Earlier quoted context omitted.
My laptop's BIOS settings are password protected. Good luck with booting from CD/USB/Network without hardware tampering.
As the article points out, this is easy to circumvent by removing the hard drive from your laptop. It adds a few minutes to the attack, and requires that the attacker bring a laptop, but you're still hosed.
Evil Maid goes after TrueCrypt
11–20 of 67 posts
Re: Evil Maid goes after TrueCrypt
#12That even bypasses physical (lockbox) security.
(I liked the article but I think she waffled on a bit long about physical security, which TC developers made a good point about, and TPM)
Re: Evil Maid goes after TrueCrypt
#13Re: Evil Maid goes after TrueCrypt
#14Physical access can almost always be leveraged to full system access.
What is of interest here is the small window of time required. You pretty much have to be in constant possession of your laptop (or a USB key that you religiously use to verify your boot record) in order to have any confidence that it has not been compromised.
Re: Evil Maid goes after TrueCrypt
#15Earlier quoted context omitted.
As the article points out, this is easy to circumvent by removing the hard drive from your laptop. It adds a few minutes to the attack, and requires that the attacker bring a laptop, but you're still hosed.
Not my hard drive, the disk itself is fully encrypted and won't work in other laptops without that bios password (I also use a truecrypt-like thing at the filesystem level). The main attack I need to worry about is someone replacing the keyboard, etc.
Of course as the strip also points out "Actual actual reality: nobody cares about his secrets"
Re: Evil Maid goes after TrueCrypt
#16Earlier quoted context omitted.
Not my hard drive, the disk itself is fully encrypted and won't work in other laptops without that bios password (I also use a truecrypt-like thing at the filesystem level). The main attack I need to worry about is someone replacing the keyboard, etc.
When you get to that level of protection, the main attack I'd be worried about is the $5 wrench. http://xkcd.com/538/ Of course as the strip also points out "Actual actual reality: nobody cares about his secrets"
Re: Evil Maid goes after TrueCrypt
#17This is utterly fascinating. I use TrueCrypt and never dreamt that such a simple attack even existed. Sigh - privacy in the age of information seems to be an impossible dream.
"There are two types of encryption: one that will prevent your sister from reading your diary and one that will prevent your government." -- Bruce Schneier. Addendum: "Provided it's implemented well".
Re: Evil Maid goes after TrueCrypt
#18Earlier quoted context omitted.
As the article points out, this is easy to circumvent by removing the hard drive from your laptop. It adds a few minutes to the attack, and requires that the attacker bring a laptop, but you're still hosed.
Not my hard drive, the disk itself is fully encrypted and won't work in other laptops without that bios password (I also use a truecrypt-like thing at the filesystem level). The main attack I need to worry about is someone replacing the keyboard, etc.
Re: Evil Maid goes after TrueCrypt
#19Re: Evil Maid goes after TrueCrypt
#20Joanna Rutkowska: If I could arrange for a proper lock or an impenetrable strongbox, than why in the world should I need encryption?
TrueCrypt Developer: Your question was: "And how can you determine that the attacker has or has not worked with your hardware?" My answer was a good safety case or strongbox with a good lock. If you use it, then you will notice that the attacker has accessed your notebook inside (as the case or strongbox will be damaged and it cannot be replaced because you had the correct key with you). If the safety case or strongbox can be opened without getting damaged & unusable, then it's not a good safety case or strongbox. ;-)