Home | Cyber Crime | Is It Possible to Steal Encrypted Data?

Is It Possible to Steal Encrypted Data?

Font size: Decrease font Enlarge font
image Installing RAM in Computer

Most people use disk encryption tools to prevent someone who may have physical possession of their computer from gaining access to their data without their personal password or key. These tools are supposed to be very effective, and people commonly assume that with the tools, their data are protected even when their computers are lost or stolen.

Share
A group of researchers recently published a paper that details simple methods they developed to steal encrypted data stored in hard disk drives. Their technique could seriously undermine the effectiveness of security software used to protect data on computers, especially laptops and other portable computers which are very vulnerable to theft.

The procedure requires the attacker to have physical access to the computer; it cannot be done remotely. It exploits an obscure vulnerability in the DRAM (dynamic random access memory) chip, which temporarily holds data while you are working on your computer. When you shut off the computer, the data in the DRAM, including the data encryption keys, are erased from the DRAM.

Contrary to popular assumption, however, the content in the DRAMs do not disappear immediately. It takes several seconds or a few minutes after shutting off power before the data is erased, and even if the DRAMs are separated from the motherboard. With more specialized techniques, the data could remain for hours, or even days, in the chips.

The simplest method involved chilling the chips with a can of inexpensive dust remover. This produced temperatures cold enough (-50 °C) to have the data in the chips stay long enough for the researchers to retrieve the keys easily.

The more complicated method involved cooling the chips in liquid nitrogen to temperatures of -196 °C. This froze the data in place for hours without any power.

In either method, the researchers then put the chips back into a computer after cooling and easily retrieved the contents. They then used pattern-recognition software to pick out the security keys from the other bits of data on the cooled DRAM chip.

The researchers successfully tested their procedure on various encryption utilities in Windows, Macintosh and Linux operating systems. They did not test the methods on disk encryption systems now built into a number of commercial disk drives.

Nevertheless, their tests proved that current industry standard platforms (called Trusted Computing) to securing data on modern personal computers may not give sufficient protection against these potential attacks. People cannot simply assume anymore that claims of robust computer security are correct.

Safety Tips:

• Shut down your computer completely several minutes before you leave your computer (which could compromise its physical security). If you want to protect your encrypted files better, do not leave your computer in ‘sleep’ mode or with locked screen saver. This does not completely shut off the computer.

• Protect your computer from theft.

• Use an encrypted volume PGP disk and remove it when you’re done.

• Use multi-factor authentication.
Rate this article:
4.00
  • email Email to a friend
  • print Print version
  • Plain text Plain text

Comments (5 posted):

credit repair specialist on 10/18/11 07:01:06
avatar
A computer security research group has developed a way to steal encrypted information from computer hard disks.
Daily Guide on 01/22/12 01:07:44
avatar
Nice post.Thank you for taking the time to publish this information very useful! I've been looking for books of this nature for a way too long. I'm just glad that I found yours. Looking forward for your next post. Thanks :)

Daily Guide
www.0y7.net
gen on 01/24/12 10:56:04
avatar
Nice! Actually I'm glad this is an option that we can implement. I've always wanted to have my comments stand out from others. Allows us to be much more creative.






<a href="http://www.skilch.com">gen</a>
www.skilch.com
Fan Parts on 01/24/12 10:59:39
avatar
A group led by a Princeton University computer security researcher has developed a simple method to steal encrypted information stored on computer hard disks.

The technique, which could undermine security software protecting critical data on computers, is as easy as chilling a computer memory chip with a blast of frigid air from a can of dust remover. Encryption software is widely used by companies and government agencies, notably in portable computers that are especially susceptible to theft.
avatar
Well, I'm so delighted that I have found your post because I have been seeking some information regarding it for nearly 3 hours.

Post your comment comment

Please enter the code you see in the image:

Access restricted articles free
TheSafetyChannel
To show your safety related video, Contact Us.
Protecting public health through food safety and defence.
What Simon says about...


Monthly Newsletter
Email:
Supporting SafetyIssues
If you support this website, please consider making a donation and help us continue providing this free service.
Please consider making a donation
Tags