Newly Discovered Security Weakness Affects Most Laptops

(Image credit: F-Secure)
Latest Videos FromTom's Hardware
Nathaniel Mott
Freelance News & Features Writer

Nathaniel Mott is a freelance news and features writer for Tom's Hardware US, covering breaking news, security, and the silliest aspects of the tech industry.

  • Co BIY
    So the attacker has to steal a laptop that is currently running, before performing the firmware switch and cold boot. Because the data they could potentially steal is wiped out during a normal shutdown ?

    This would be a pretty advanced and complicated attack.
    Reply
  • Pat Flynn
    OK... I work in IT... if you have physical access to a device that isn't supposed to be accesed., the security is compromised. PERIOD.
    I think we really need the media to chill on these 'security flaws', all you're doing is scaring the sheeple.
    Reply
  • dextermat
    I repair computer and sometimes clients forget their password (stored in outlook or web browser) When I show them how easy it is to get them they are mostly shocked. If you have physical access to computer, it is really easy to download tools and get info you want. This is not a new security issue.
    Reply
  • stdragon
    21317840 said:
    OK... I work in IT... if you have physical access to a device that isn't supposed to be accesed., the security is compromised. PERIOD.
    I think we really need the media to chill on these 'security flaws', all you're doing is scaring the sheeple.

    Short of an exploit I"m not aware of, I'm not sure a machine encrypted with BitLocker (FIPS certified encryption) can be cracked. I suppose it might be possible if the hibernation file (a RAM dump in a large file) was left in an unencrypted state, but I'm certain it's not, no?

    Reply
  • anbello262
    This is inportant for companies that keep big trade secrets, not for consumers (the same as most security issues discovered recently).
    So I wouldn't ignore it, but also it's important to know about the demographics targeted.
    Reply
  • mihen
    Watch out for this major security flaw. The hacker must convince the user to login to their account and wire them money.
    Reply
  • Dosflores
    21317956 said:
    I repair computer and sometimes clients forget their password (stored in outlook or web browser) When I show them how easy it is to get them they are mostly shocked. If you have physical access to computer, it is really easy to download tools and get info you want. This is not a new security issue.

    Are you talking about computers that are protected by BitLocker? If you don't use BitLocker, data isn't protected at all.
    Reply
  • Dosflores
    21318551 said:
    Short of an exploit I"m not aware of, I'm not sure a machine encrypted with BitLocker (FIPS certified encryption) can be cracked. I suppose it might be possible if the hibernation file (a RAM dump in a large file) was left in an unencrypted state, but I'm certain it's not, no?

    Hibernation is safe. This new vulnerability only affects computers that are in sleep mode.
    Reply
  • Long__T123
    once someone has physical access all they really have to do is take the hard drive and place it in a different computer to get everything
    Reply
  • newsonline5000000
    21317840 said:
    OK... I work in IT... if you have physical access to a device that isn't supposed to be accesed., the security is compromised. PERIOD.
    I think we really need the media to chill on these 'security flaws', all you're doing is scaring the sheeple.

    You should be fired . PERIOD.

    Physical access to a device does not mean security is compromised . it means the IT department is ignorant.

    The best protection is being smart when you use your device . not open 100 Apps and sites and then cry when some one Hacks into your PC in standby mode
    Reply