Evil Maid goes after TrueCrypt
31–40 of 67 posts
Re: Evil Maid goes after TrueCrypt
#32Physical access can almost always be leveraged to full system access.
What is of interest here is the small window of time required. You pretty much have to be in constant possession of your laptop (or a USB key that you religiously use to verify your boot record) in order to have any confidence that it has not been compromised.
TrueCrypt is about the guy with the cinderblock, not about stopping Joanna Rutkowska from installing a keylogger.
Re: Evil Maid goes after TrueCrypt
#33This is utterly fascinating. I use TrueCrypt and never dreamt that such a simple attack even existed. Sigh - privacy in the age of information seems to be an impossible dream.
"There are two types of encryption: one that will prevent your sister from reading your diary and one that will prevent your government." -- Bruce Schneier. Addendum: "Provided it's implemented well".
Re: Evil Maid goes after TrueCrypt
#34Earlier quoted context omitted.
> If I could arrange for a proper lock or an impenetrable strongbox, than why in the world should I need encryption? In case the attacker steals your laptop and decides to keep it, for example.
Assuming I understand you correctly, the hypothetical solution is now this: The attacker has complete physical access to a laptop with an encrypted hard drive for an indefinite period of time. Forgive my ignorance on the matter, but what good would encryption do you there? Other than slow them down, of course.
If your laptop is encrypted, contains PI, and is stolen, you probably don't need to disclose the loss.
No matter what Joanna Rutkowska does with her (very slick) USB key, things like TrueCrypt are very cheap, very very effective insurance.
Re: Evil Maid goes after TrueCrypt
#35This is utterly fascinating. I use TrueCrypt and never dreamt that such a simple attack even existed. Sigh - privacy in the age of information seems to be an impossible dream.
My laptop's BIOS settings are password protected. Good luck with booting from CD/USB/Network without hardware tampering.
Re: Evil Maid goes after TrueCrypt
#36Earlier quoted context omitted.
What is of interest here is the small window of time required. You pretty much have to be in constant possession of your laptop (or a USB key that you religiously use to verify your boot record) in order to have any confidence that it has not been compromised.
The reality is, nobody is going to physically attack your laptop (just don't bring your work machine to Black Hat). But there is an unacceptably high probability that your laptop will get stolen; for instance, you will often leave it in your car, where anyone with a cinderblock can get it in under a minute. TrueCrypt is about the guy with the cinderblock, not about stopping Joanna Rutkowska from installing a keylogge…
Re: Evil Maid goes after TrueCrypt
#37Earlier quoted context omitted.
As the article points out, this is easy to circumvent by removing the hard drive from your laptop. It adds a few minutes to the attack, and requires that the attacker bring a laptop, but you're still hosed.
Not my hard drive, the disk itself is fully encrypted and won't work in other laptops without that bios password (I also use a truecrypt-like thing at the filesystem level). The main attack I need to worry about is someone replacing the keyboard, etc.
Re: Evil Maid goes after TrueCrypt
#38Re: Evil Maid goes after TrueCrypt
#39Couldn't a secure token (ala RSA SecurID) theoretically be used in some manner to prevent this attack?
Re: Evil Maid goes after TrueCrypt
#40Earlier quoted context omitted.
The problem with this is you're assuming the target will actually access his encrypted data while in the hotel room. If you really want to cut it in half, just kidnap him and hit him with this $5 wrench until he tells us the password. We're breaking laws, but hey, whose counting?
your right; though your solution is even more shaky ;) I find screwdrivers 100% more effective.