<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Ram dumping to defeat disk encryption. Pedophiles and drug czars beware!</title>
	<atom:link href="http://www.asktheadmin.com/2008/02/ram-dumping-to-defeat-disk-encryption.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.asktheadmin.com/2008/02/ram-dumping-to-defeat-disk-encryption.html</link>
	<description></description>
	<lastBuildDate>Fri, 03 Feb 2012 06:08:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: El Di Pablo</title>
		<link>http://www.asktheadmin.com/2008/02/ram-dumping-to-defeat-disk-encryption.html/comment-page-1#comment-4968</link>
		<dc:creator>El Di Pablo</dc:creator>
		<pubDate>Mon, 25 Feb 2008 19:20:18 +0000</pubDate>
		<guid isPermaLink="false">http://ata.bansal-inc.com/?p=655#comment-4968</guid>
		<description>I got your comment. Yours does that to me too. If you refresh the page after you see that error, you will see your comment. Makes sense though, Intense Debate is still in beta.  </description>
		<content:encoded><![CDATA[<p>I got your comment. Yours does that to me too. If you refresh the page after you see that error, you will see your comment. Makes sense though, Intense Debate is still in beta.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AskTheAdmin</title>
		<link>http://www.asktheadmin.com/2008/02/ram-dumping-to-defeat-disk-encryption.html/comment-page-1#comment-4967</link>
		<dc:creator>AskTheAdmin</dc:creator>
		<pubDate>Mon, 25 Feb 2008 19:14:25 +0000</pubDate>
		<guid isPermaLink="false">http://ata.bansal-inc.com/?p=655#comment-4967</guid>
		<description>I went to leave you a comment Paul and it didn&#039;t work out for me. The ID timed out trying to save my comment. I was in FF 2. What I wanted to say was: &lt;br /&gt;  &lt;br /&gt; Thanks for the link and your 2 cents! :)  </description>
		<content:encoded><![CDATA[<p>I went to leave you a comment Paul and it didn&#039;t work out for me. The ID timed out trying to save my comment. I was in FF 2. What I wanted to say was: </p>
<p> Thanks for the link and your 2 cents! :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: El Di Pablo</title>
		<link>http://www.asktheadmin.com/2008/02/ram-dumping-to-defeat-disk-encryption.html/comment-page-1#comment-4966</link>
		<dc:creator>El Di Pablo</dc:creator>
		<pubDate>Mon, 25 Feb 2008 19:06:15 +0000</pubDate>
		<guid isPermaLink="false">http://ata.bansal-inc.com/?p=655#comment-4966</guid>
		<description>So I reposted this here: &lt;a href=&quot;&lt;a href=&quot;http://tinyurl.com/yuhknc &quot; rel=&quot;nofollow&quot;&gt;http://tinyurl.com/yuhknc &lt;/a&gt;&quot;&gt;&lt;a href=&quot;http://tinyurl.com/yuhknc &quot; rel=&quot;nofollow&quot;&gt;http://tinyurl.com/yuhknc &lt;/a&gt;&lt;/a&gt;&lt;br /&gt;  &lt;br /&gt; You ask what do we use to lock down our systems, well on my work desktop I have the new Truecrypt installed, which is one of the apps tested in the video. I also used to use Compusec (&lt;a href=&quot;&lt;a href=&quot;http://tinyurl.com/25shro) &quot; rel=&quot;nofollow&quot;&gt;http://tinyurl.com/25shro) &lt;/a&gt;&quot;&gt;&lt;a href=&quot;http://tinyurl.com/25shro) &quot; rel=&quot;nofollow&quot;&gt;http://tinyurl.com/25shro) &lt;/a&gt;&lt;/a&gt;on my personal laptop, but did away with that when I switched to Ubuntu. I guess it doesn&#039;t matter what we use anymore huh ;-)  </description>
		<content:encoded><![CDATA[<p>So I reposted this here: <a href="<a href="http://tinyurl.com/yuhknc " rel="nofollow"></a><a href="http://tinyurl.com/yuhknc" rel="nofollow">http://tinyurl.com/yuhknc</a> &#8220;><a href="http://tinyurl.com/yuhknc " rel="nofollow"></a><a href="http://tinyurl.com/yuhknc" rel="nofollow">http://tinyurl.com/yuhknc</a> </p>
