DM-Crypt Archive on lore.kernel.org
 help / color / mirror / Atom feed
* Re: [dm-crypt] Memory location of the encryption key
@ 2011-03-14 22:16 Hanno Foest
  2011-03-14 23:15 ` Arno Wagner
  0 siblings, 1 reply; 5+ messages in thread
From: Hanno Foest @ 2011-03-14 22:16 UTC (permalink / raw)
  To: dm-crypt

On Tue Feb 15 10:54:35 CET 2011, Milan Broz wrote:

[Cold Boot attacks]
> Moreover, this attacks also include "platform reset" attack when you
> simply reset device and store memory image, because the power was
> still present, there is no memory loss (except few pages for image
> tool).

Hi, sorry for the late reply... but I've been wondering if these attacks
- rebooting the device into some kind of imaging tool for retrieving the
  memory image with the encryption key - can't be prevented by storing
the key in a place in memory where it would be inevitably overwritten by
the contents of the boot media.

Obviously this wouldn't stop the kind of attacks where the cooled RAM is
being read in some kind of external device, but it would surely make
attacks more expensive.

Hanno

^ permalink raw reply	[flat|nested] 5+ messages in thread
* [dm-crypt] Memory location of the encryption key
@ 2011-02-14 13:03 Peter
  2011-02-15  9:54 ` Milan Broz
  2011-02-15 15:42 ` Arno Wagner
  0 siblings, 2 replies; 5+ messages in thread
From: Peter @ 2011-02-14 13:03 UTC (permalink / raw)
  To: dm-crypt

Hey!

I've been reading Gutmann's paper on data remanence, which says that if some data is kept in the same memory location for very little time (1 second), the possibility for recovery of this data is very low, because the data had not yet had the time to change the relevant physical properties used in cold boot attacks. My question is, does dm-crypt change the memory location of encryption key every second? Does dm-crypt rewrite the memory location of the key when removing an active mapping? What other cold boot attack mitigation techniques the dm-crypt does?

Happy day,
Peter

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2011-03-14 23:15 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-03-14 22:16 [dm-crypt] Memory location of the encryption key Hanno Foest
2011-03-14 23:15 ` Arno Wagner
  -- strict thread matches above, loose matches on Subject: below --
2011-02-14 13:03 Peter
2011-02-15  9:54 ` Milan Broz
2011-02-15 15:42 ` Arno Wagner

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox