Live data from Hacker News

MacOS FileVault2 Password Retrieval

blog.frizk.net

1–10 of 90 posts

Re: MacOS FileVault2 Password Retrieval

#3
Has Apple released patches for El Capitan?

I'm still using it instead of Sierra because of Karabiner but this could force me to upgrade.

That vulnerability seems to be a pretty obvious oversight. I remember hearing about DMA (in the context of Firewire) as an attack vector since people first started talking of Truecrypt and Filevault and scrubbing the memory seems obvious... It's worrying that this could have been overlooked by Apple's engineers.

Re: MacOS FileVault2 Password Retrieval

#4
Things like this are a reason I unhesitatingly recommend that people stick with their OS's built in FDE:

1. FDE is extremely limited. This particular attack is a clever abuse of sleep/reboot cycles, but of course people intimately familiar with FDE know that if a laptop is sleeping but not shut down it's already perilously close to the boundary at which FDE breaks down. And, of course, once it's woken up and unlocked --- which every attacker who actually challenges FDE can arrange for, all bets are off.

2. When flaws like this are found, the OS vendors have much more recourse than third parties do, which is why this post concludes by saying that Macs are now the most secure laptop platform with respect to DMA attacks against FDE.

Use FDE! Enable it on all your machines! But try not to rely on it, and don't waste too much time optimizing it.

Re: MacOS FileVault2 Password Retrieval

#6
post #4

Things like this are a reason I unhesitatingly recommend that people stick with their OS's built in FDE: 1. FDE is extremely limited. This particular attack is a clever abuse of sleep/reboot cycles, but of course people intimately familiar with FDE know that if a laptop is sleeping but not shut down it's already perilously close to the boundary at which FDE breaks down. And, of course, once it's woken up and unlocked…

> And, of course, once it's woken up and unlocked --- which every attacker who actually challenges FDE can arrange for, all bets are off.

I'm not sure what you mean by that? Do you mean that the attacker can force you to wake up and unlock the computer? In that case FDE is not moot anyway, no?

For me, the reason I use FDE is in the case I lose or forget my computer somewhere, I do not want the legal liabilities with a thief accessing my customer's source code.

Re: MacOS FileVault2 Password Retrieval

#7

Has Apple released patches for El Capitan? I'm still using it instead of Sierra because of Karabiner but this could force me to upgrade. That vulnerability seems to be a pretty obvious oversight. I remember hearing about DMA (in the context of Firewire) as an attack vector since people first started talking of Truecrypt and Filevault and scrubbing the memory seems obvious... It's worrying that this could have been ov…

You better update quick! /s

Chances that someone use that device to hack your computer: 0

Re: MacOS FileVault2 Password Retrieval

#8
While I'm not excusing this bug (didn't they already go through this round of DMA bugs with FireWire?), this reinforces my belief that once you have physical access to a personal computer - all bets are off. If you lost your laptop, rotate all keys. Change all passwords. Assume everything is compromised.

Re: MacOS FileVault2 Password Retrieval

#9
post #4

Things like this are a reason I unhesitatingly recommend that people stick with their OS's built in FDE: 1. FDE is extremely limited. This particular attack is a clever abuse of sleep/reboot cycles, but of course people intimately familiar with FDE know that if a laptop is sleeping but not shut down it's already perilously close to the boundary at which FDE breaks down. And, of course, once it's woken up and unlocked…

> And, of course, once it's woken up and unlocked --- which every attacker who actually challenges FDE can arrange for, all bets are off. I'm not sure what you mean by that? Do you mean that the attacker can force you to wake up and unlock the computer? In that case FDE is not moot anyway, no? For me, the reason I use FDE is in the case I lose or forget my computer somewhere, I do not want the legal liabilities with…

Even though the computer may be “locked”, if the OS is running and accessing the disk, it means that the key is present somewhere in memory. There are various methods of accessing this key, the fallback brute-force method being the (https://en.wikipedia.org/wiki/Cold_boot_attack). The method from the article only removes the need to physically remove and cool the memory chips.

Re: MacOS FileVault2 Password Retrieval

#10

Has Apple released patches for El Capitan? I'm still using it instead of Sierra because of Karabiner but this could force me to upgrade. That vulnerability seems to be a pretty obvious oversight. I remember hearing about DMA (in the context of Firewire) as an attack vector since people first started talking of Truecrypt and Filevault and scrubbing the memory seems obvious... It's worrying that this could have been ov…

You better update quick! /s Chances that someone use that device to hack your computer: 0

[deleted]
Post reply on HN