Disk encryption: Can you trust it?
Computer scientists have discovered a novel way to bypass the encryption used in programs like Microsoft's BitLocker and Apple's FileVault and then view the contents of supposedly secure files. — In a paper (PDF) published Thursday that could prompt …
Context & Ripple Effects
Microsoft pitched BitLocker as a security centerpiece of Vista, and CNET examined how its full-disk encryption worked back in December 2006. On Thursday, researchers published a paper showing that the encryption keys those products keep in memory survive brief power loss, letting an attacker with physical access recover them and read supposedly secure files on machines running BitLocker or Apple's FileVault.
The result traveled quickly for academic work — Princeton-affiliated researchers' writeup was picked up the same day at Freedom to Tinker under the name 'cold boot attacks' — because it targets the assumption underneath every full-disk-encryption product rather than any one vendor's code.
First-order effects
- Enterprises that deployed BitLocker or FileVault specifically to protect laptops against theft lose that guarantee whenever an attacker gets the machine while it is running or recently powered down, since the key can be read from memory.
- Microsoft and Apple face immediate pressure to change how their products hold keys in RAM, since the flaw sits below their software in the memory chips themselves.
Second-order effects
- Corporate security teams and auditors have to reassess whether full-disk encryption alone satisfies data-breach requirements for lost laptops, which affects purchasing criteria for every FDE product, not just these two.
- Hardware vendors gain leverage as the mitigation moves toward platform features such as TPM-based key handling, giving PC makers a new security differentiator over software-only offerings.
Third-order effects
- If memory-remanence attacks become a standing part of the threat model, disk-encryption trust shifts from the strength of ciphers like AES to hardware assumptions about how long keys persist in RAM, pushing key management into chipsets and firmware.
- Independent academic attack papers of this kind are likely to become a routine gate that encryption products must pass before enterprises accept them as compliant.
The trend: Full-disk encryption's credibility is being stress-tested by attacks that go after the machine's memory rather than the cryptography, shifting trust from software products toward hardware-rooted key protection.