Ads
Ads
All about Memory
 Latest Memory articles
Value DDR3 For Intel's P55: Six 4GB Kits Rounded Up

Value DDR3 For Intel's P55: Six 4GB Kits Rounded Up
The exceptional value of LGA 1156-based platforms demands memory modules equal in value. Testing Newegg’s six cheapest 4GB dual-channel kits revealed some surprisingly good parts. We're comparing them today, with a definitive winner you'll want to see. Read More

  • DDR3 On A Budget: Six 6 GB Memory Kits
    Triple-channel 6 GB kits finally dropped below $100 last month. Today’s overclocking and under-latency tests prove how much value these low-cost parts can provide. Sure, Intel's Core i5 might be close at hand, but don't think Core i7 is going anywhere. Read More
  • DDR3 Memory Scaling: Intel's Core 2 Quad Examined
    This is our third RAM scaling story in a series that will conclude next week. In this piece, we're comparing a number of different DDR3 memory speeds using both tight and relaxed timings. Which memory setting is best for your Core 2 Quad setup? Read More
All Memory articles

Newsletters


  • Ask your question about IT issues
  • Post

Partners

The Games selection

kids : Bob Throw bubbles so as to make the ones that appear in the game disappear. For this, use the Right / Left arrow keys to duck or move about, and the...
crazy : PC Breakdown What is worst than a Fatal Error occuring during a game you did not save? Unleash your rage at your PC in this game. Blow it to pieces, it feels so...
Ads

Sponsored links

RAM Exposes The Key To Your Secret Data

Next news
1:50 PM - February 21, 2008 by Wolfgang Gruener

Princeton (NJ) - Researchers from Princeton University are describing a new and apparently very effective security attack that will allow hackers to access encrypted data on your PC. Technologies such Microsoft’s BitLocker, Apple’s FileVault and Linux’s dm-crypt have no defense against this new attack.

A stolen laptop is a scary scenario for any road warrior, especially if you are carrying important information such as personal information of customers or trade secrets. The most effective method to keep critical data safe in the event a laptop is stolen or lost has been data encryption or even a hard drive that automatically encrypts data. As it turns out, that data may not be safe at all, according to a paper released by Princeton researchers today.

In a project that specifically examined the safety of encrypted data on a PC, they found that encrypted data can easily be accessed by obtaining the encryption key. That key is stored in a computer’s random access memory (RAM) as soon as a user has typed in his password.

While it is generally believed that data is lost as soon as the RAM loses its power, the researchers found that that contents stored in RAM do not disappear immediately when the power supply to the chip is removed - which typically is the case when a computer is turned off. Instead, data decays over time and can remain in the chip for a period of several seconds to up to a minute. This process can be "slowed considerably" if the chip is cooled, the researchers said. 99.9% of the RAM data was still available after 10 minutes when the chip was cooled down to -50 degrees Celsius.

These findings suggest that a security attack especially on notebooks can always be successful when a system is at least in a sleep mode. Only completely powered down systems apparently can withstand such an attack and provide the protection level promised by data encryption.

The researchers said they were able to write programs that gained access to essential encryption information automatically after cutting power to machines and rebooting them. The method worked when the attackers had physical access to the computer and when they accessed it remotely over a computer network. The attack even worked when the encryption key had already started to decay, because the researchers were able to reconstruct it from multiple derivative keys that were also stored in memory. The attack on RAM can be extremely effective as full data access was even achieved when the memory chip was physically removed from one computer and placed in another machine to retrieve the encryption key.

None of the attacks required specialized equipment. "I think we’re going to see attackers doing things that people have previously though impractical or impossible," said computer security researcher Jacob Appelbaum.

The researchers said they have contacted several manufacturers to make them aware of the vulnerability, including Microsoft, Apple as well as the makers of dm-crypt and TrueCrypt. "There’s not much they can do at this point," said Alex Halderman, a Ph.D. candidate in Princeton’s computer science department. "In the short term, they can warn their customers about the vulnerability and tell them to shut their computers down completely when traveling."

Source : Tom's Hardware US

Talkback
Add your comment
Comments are closed on this page.

Sponsored links