Live data from Hacker News

Evil Maid goes after TrueCrypt

theinvisiblethings.blogspot.com

21–30 of 67 posts

Re: Evil Maid goes after TrueCrypt

#21
post #20

Am I the only one who feel that trucrypt dev is just running away from answer here. Joanna Rutkowska: If I could arrange for a proper lock or an impenetrable strongbox, than why in the world should I need encryption? TrueCrypt Developer: Your question was: "And how can you determine that the attacker has or has not worked with your hardware?" My answer was a good safety case or strongbox with a good lock. If you use…

> If I could arrange for a proper lock or an impenetrable strongbox, than why in the world should I need encryption?

In case the attacker steals your laptop and decides to keep it, for example.

Re: Evil Maid goes after TrueCrypt

#22
post #20

Am I the only one who feel that trucrypt dev is just running away from answer here. Joanna Rutkowska: If I could arrange for a proper lock or an impenetrable strongbox, than why in the world should I need encryption? TrueCrypt Developer: Your question was: "And how can you determine that the attacker has or has not worked with your hardware?" My answer was a good safety case or strongbox with a good lock. If you use…

I don't think so. If the attacker got physical access to the hardware there is very little you can do via software, given the architecture of normal computers. So the only thing that makes sense is to find a way to detect physical access, and currently the only one is to physically protect the computer itself.

Edit: still there are a few tricks that can be done in theory. For instance to flash a new bios modified in order to write some data in a given sector of the disk if after the power up you don't press a special sequence of keys. This makes the owner able to detect if there was access to the PC, and because it's done in the BIOS even starting a different operating system from the CD will not avoid the detection.

This is security by obscurity, but can work against Maids.

Another simpler, less effective, but still better than nothing approach is to set a password in the BIOS. Unfortunately if I remember correctly a lot of BIOSes used to have backdoors.

Re: Evil Maid goes after TrueCrypt

#23
post #21
post #20

Am I the only one who feel that trucrypt dev is just running away from answer here. Joanna Rutkowska: If I could arrange for a proper lock or an impenetrable strongbox, than why in the world should I need encryption? TrueCrypt Developer: Your question was: "And how can you determine that the attacker has or has not worked with your hardware?" My answer was a good safety case or strongbox with a good lock. If you use…

> If I could arrange for a proper lock or an impenetrable strongbox, than why in the world should I need encryption? In case the attacker steals your laptop and decides to keep it, for example.

Assuming I understand you correctly, the hypothetical solution is now this:

  The attacker has complete physical access to a laptop with an encrypted hard drive for an indefinite period of time.
Forgive my ignorance on the matter, but what good would encryption do you there? Other than slow them down, of course.

Re: Evil Maid goes after TrueCrypt

#24
post #14

Earlier quoted context omitted.

What is of interest here is the small window of time required. You pretty much have to be in constant possession of your laptop (or a USB key that you religiously use to verify your boot record) in order to have any confidence that it has not been compromised.

That is the premise you should start with IMO; which is why this is not interesting. Absolutely you need to avoid releasing physical control of your machine.

Just keep it in a lock case. This solves the problem of Evil Maids, but not of Evil Maids-financed-by-the-NSA-with-lockpickers. I have to imagine that if those types of people were after your encrypted info,you'd know and you'd probably keep it handcuffed to your wrist.

Re: Evil Maid goes after TrueCrypt

#25
post #23
post #21

Earlier quoted context omitted.

> If I could arrange for a proper lock or an impenetrable strongbox, than why in the world should I need encryption? In case the attacker steals your laptop and decides to keep it, for example.

Assuming I understand you correctly, the hypothetical solution is now this: The attacker has complete physical access to a laptop with an encrypted hard drive for an indefinite period of time. Forgive my ignorance on the matter, but what good would encryption do you there? Other than slow them down, of course.

It could slow them down for thousands of years, well beyond the time when the data it holds becomes worthless.

Re: Evil Maid goes after TrueCrypt

#26
post #23

Earlier quoted context omitted.

Assuming I understand you correctly, the hypothetical solution is now this: The attacker has complete physical access to a laptop with an encrypted hard drive for an indefinite period of time. Forgive my ignorance on the matter, but what good would encryption do you there? Other than slow them down, of course.

It could slow them down for thousands of years, well beyond the time when the data it holds becomes worthless.

That makes sense, although I was already aware of it. I suppose I was wondering if there was anything else to it, really, though I haven't a clue what "anything else" would look like, or (for that matter) if the question (when phrased as such) even makes sense.

Thanks for clarifying, though.

Re: Evil Maid goes after TrueCrypt

#27
post #7

Physical access can almost always be leveraged to full system access.

What is of interest here is the small window of time required. You pretty much have to be in constant possession of your laptop (or a USB key that you religiously use to verify your boot record) in order to have any confidence that it has not been compromised.

For almost any given scenario to protect a system (even the one you mentioned), there's still likely to be a way to circumvent it if you can surreptitiously tinker with the machine for 30 minutes. This is a minuscule subset of the general rule: There is no such thing as perfect security.

Re: Evil Maid goes after TrueCrypt

#28
post #12

I can cut this "insertion" time in half. :) Miniature camera pasted somewhere discrete on the ceiling. That even bypasses physical (lockbox) security. (I liked the article but I think she waffled on a bit long about physical security, which TC developers made a good point about, and TPM)

The problem with this is you're assuming the target will actually access his encrypted data while in the hotel room.

If you really want to cut it in half, just kidnap him and hit him with this $5 wrench until he tells us the password. We're breaking laws, but hey, whose counting?

Re: Evil Maid goes after TrueCrypt

#29
post #19

There must be laptops out there with the feature that they lock closed and require some physical opening token (key, combination, etc). Given a sufficiently strong and tamper-evident locking mechanism, you wouldn't need an external lockbox and this attack would be difficult or impossible. (Emphasis on the "sufficiently", of course.)

The 'tamper-evident' aspect can be separate from the 'strong' aspect. You could for example put the laptop in a tamper-evident bag.

http://alertsecurityproducts.com/js2/eshop/prod_view?id=780

Re: Evil Maid goes after TrueCrypt

#30
post #28
post #12

I can cut this "insertion" time in half. :) Miniature camera pasted somewhere discrete on the ceiling. That even bypasses physical (lockbox) security. (I liked the article but I think she waffled on a bit long about physical security, which TC developers made a good point about, and TPM)

The problem with this is you're assuming the target will actually access his encrypted data while in the hotel room. If you really want to cut it in half, just kidnap him and hit him with this $5 wrench until he tells us the password. We're breaking laws, but hey, whose counting?

your right; though your solution is even more shaky ;) I find screwdrivers 100% more effective.
Post reply on HN