Live data from Hacker News

Evil Maid goes after TrueCrypt

theinvisiblethings.blogspot.com

51–60 of 67 posts

Re: Evil Maid goes after TrueCrypt

#51
post #11

Earlier quoted context omitted.

Not my hard drive, the disk itself is fully encrypted and won't work in other laptops without that bios password (I also use a truecrypt-like thing at the filesystem level). The main attack I need to worry about is someone replacing the keyboard, etc.

Are you using a hard drive password? Those are easily crackable as well as they usually have a vendor supplied master password. Do you mind giving more details?

http://www.thinkwiki.org/wiki/Full_Disk_Encryption_%28FDE%29

Re: Evil Maid goes after TrueCrypt

#52
post #7

Physical access can almost always be leveraged to full system access.

This is the crux of the problem. Physical (and network) access can always break any security because you have a million vectors of attack - physical hardware, software, etc.. . And how secure is your laptop when its in your possession? As laptops become smaller (i.e. netbooks) they'll be as easily stolen as one's wallet.

Frankly, most people's data is really not that important and the cinderblock attack is what truecrypt and similar crypto systems prevent. Every time you see a news item about "a million social security numbers have been compromised " - its always due to the cinderblock attack.

The "only" way to secure your data is to put your computer it in a vault (unplugged from AC outlet and no network access) with multiple physical security and surrounded by people with guns. If your data is that important and you can afford this sort of security...then the evil maid attack is irrelevant.

Re: Evil Maid goes after TrueCrypt

#53
post #24
post #14

Earlier quoted context omitted.

That is the premise you should start with IMO; which is why this is not interesting. Absolutely you need to avoid releasing physical control of your machine.

Just keep it in a lock case. This solves the problem of Evil Maids, but not of Evil Maids-financed-by-the-NSA-with-lockpickers. I have to imagine that if those types of people were after your encrypted info,you'd know and you'd probably keep it handcuffed to your wrist.

please, think of james bond! how could he drink a martini gracefully when a suitcase is chained to his hand?

Re: Evil Maid goes after TrueCrypt

#54
Full drive encryption is meant to protect against theft or loss, not against trojan horses (be that hardware or software).

To protect against trojan horses you need an external validation mechanism or a physical protection (be that a safebox or TPM, by the way the Truecrypt team is wrong about TPM, it's much more difficult to temper than bytes on a hard disk).

Re: Evil Maid goes after TrueCrypt

#55
post #24
post #14

Earlier quoted context omitted.

That is the premise you should start with IMO; which is why this is not interesting. Absolutely you need to avoid releasing physical control of your machine.

Just keep it in a lock case. This solves the problem of Evil Maids, but not of Evil Maids-financed-by-the-NSA-with-lockpickers. I have to imagine that if those types of people were after your encrypted info,you'd know and you'd probably keep it handcuffed to your wrist.

I usually just keep my data on a USB key and then buy a brand new laptop from a random store every time I want to access it.

Re: Evil Maid goes after TrueCrypt

#56
post #24

Earlier quoted context omitted.

Just keep it in a lock case. This solves the problem of Evil Maids, but not of Evil Maids-financed-by-the-NSA-with-lockpickers. I have to imagine that if those types of people were after your encrypted info,you'd know and you'd probably keep it handcuffed to your wrist.

please, think of james bond! how could he drink a martini gracefully when a suitcase is chained to his hand?

james gracefully holds cocktail glass with both hands? now if he had other hand around woman's waist, that I would understand :)

Re: Evil Maid goes after TrueCrypt

#57
post #47

Whenever I suspect I might be somewhere where there's a keylogger running (public terminal etc) and I absolutely have to enter a password anyway, I just use the mouse to enter it out of order (and click away to throw in some random junk) while typing it in. Thwarts screen grabbers and keyloggers.

wouldn't that just be defeated if the form post was intercepted?

Before it hit the local ssl? You'd have more to worry about than a keylogger then.

Re: Evil Maid goes after TrueCrypt

#58
post #4

This is like countless other social engineering attacks, getting people to unwittingly enter their passwords (e.g. phishing) has a high ROI and physical access just makes this very easy (e.g. ATM skimming).

How is this a social engineering attack in any way? The point of interest here is how rapidly an encrypted laptop can be compromised by an untrained person, in a way that evades easy detection.

Because it's 'compromised' by surreptitiously convincing the user to give you the password.

Re: Evil Maid goes after TrueCrypt

#59

It seems like the easiest poor-man's solution would be to disable booting from external devices, set a strong BIOS password, and fill the laptop's screw holes with epoxy. At that point, you only have to worry about the strength of the BIOS's password-protection. Any other attempt at circumvention would be self-evident thanks to the destroyed case or epoxy.

[deleted]

Re: Evil Maid goes after TrueCrypt

#60
post #52
post #7

Physical access can almost always be leveraged to full system access.

This is the crux of the problem. Physical (and network) access can always break any security because you have a million vectors of attack - physical hardware, software, etc.. . And how secure is your laptop when its in your possession? As laptops become smaller (i.e. netbooks) they'll be as easily stolen as one's wallet. Frankly, most people's data is really not that important and the cinderblock attack is what truec…

> As laptops become smaller (i.e. netbooks) they'll be as easily stolen as one's wallet.

On the flipside it's easier to keep a netbook always on your possession than it is even a 12" laptop. So yea, smaller computing devices could be 'easier to pick-pocket' or it could mean 'harder to separate from the user.'

Post reply on HN