Things like this are a reason I unhesitatingly recommend that people stick with their OS's built in FDE: 1. FDE is extremely limited. This particular attack is a clever abuse of sleep/reboot cycles, but of course people intimately familiar with FDE know that if a laptop is sleeping but not shut down it's already perilously close to the boundary at which FDE breaks down. And, of course, once it's woken up and unlocked…
I don't know about Apple but Microsoft has a pretty nasty way of handling user's Bitlocker keys. If you use a Microsoft account, your key is automatically backed-up in Microsoft's cloud. Red flag #1. Also, as the recent Bitlocker bypass "bug" showed us, Microsoft has some way of bypassing Bitlocker encryption when it performs updates on the system. I don't know if they have some kind of key escrow or what, but either…
MacOS FileVault2 Password Retrieval
21–30 of 90 posts
Re: MacOS FileVault2 Password Retrieval
#22Is the update an EFI update which disables DMA or does it with IOMMU? Or is the memory just overwritten on boot?
I'm also quite surprised they leave the password in memory in multiple locations. - Assuming the password is only used to derive the KEK for the actual key.
Re: MacOS FileVault2 Password Retrieval
#23Earlier quoted context omitted.
Is Karabiner Elements missing features you need? https://github.com/tekezo/Karabiner-Elements I haven't tried it because I can't find the wireless mouse that I needed Karabiner for, but my impression was it has most of the functionality running, especially the key/button remapping which seems to be their biggest use case.
I haven't found a way to configure Karabiner Elements to replace Caps lock with Escape when I only press that key (for vim) and with Ctrl when I press it in combination with other keys (for the terminal). I also have both Shift keys bound to () when pressed alone and Shift when pressed in combination with other keys.
Looks like it's not in master, but somebody has builds that do it.
Re: MacOS FileVault2 Password Retrieval
#24Re: MacOS FileVault2 Password Retrieval
#25Earlier quoted context omitted.
Is Karabiner Elements missing features you need? https://github.com/tekezo/Karabiner-Elements I haven't tried it because I can't find the wireless mouse that I needed Karabiner for, but my impression was it has most of the functionality running, especially the key/button remapping which seems to be their biggest use case.
I haven't found a way to configure Karabiner Elements to replace Caps lock with Escape when I only press that key (for vim) and with Ctrl when I press it in combination with other keys (for the terminal). I also have both Shift keys bound to () when pressed alone and Shift when pressed in combination with other keys.
Re: MacOS FileVault2 Password Retrieval
#26I'm interested in how this was fixed. Is the update an EFI update which disables DMA or does it with IOMMU? Or is the memory just overwritten on boot? I'm also quite surprised they leave the password in memory in multiple locations. - Assuming the password is only used to derive the KEK for the actual key.
Re: MacOS FileVault2 Password Retrieval
#27Earlier quoted context omitted.
I haven't found a way to configure Karabiner Elements to replace Caps lock with Escape when I only press that key (for vim) and with Ctrl when I press it in combination with other keys (for the terminal). I also have both Shift keys bound to () when pressed alone and Shift when pressed in combination with other keys.
Discussion of the caps lock solo/chorded feature here: https://github.com/tekezo/Karabiner-Elements/pull/170#issuec... Looks like it's not in master, but somebody has builds that do it.
Re: MacOS FileVault2 Password Retrieval
#28I'm interested in how this was fixed. Is the update an EFI update which disables DMA or does it with IOMMU? Or is the memory just overwritten on boot? I'm also quite surprised they leave the password in memory in multiple locations. - Assuming the password is only used to derive the KEK for the actual key.
sudo firmwarepasswd -setpasswd -setmode command
enter in a password to lock down Option ROM, reboot. Now you're protected.
source, the hacker-now-Apple-developer: https://twitter.com/XenoKovah/status/809418554428657666
Re: MacOS FileVault2 Password Retrieval
#29Earlier quoted context omitted.
> And, of course, once it's woken up and unlocked --- which every attacker who actually challenges FDE can arrange for, all bets are off. I'm not sure what you mean by that? Do you mean that the attacker can force you to wake up and unlock the computer? In that case FDE is not moot anyway, no? For me, the reason I use FDE is in the case I lose or forget my computer somewhere, I do not want the legal liabilities with…
Assume that there are generally two kinds of physical attackers: * Casual, opportunistic attackers who will steal any available laptop. * Targeted attackers who want your laptop in particular. Against a casual attacker, even if your laptop is stolen unlocked, it's not going to be carefully kept unlocked. Doing so requires sophistication, care, and extra risk. Instead, the laptop is just going to get wiped. Against a…
[0] "On the afternoon of October 1, 2013, officers watched as Ulbricht entered the library and made his way up the stairs to work by the window at a desk in the science fiction section, Kiernan recalled. Meanwhile, sitting on a bench outside of the library, homeland security officer Jared Der-Yeghiayan — who had been working undercover as Silk Road employee "cirrus" — initiated a chat with Ulbricht, requesting that he log in to Silk Road's back end to fix a technical problem. As soon as Der-Yeghiayan could confirm that Ulbricht was logged into the site, FBI agents entered the library.
Two plainclothes FBI agents, one male and one female, walked up behind Ulbricht and began arguing loudly. This staged lovers' tiff caught Ulbricht's attention long enough to distract him from his laptop. As soon as Ulbricht looked up, the male agent reached down and slid the computer over to his female colleague, who quickly snatched it up and handed it over to Kiernan for further investigation."
[0] http://www.businessinsider.com/ross-ulbricht-will-be-sentenc...
Re: MacOS FileVault2 Password Retrieval
#30Earlier quoted context omitted.
> And, of course, once it's woken up and unlocked --- which every attacker who actually challenges FDE can arrange for, all bets are off. I'm not sure what you mean by that? Do you mean that the attacker can force you to wake up and unlock the computer? In that case FDE is not moot anyway, no? For me, the reason I use FDE is in the case I lose or forget my computer somewhere, I do not want the legal liabilities with…
Assume that there are generally two kinds of physical attackers: * Casual, opportunistic attackers who will steal any available laptop. * Targeted attackers who want your laptop in particular. Against a casual attacker, even if your laptop is stolen unlocked, it's not going to be carefully kept unlocked. Doing so requires sophistication, care, and extra risk. Instead, the laptop is just going to get wiped. Against a…