea is to leave all information on the corporate network and require my traveling users to log in via secure VPN and RDP directly to their desktops. On top of not storing information, the thin clients are sturdy, don't have moving parts, run our VPN software just fine, easy to replace (no user specific information to transfer to another laptop), and are fairly cheap (approx a third of the cost of a regular laptop). I usually just keep a couple laying around for loaners; so if someone who doesn't travel much can check one out and I don't have to set up anything on it for them, only have to enable RDP on their desktops.
February 22, 2008
September 01, 2006
Wormy bots exploiting Windows Server flaw: "It took less than a week for underground programmers to modify their bot software to take advantage of the latest Windows flaw, described in security bulletin MS06-040."
August 11, 2006
As the spotlight on a dangerous Windows vulnerability grows brighter by the hour, security analysts Thursday said that it's not hype driving the alarms, but genuine fear that a major worm attack is just days away. This is no drill. Thursday's deepening concern was fueled by several releases of new exploit code.
A lot of exploit code activity over this one. See yesterday's post about eEye's scanner for help identifying systems that haven't been patched.
read more | digg story
August 10, 2006
eEye Digital Security Retina MS06-040 NetApi32 Scanner: "The Retina MS06-040 NetApi32 Scanner is being made available free of charge by eEye. The tool will scan multiple addresses at once to determine if any are vulnerable to the Server Service flaw reported in the Microsoft Bulletin MS06-040. If an IP address is found to be vulnerable, the Retina MS06-040 NetApi32 Scanner will flag that IP address.
This tool does not require administrative privileges on the scanned machines in order to determine if the systems are vulnerable."
Much props to Marc Maiffret, the Chief Hacking Officer at eEye Digital Security. I applaud his company's community involvement.. It's nice to see a company ask the community if they have a need for a product and then go out of their way to deliver, free of charge.
May 05, 2006
Wired 14.05: The RFID Hacking Underground: "They can steal your smartcard, lift your passport, jack your car, even clone the chip in your arm. And you won't feel a thing. 5 tales from the RFID-hacking underground."
May 01, 2006
Computerworld > The best person to hack your system is you: "I’ve always been a firm believer in the idea of hacking yourself. After all, if you don’t hack yourself, the hackers will. So, if you’re a good security administrator, you must learn about the various hacking tools that might be used against your environment, become familiar with them, and use them. "
April 30, 2006
Security Reference Guide > Handheld War-driving: "This article will take a look at handheld devices and the tools/equipment that are available for the war-driver on the go. As you will see, there are some facets of PDA based war-driving that have no equal in the PC world (for the price)."
Theoretical Hacking for IT Managers | Linux Journal: "Not everyone has 'l33t skilz' or mass amounts of hardened TCP/IP stack programming experience. When I'm at work, I don't look at logs all day long, nor do I run security audits every five minutes. I do my job, which takes all of my time. This is the situation for most small to medium sized companies that have only a few IT guys. So how does an everyday IT guy handle the constant threat of impending attack?"
April 07, 2006
Beyond Rootkits: World's First Standalone Kernel Mode Bot?: "A European student has just developed a Proof of Concept for what the developer believes is the world's first kernel mode IRCbot.
The creator, Tibbar ('Rabbit' spelled backwards), says the difference between this innovation and standard Windows rootkits lies in its crossover ability. Most Windows-based rootkits hide in device drivers, then depend on outside, usermode applications to get anything done."
March 23, 2006
Microsoft Confirms 'Highly Critical' IE Hole: "Microsoft plans to release a pre-patch advisory with workarounds for a 'highly critical' vulnerability that could put millions of Internet Explorer users at the mercy of malicious hackers."
March 14, 2006
A summary of the 10 best LiveCD distributions dealing with security (pen testing, forensics & recovery). With links to download and a little information about each one.
read more | digg story