Earlier quoted context omitted.
Not impossible, but some smart people have been looking, at least for Apple's FileVault 2: http://www.schneier.com/blog/archives/2012/08/an_analysis_of... Paper here: http://eprint.iacr.org/2012/374.pdf Currently, there seem to be three vectors: 1) Weak passwords 2) If you opt-in to store a recovery key with Apple 3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thund…
3) If attacker has physical access to machine, and machine is powered on (direct memory access via Thunderbolt or Firewire) This may have changed, but turning on FileVault used to disable DMA in many situations (laptop had been suspended being a key one) until the user logged back in. Not that this isn't a vector, but it's actually a very narrow one; you basically need the person to already be logged in at the time y…
http://www.frameloss.org/wp-content/uploads/2011/09/Lion-Mem...
Though apparently there was a company offering a commercial solution for getting FileVault passwords using this method so...
http://privacycast.com/filevault-vulnerability-how-to-protec...
There's also a really interesting pdf from Apple containing more details on FileVault 2:
http://training.apple.com/pdf/WP_FileVault2.pdf
which suggests turning on firmware passwords to prevent DMA.