Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 24-02-2008, 01:32 PM   #1 (permalink)
The Thread Killer >:)
 
phreak0ut's Avatar
 
Join Date: Apr 2006
Location: Bangalore
Posts: 1,185
Exclamation Computer Memory Vulnerable to Hacking


Quote:
Want to break into a computer's encrypted hard drive? Just blast the machine's memory chip with a burst of cold air.

That's the conclusion of new research out of Princeton University demonstrating a novel, low-tech way hackers can access even the most well-protected computers, provided they have physical access to the machines.

The Princeton report shows how encryption, long considered a vital shield against hacker attacks, can be defeated by manipulating the way memory chips work. The researchers say the ease of their attack raises fears about the security of laptop computers increasingly used to store sensitive information, from personal banking data, to company trade secrets, to national security documents.

Freezing a dynamic random access memory, or DRAM, chip, the most common type of memory chip in personal computers, causes it to retain data for minutes or even hours after the machine loses power, the report found. That data includes the keys to unlock encryption. Without freezing, the chip loses its contents within seconds.

Hackers can steal information stored in memory by rebooting the compromised machine with a simple program designed to copy the memory contents - before the computer has a chance to purge sensitive data, according to the study.

Laptops left in hibernation or sleep mode, or simply not turned off at all, are the most vulnerable to the new type of attack.

"These risks imply that disk encryption on laptops may do less good than widely believed," according to the report, which was published this week by researchers from Princeton, the Electronic Frontier Foundation digital rights group, and Wind River Systems software company. "Ultimately, it might become necessary to treat DRAM as untrusted, and to avoid storing sensitive confidential data there, but this will not be feasible until architectures are changed to give software a safe place to keep its keys."

Researchers have known since the 1970s that cooled DRAM chips can retain their contents long after power to them is extinguished, but the researchers said they believe their study is the first security paper to focus on the phenomenon. National security agencies may also have been aware that the types of breaches outlined in the study are possible, the researchers said, but added they weren't able to find evidence of that in any publications.

The attacks were carried out by spraying an upside-down canister of multipurpose duster spray directly onto the memory chips, freezing them to minus 50 degrees Celsius, about minus 60 Fahrenheit.

One challenge faced by the researchers was the threat that booting the system will automatically overwrite some parts of the memory. To make sure the contents were retained, they used small, special-purpose programs known as memory-imaging tools, which can be loaded over a network connection or a USB device, to save images captured from the memory chip. The attacks even work when the DRAM chip is removed and transferred to a machine set up by the hacker.

Special programs were then used to correct errors in the recovered memory contents and reconstruct the keys used for encryption.

The researchers said their results suggest that "this faith in the strength of disk encryption may be misplaced," arguing that a moderately skilled attacker can bypass many widely used encryption products - including BitLocker, included with some versions of Windows Vista; Apple's FileVault; open-source TrueCrypt; and dm-crypt - if a laptop is stolen while it is powered on or suspended.

"The use of encryption is not, by itself, necessarily an adequate defense, and data in stolen laptops may be compromised even when encryption is used," the researchers said.
SOURCE
__________________
Want to make this world a better place? Then, start seeding and don't be just a leecher :)
phreak0ut is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 24-02-2008, 02:27 PM   #2 (permalink)
The Smaller Bang
 
MetalheadGautham's Avatar
 
Join Date: Sep 2007
Location: Gautham City
Posts: 7,492
Default Re: Computer Memory Vulnerable to Hacking

great. my computer is locked up in a vault in venus. no worries for me.
__________________
http://TheSmallerBang.wordpress.com
eMachines E725 - T4400 2.2GHz, 1GB, 160GB
Nokia 5130XM * T-Sonic 610 2GB
Nokia 2323C * Samsung Galaxy Y
Apple iPad 2 16GB WiFi
MetalheadGautham is offline  
Old 27-02-2008, 12:35 PM   #3 (permalink)
ax3
Cool as a CUCUMBAR ! ! !
 
ax3's Avatar
 
Join Date: Dec 2003
Posts: 5,052
Default Re: Computer Memory Vulnerable to Hacking

ya ...... i had read this thing in TOI & was shocked ...... ppl do anything 2 steal data .......
__________________
... W H O T ...
ax3 is offline  
Old 27-02-2008, 12:36 PM   #4 (permalink)
Dreamweaver
 
Gigacore's Avatar
 
Join Date: Aug 2006
Location: Bangalore
Posts: 3,904
Default Re: Computer Memory Vulnerable to Hacking

i have no important data..
__________________
Today's noobs are tomorrow's geeks. Don't make fun of them.. encourage them. - Gigacore

Follow me on twitter.com/gigacore
Gigacore is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
USB memory devices are not showing in my computer ANURAG SHARMA Peripherals 1 29-07-2007 11:51 PM
What is Damn Vulnerable Linux? i_am_crack Chit-Chat 1 08-06-2007 10:28 AM
phpBB forums vulnerable to attack rohan Technology News 11 11-08-2006 02:11 PM
Computer Hacking william QnA (read only) 2 21-02-2006 10:50 AM
Next Generation of Computer Memory – DDR3 AGENT_SMITH QnA (read only) 6 20-02-2005 10:36 PM

 
Latest Threads
- by Tenida
- by clinton
- by Anorion

Advertisement




All times are GMT +5.5. The time now is 03:30 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2