physical access = compromised system There are things you can do to mitigate this problem, but once someone has physical access to a computer they have many pathways to gaining access to data and control.
This is already not true for modern iPhones. I think the time to stop accepting this has come. We should demand better from commodity devices.
Cold Boot Attacks
11–20 of 48 posts
Re: Cold Boot Attacks
#12Cold boot, you keep using this word and you don't know what it means. Or is it me who have a screwed definiton of cold boot?
Re: Cold Boot Attacks
#13Last I checked, cold boot attacks have to be executed within moments of a computer powering down unless it's immediately put on ice. I don't understand why we're worried about this.
Re: Cold Boot Attacks
#14Everyone's quickly jumping in to post "physical access is not secure", while over there Apple have iPhones that appear to be almost completely secure against all but the most dedicated state-level attacks (and of course compromised accounts). We can do better, and should. Without compromising the freedom to change operating system. Mind you we also need to keep pressing on security for the desktop, against ransomware…
Re: Cold Boot Attacks
#15That's why the #1 rule of security is physical security. If someone has physical access to your computer, it's pretty much game over.
Not necessarily if you turn off your computer or use hibernation instead of sleep, AND you use full disk encryption. This will stop short-term attacks, like cold boot attacks and the like.
Of course, if they "borrow" your laptop for a while, opens it up, installing key loggers, modifying the firmware/hardware, and you do not notice this: you are f*ed.
I mean: even if you believe that "if someone has physical access to your computer, it's pretty much game over" you don't necessarily drop encryption and user password on the laptop and always put it in sleep mode.
Re: Cold Boot Attacks
#16physical access = compromised system There are things you can do to mitigate this problem, but once someone has physical access to a computer they have many pathways to gaining access to data and control.
What I'm worried about is closing these holes while preserving the ability to run whatever software I want.
And also preserving the ability to provide consistent instruction to people on how to install other operating systems. In other words if every laptop has a different magic keyboard sequence to bypass boot security it's going to be a pain to write the Debian install instructions.
Re: Cold Boot Attacks
#17With all the talk I hear about "cache being the new RAM", since it's so much faster, particularly the L1, it sounds like it would make sense to have some transparent encryption going on. A random key generated at power on, then kept inside the CPU, and instantly lost at power off, would be enough to secure the contents of DIMMs against attacks like this.
Re: Cold Boot Attacks
#18So do y'all regularly dump liquid nitrogen on your computers after powering them off? Last I checked, cold boot attacks have to be executed within moments of a computer powering down unless it's immediately put on ice. I don't understand why we're worried about this.
Re: Cold Boot Attacks
#19Leaving the computer on is a cold boot attack now?
Re: Cold Boot Attacks
#20So do y'all regularly dump liquid nitrogen on your computers after powering them off? Last I checked, cold boot attacks have to be executed within moments of a computer powering down unless it's immediately put on ice. I don't understand why we're worried about this.