Live data from Hacker News

Cold Boot Attacks

blog.f-secure.com

1–10 of 48 posts

Re: Cold Boot Attacks

#2
From a security standpoint, isn’t there a common understanding that if an attacker gains physical access to your computer, you already lost?

As a side note, there are so many vulnerabilities constantly coming out that I’ve almost became desensitized. I’m sure that’s not a good thing but it’s almost like “when” not “if” someone will just steal my data.

Not sure if anyone agrees or I’m just a one-off...

Re: Cold Boot Attacks

#3
> Cold boot attacks aren’t new. They were developed by a research group back in 2008

Older than that. E.g. Pettersson's talk at CCCamp 2007.

Re: Cold Boot Attacks

#5
physical access = compromised system

There are things you can do to mitigate this problem, but once someone has physical access to a computer they have many pathways to gaining access to data and control.

Re: Cold Boot Attacks

#7

physical access = compromised system There are things you can do to mitigate this problem, but once someone has physical access to a computer they have many pathways to gaining access to data and control.

This is already not true for modern iPhones. I think the time to stop accepting this has come. We should demand better from commodity devices.

Re: Cold Boot Attacks

#9

physical access = compromised system There are things you can do to mitigate this problem, but once someone has physical access to a computer they have many pathways to gaining access to data and control.

That's true, but it's what encrypted filesystems are supposed to prevent. The lesson is that sleep/low power modes are not enough. You should be powering-off or hibernating any time the computer is not in use.

Unfortunately this is against many enterprise policies for desktops, because they like to apply updates during off-hours and need the computers to be on (or at least able to wake up from sleep) to do that.

For laptops, you should configure them to hibernate when the lid is closed, not just sleep.

Re: Cold Boot Attacks

#10
Everyone's quickly jumping in to post "physical access is not secure", while over there Apple have iPhones that appear to be almost completely secure against all but the most dedicated state-level attacks (and of course compromised accounts). We can do better, and should. Without compromising the freedom to change operating system.

Mind you we also need to keep pressing on security for the desktop, against ransomware and malicious installs. Again without compromising freedom of choice.

Post reply on HN