Live data from Hacker News

Evil Maid goes after TrueCrypt

theinvisiblethings.blogspot.com

31–40 of 67 posts

Re: Evil Maid goes after TrueCrypt

#32
post #7

Physical access can almost always be leveraged to full system access.

What is of interest here is the small window of time required. You pretty much have to be in constant possession of your laptop (or a USB key that you religiously use to verify your boot record) in order to have any confidence that it has not been compromised.

The reality is, nobody is going to physically attack your laptop (just don't bring your work machine to Black Hat). But there is an unacceptably high probability that your laptop will get stolen; for instance, you will often leave it in your car, where anyone with a cinderblock can get it in under a minute.

TrueCrypt is about the guy with the cinderblock, not about stopping Joanna Rutkowska from installing a keylogger.

Re: Evil Maid goes after TrueCrypt

#33
post #3

This is utterly fascinating. I use TrueCrypt and never dreamt that such a simple attack even existed. Sigh - privacy in the age of information seems to be an impossible dream.

"There are two types of encryption: one that will prevent your sister from reading your diary and one that will prevent your government." -- Bruce Schneier. Addendum: "Provided it's implemented well".

Doesn't the OP sort of invalidate this? Any government should find it reasonably easy to install this kind of a keylogger on your computer. It would be quite easy to get a few minutes alone with your laptop.

Re: Evil Maid goes after TrueCrypt

#34
post #23
post #21

Earlier quoted context omitted.

> If I could arrange for a proper lock or an impenetrable strongbox, than why in the world should I need encryption? In case the attacker steals your laptop and decides to keep it, for example.

Assuming I understand you correctly, the hypothetical solution is now this: The attacker has complete physical access to a laptop with an encrypted hard drive for an indefinite period of time. Forgive my ignorance on the matter, but what good would encryption do you there? Other than slow them down, of course.

It's very simple. If your laptop is unencrypted, could even possibly contain Protected/Personal/Patient-Health Information, and is stolen, you are very likely legally required to formally disclose the loss. That's a legal and PR nightmare.

If your laptop is encrypted, contains PI, and is stolen, you probably don't need to disclose the loss.

No matter what Joanna Rutkowska does with her (very slick) USB key, things like TrueCrypt are very cheap, very very effective insurance.

Re: Evil Maid goes after TrueCrypt

#35
post #5

This is utterly fascinating. I use TrueCrypt and never dreamt that such a simple attack even existed. Sigh - privacy in the age of information seems to be an impossible dream.

My laptop's BIOS settings are password protected. Good luck with booting from CD/USB/Network without hardware tampering.

Unless you've got a very special sort of BIOS, those passwords aren't very strong. And I'd probably just use a keylogger.

Re: Evil Maid goes after TrueCrypt

#36
post #32

Earlier quoted context omitted.

What is of interest here is the small window of time required. You pretty much have to be in constant possession of your laptop (or a USB key that you religiously use to verify your boot record) in order to have any confidence that it has not been compromised.

The reality is, nobody is going to physically attack your laptop (just don't bring your work machine to Black Hat). But there is an unacceptably high probability that your laptop will get stolen; for instance, you will often leave it in your car, where anyone with a cinderblock can get it in under a minute. TrueCrypt is about the guy with the cinderblock, not about stopping Joanna Rutkowska from installing a keylogge…

Cinderblock is so unwieldy! I'm more of a broken spark plug man:

http://www.youtube.com/watch?v=wUgsi9gQBeA

Re: Evil Maid goes after TrueCrypt

#37
post #11

Earlier quoted context omitted.

As the article points out, this is easy to circumvent by removing the hard drive from your laptop. It adds a few minutes to the attack, and requires that the attacker bring a laptop, but you're still hosed.

Not my hard drive, the disk itself is fully encrypted and won't work in other laptops without that bios password (I also use a truecrypt-like thing at the filesystem level). The main attack I need to worry about is someone replacing the keyboard, etc.

Are you using a hard drive password? Those are easily crackable as well as they usually have a vendor supplied master password. Do you mind giving more details?

Re: Evil Maid goes after TrueCrypt

#39

Couldn't a secure token (ala RSA SecurID) theoretically be used in some manner to prevent this attack?

Even easier to get around. Truecrypt uses your passphrase to decrypt the key which is then used to decrypt the disk. With a ID tag it would just match the tag generated number with it's own algorithm and then decrypt the disk . All the evil maid would then have to do is add a line to the Truecrypt loader that said if key=999 unlock anyway.

Re: Evil Maid goes after TrueCrypt

#40
post #30
post #28

Earlier quoted context omitted.

The problem with this is you're assuming the target will actually access his encrypted data while in the hotel room. If you really want to cut it in half, just kidnap him and hit him with this $5 wrench until he tells us the password. We're breaking laws, but hey, whose counting?

your right; though your solution is even more shaky ;) I find screwdrivers 100% more effective.

http://xkcd.com/538/
Post reply on HN