Live data from Hacker News

Evil Maid goes after TrueCrypt

theinvisiblethings.blogspot.com

1–10 of 67 posts

Re: Evil Maid goes after TrueCrypt

#3

This is utterly fascinating. I use TrueCrypt and never dreamt that such a simple attack even existed. Sigh - privacy in the age of information seems to be an impossible dream.

"There are two types of encryption: one that will prevent your sister from reading your diary and one that will prevent your government." -- Bruce Schneier.

Addendum: "Provided it's implemented well".

Re: Evil Maid goes after TrueCrypt

#4
This is like countless other social engineering attacks, getting people to unwittingly enter their passwords (e.g. phishing) has a high ROI and physical access just makes this very easy (e.g. ATM skimming).

Re: Evil Maid goes after TrueCrypt

#5

This is utterly fascinating. I use TrueCrypt and never dreamt that such a simple attack even existed. Sigh - privacy in the age of information seems to be an impossible dream.

My laptop's BIOS settings are password protected. Good luck with booting from CD/USB/Network without hardware tampering.

Re: Evil Maid goes after TrueCrypt

#6
post #5

This is utterly fascinating. I use TrueCrypt and never dreamt that such a simple attack even existed. Sigh - privacy in the age of information seems to be an impossible dream.

My laptop's BIOS settings are password protected. Good luck with booting from CD/USB/Network without hardware tampering.

As the article points out, this is easy to circumvent by removing the hard drive from your laptop. It adds a few minutes to the attack, and requires that the attacker bring a laptop, but you're still hosed.

Re: Evil Maid goes after TrueCrypt

#8
post #4

This is like countless other social engineering attacks, getting people to unwittingly enter their passwords (e.g. phishing) has a high ROI and physical access just makes this very easy (e.g. ATM skimming).

How is this a social engineering attack in any way? The point of interest here is how rapidly an encrypted laptop can be compromised by an untrained person, in a way that evades easy detection.

Re: Evil Maid goes after TrueCrypt

#9
post #7

Physical access can almost always be leveraged to full system access.

What is of interest here is the small window of time required. You pretty much have to be in constant possession of your laptop (or a USB key that you religiously use to verify your boot record) in order to have any confidence that it has not been compromised.

Re: Evil Maid goes after TrueCrypt

#10
post #4

This is like countless other social engineering attacks, getting people to unwittingly enter their passwords (e.g. phishing) has a high ROI and physical access just makes this very easy (e.g. ATM skimming).

How is this a social engineering attack in any way? The point of interest here is how rapidly an encrypted laptop can be compromised by an untrained person, in a way that evades easy detection.

You get/let someone to trust the physical situation of their machine. In this case of the "maid" getting to play the maid is the engineering part. Once you have physical access to a machine, cracking is usually guaranteed (this is not new or of much interest). This is no different than a complicated "Sneakers" movie style social engineering attack to get physical access to something... it's just easier in a hotel.
Post reply on HN