Earlier quoted context omitted.
Not my hard drive, the disk itself is fully encrypted and won't work in other laptops without that bios password (I also use a truecrypt-like thing at the filesystem level). The main attack I need to worry about is someone replacing the keyboard, etc.
Are you using a hard drive password? Those are easily crackable as well as they usually have a vendor supplied master password. Do you mind giving more details?
Evil Maid goes after TrueCrypt
51–60 of 67 posts
Re: Evil Maid goes after TrueCrypt
#52Physical access can almost always be leveraged to full system access.
Frankly, most people's data is really not that important and the cinderblock attack is what truecrypt and similar crypto systems prevent. Every time you see a news item about "a million social security numbers have been compromised " - its always due to the cinderblock attack.
The "only" way to secure your data is to put your computer it in a vault (unplugged from AC outlet and no network access) with multiple physical security and surrounded by people with guns. If your data is that important and you can afford this sort of security...then the evil maid attack is irrelevant.
Re: Evil Maid goes after TrueCrypt
#53Earlier quoted context omitted.
That is the premise you should start with IMO; which is why this is not interesting. Absolutely you need to avoid releasing physical control of your machine.
Just keep it in a lock case. This solves the problem of Evil Maids, but not of Evil Maids-financed-by-the-NSA-with-lockpickers. I have to imagine that if those types of people were after your encrypted info,you'd know and you'd probably keep it handcuffed to your wrist.
Re: Evil Maid goes after TrueCrypt
#54To protect against trojan horses you need an external validation mechanism or a physical protection (be that a safebox or TPM, by the way the Truecrypt team is wrong about TPM, it's much more difficult to temper than bytes on a hard disk).
Re: Evil Maid goes after TrueCrypt
#55Earlier quoted context omitted.
That is the premise you should start with IMO; which is why this is not interesting. Absolutely you need to avoid releasing physical control of your machine.
Just keep it in a lock case. This solves the problem of Evil Maids, but not of Evil Maids-financed-by-the-NSA-with-lockpickers. I have to imagine that if those types of people were after your encrypted info,you'd know and you'd probably keep it handcuffed to your wrist.
Re: Evil Maid goes after TrueCrypt
#56Earlier quoted context omitted.
Just keep it in a lock case. This solves the problem of Evil Maids, but not of Evil Maids-financed-by-the-NSA-with-lockpickers. I have to imagine that if those types of people were after your encrypted info,you'd know and you'd probably keep it handcuffed to your wrist.
please, think of james bond! how could he drink a martini gracefully when a suitcase is chained to his hand?
Re: Evil Maid goes after TrueCrypt
#57Whenever I suspect I might be somewhere where there's a keylogger running (public terminal etc) and I absolutely have to enter a password anyway, I just use the mouse to enter it out of order (and click away to throw in some random junk) while typing it in. Thwarts screen grabbers and keyloggers.
wouldn't that just be defeated if the form post was intercepted?
Re: Evil Maid goes after TrueCrypt
#58This is like countless other social engineering attacks, getting people to unwittingly enter their passwords (e.g. phishing) has a high ROI and physical access just makes this very easy (e.g. ATM skimming).
How is this a social engineering attack in any way? The point of interest here is how rapidly an encrypted laptop can be compromised by an untrained person, in a way that evades easy detection.
Re: Evil Maid goes after TrueCrypt
#59It seems like the easiest poor-man's solution would be to disable booting from external devices, set a strong BIOS password, and fill the laptop's screw holes with epoxy. At that point, you only have to worry about the strength of the BIOS's password-protection. Any other attempt at circumvention would be self-evident thanks to the destroyed case or epoxy.
Re: Evil Maid goes after TrueCrypt
#60Physical access can almost always be leveraged to full system access.
This is the crux of the problem. Physical (and network) access can always break any security because you have a million vectors of attack - physical hardware, software, etc.. . And how secure is your laptop when its in your possession? As laptops become smaller (i.e. netbooks) they'll be as easily stolen as one's wallet. Frankly, most people's data is really not that important and the cinderblock attack is what truec…
On the flipside it's easier to keep a netbook always on your possession than it is even a 12" laptop. So yea, smaller computing devices could be 'easier to pick-pocket' or it could mean 'harder to separate from the user.'