<p> You ask what do we use to lock down our systems, well on my work desktop I have the new Truecrypt installed, which is one of the apps tested in the video. I also used to use Compusec (<a href="<a href="http://tinyurl.com/25shro) " rel="nofollow"></a><a href="http://tinyurl.com/25shro" rel="nofollow">http://tinyurl.com/25shro</a>) &#8220;><a href="http://tinyurl.com/25shro) " rel="nofollow"></a><a href="http://tinyurl.com/25shro" rel="nofollow">http://tinyurl.com/25shro</a>) on my personal laptop, but did away with that when I switched to Ubuntu. I guess it doesn&#039;t matter what we use anymore huh ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: El Di Pablo</title>
		<link>http://www.asktheadmin.com/2008/02/ram-dumping-to-defeat-disk-encryption.html/comment-page-1#comment-7203</link>
		<dc:creator>El Di Pablo</dc:creator>
		<pubDate>Mon, 25 Feb 2008 19:06:15 +0000</pubDate>
		<guid isPermaLink="false">http://ata.bansal-inc.com/?p=655#comment-7203</guid>
		<description>So I reposted this here: &lt;a href=&quot;&lt;a href=&quot;http://tinyurl.com/yuhknc &quot; rel=&quot;nofollow&quot;&gt;http://tinyurl.com/yuhknc &lt;/a&gt;&quot;&gt;&lt;a href=&quot;http://tinyurl.com/yuhknc &quot; rel=&quot;nofollow&quot;&gt;http://tinyurl.com/yuhknc &lt;/a&gt;&lt;/a&gt;&lt;br /&gt;  &lt;br /&gt; You ask what do we use to lock down our systems, well on my work desktop I have the new Truecrypt installed, which is one of the apps tested in the video. I also used to use Compusec (&lt;a href=&quot;&lt;a href=&quot;http://tinyurl.com/25shro) &quot; rel=&quot;nofollow&quot;&gt;http://tinyurl.com/25shro) &lt;/a&gt;&quot;&gt;&lt;a href=&quot;http://tinyurl.com/25shro) &quot; rel=&quot;nofollow&quot;&gt;http://tinyurl.com/25shro) &lt;/a&gt;&lt;/a&gt;on my personal laptop, but did away with that when I switched to Ubuntu. I guess it doesn&#039;t matter what we use anymore huh ;-)  </description>
		<content:encoded><![CDATA[<p>So I reposted this here: <a href="<a href="http://tinyurl.com/yuhknc " rel="nofollow"></a><a href="http://tinyurl.com/yuhknc" rel="nofollow">http://tinyurl.com/yuhknc</a> &#8220;><a href="http://tinyurl.com/yuhknc " rel="nofollow"></a><a href="http://tinyurl.com/yuhknc" rel="nofollow">http://tinyurl.com/yuhknc</a> </p>
<p> You ask what do we use to lock down our systems, well on my work desktop I have the new Truecrypt installed, which is one of the apps tested in the video. I also used to use Compusec (<a href="<a href="http://tinyurl.com/25shro) " rel="nofollow"></a><a href="http://tinyurl.com/25shro" rel="nofollow">http://tinyurl.com/25shro</a>) &#8220;><a href="http://tinyurl.com/25shro) " rel="nofollow"></a><a href="http://tinyurl.com/25shro" rel="nofollow">http://tinyurl.com/25shro</a>) on my personal laptop, but did away with that when I switched to Ubuntu. I guess it doesn&#039;t matter what we use anymore huh ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: El Di Pablo</title>
		<link>http://www.asktheadmin.com/2008/02/ram-dumping-to-defeat-disk-encryption.html/comment-page-1#comment-4965</link>
		<dc:creator>El Di Pablo</dc:creator>
		<pubDate>Mon, 25 Feb 2008 17:19:56 +0000</pubDate>
		<guid isPermaLink="false">http://ata.bansal-inc.com/?p=655#comment-4965</guid>
		<description>Let me know how it turns out. &lt;br /&gt;  &lt;br /&gt; -EDP &lt;br /&gt; &lt;a href=&quot;&lt;a href=&quot;http://www.bauer-power.net &quot; rel=&quot;nofollow&quot;&gt;http://www.bauer-power.net &lt;/a&gt;&quot;&gt;&lt;a href=&quot;http://www.bauer-power.net &quot; rel=&quot;nofollow&quot;&gt;http://www.bauer-power.net &lt;/a&gt;&lt;/a&gt; </description>
		<content:encoded><![CDATA[<p>Let me know how it turns out. </p>
<p> -EDP <br /> <a href="<a href="http://www.bauer-power.net " rel="nofollow"></a><a href="http://www.bauer-power.net" rel="nofollow">http://www.bauer-power.net</a> &#8220;><a href="http://www.bauer-power.net " rel="nofollow"></a><a href="http://www.bauer-power.net" rel="nofollow">http://www.bauer-power.net</a> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: El Di Pablo</title>
		<link>http://www.asktheadmin.com/2008/02/ram-dumping-to-defeat-disk-encryption.html/comment-page-1#comment-7202</link>
		<dc:creator>El Di Pablo</dc:creator>
		<pubDate>Mon, 25 Feb 2008 17:19:56 +0000</pubDate>
		<guid isPermaLink="false">http://ata.bansal-inc.com/?p=655#comment-7202</guid>
		<description>Let me know how it turns out. &lt;br /&gt;  &lt;br /&gt; -EDP &lt;br /&gt; &lt;a href=&quot;&lt;a href=&quot;http://www.bauer-power.net &quot; rel=&quot;nofollow&quot;&gt;http://www.bauer-power.net &lt;/a&gt;&quot;&gt;&lt;a href=&quot;http://www.bauer-power.net &quot; rel=&quot;nofollow&quot;&gt;http://www.bauer-power.net &lt;/a&gt;&lt;/a&gt; </description>
		<content:encoded><![CDATA[<p>Let me know how it turns out. </p>
<p> -EDP <br /> <a href="<a href="http://www.bauer-power.net " rel="nofollow"></a><a href="http://www.bauer-power.net" rel="nofollow">http://www.bauer-power.net</a> &#8220;><a href="http://www.bauer-power.net " rel="nofollow"></a><a href="http://www.bauer-power.net" rel="nofollow">http://www.bauer-power.net</a> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AskTheAdmin</title>
		<link>http://www.asktheadmin.com/2008/02/ram-dumping-to-defeat-disk-encryption.html/comment-page-1#comment-4964</link>
		<dc:creator>AskTheAdmin</dc:creator>
		<pubDate>Mon, 25 Feb 2008 16:06:24 +0000</pubDate>
		<guid isPermaLink="false">http://ata.bansal-inc.com/?p=655#comment-4964</guid>
		<description>Ram dumping tools are available on the web! If you can boot to ubuntu or a live distro you can use the tools on the machine to drop the encryption code (sometimes) Maybe the app that these guys built can do it better but once you have the info dumped from the ram you do not have a time limit @ all! &lt;br /&gt;  &lt;br /&gt; We will be giving this a try in the next week over @ AtA labs. Stay tuned loyal readers!  </description>
		<content:encoded><![CDATA[<p>Ram dumping tools are available on the web! If you can boot to ubuntu or a live distro you can use the tools on the machine to drop the encryption code (sometimes) Maybe the app that these guys built can do it better but once you have the info dumped from the ram you do not have a time limit @ all! </p>
<p> We will be giving this a try in the next week over @ AtA labs. Stay tuned loyal readers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: El Di Pablo</title>
		<link>http://www.asktheadmin.com/2008/02/ram-dumping-to-defeat-disk-encryption.html/comment-page-1#comment-4963</link>
		<dc:creator>El Di Pablo</dc:creator>
		<pubDate>Mon, 25 Feb 2008 15:49:49 +0000</pubDate>
		<guid isPermaLink="false">http://ata.bansal-inc.com/?p=655#comment-4963</guid>
		<description>Damn Karl, you scooped me. I was going to blog about this today! I read about this on Friday. Watching the video, it still doesn&#039;t get me too worried. In order for someone to do this, they will have to do it close, and will not have much time to do it, even if they froze your ram with the air duster, that only gives them what 10 - 20 minutes of time to hack your stuff? That includes getting your laptop to a secluded spot to do the hack, freezing your ram, then booting up with their boot disk. Someone will have to go through a lot to do it. Besides, the researchers haven&#039;t released the source code, or the software for their hacking software. It doesn&#039;t look likely to be a wide spread problem yet.  </description>
		<content:encoded><![CDATA[<p>Damn Karl, you scooped me. I was going to blog about this today! I read about this on Friday. Watching the video, it still doesn&#039;t get me too worried. In order for someone to do this, they will have to do it close, and will not have much time to do it, even if they froze your ram with the air duster, that only gives them what 10 &#8211; 20 minutes of time to hack your stuff? That includes getting your laptop to a secluded spot to do the hack, freezing your ram, then booting up with their boot disk. Someone will have to go through a lot to do it. Besides, the researchers haven&#039;t released the source code, or the software for their hacking software. It doesn&#039;t look likely to be a wide spread problem yet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PD</title>
		<link>http://www.asktheadmin.com/2008/02/ram-dumping-to-defeat-disk-encryption.html/comment-page-1#comment-4962</link>
		<dc:creator>PD</dc:creator>
		<pubDate>Mon, 25 Feb 2008 12:44:22 +0000</pubDate>
		<guid isPermaLink="false">http://ata.bansal-inc.com/?p=655#comment-4962</guid>
		<description>Changing the boot order and protecting the BIOS are a good idea, but the attack also allows for physically removing the RAM and putting it in another machine, so changing the BIOS won&#039;t help there. &lt;br /&gt;  &lt;br /&gt; While these kinds of attacks are interesting, I think if you are facing an adversary who would go to this length, or one where you would seriously consider needing Truecrypt&#039;s plausible deniability feature, you are really in a whole different league from most encryption users.  That&#039;s a situation where the attacker has targeted YOU and/or YOUR data.  That is a much rarer occurrence than an attack that is random or someone just looking to steal the hardware. &lt;br /&gt; In those cases any level of encryption would be enough. &lt;br /&gt;  &lt;br /&gt; It&#039;s similar to car theft.  Any type of alarm or protection will generally protect you against random shopping mall attacks because there is always going to be an easier target.  But if the thief is a professional who has a reason to steal YOUR car or the specific type of car you drive, there&#039;s not a whole lot you can do unless you want to spend a huge amount of money and effort.  </description>
		<content:encoded><![CDATA[<p>Changing the boot order and protecting the BIOS are a good idea, but the attack also allows for physically removing the RAM and putting it in another machine, so changing the BIOS won&#039;t help there. </p>
<p> While these kinds of attacks are interesting, I think if you are facing an adversary who would go to this length, or one where you would seriously consider needing Truecrypt&#039;s plausible deniability feature, you are really in a whole different league from most encryption users.  That&#039;s a situation where the attacker has targeted YOU and/or YOUR data.  That is a much rarer occurrence than an attack that is random or someone just looking to steal the hardware. <br /> In those cases any level of encryption would be enough. </p>
<p> It&#039;s similar to car theft.  Any type of alarm or protection will generally protect you against random shopping mall attacks because there is always going to be an easier target.  But if the thief is a professional who has a reason to steal YOUR car or the specific type of car you drive, there&#039;s not a whole lot you can do unless you want to spend a huge amount of money and effort.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced)

Served from: www.asktheadmin.com @ 2012-02-09 17:46:25 -->
