Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




4 posts

Wannabe Geek
Inactive user


Topic # 52941 7-Dec-2009 20:47
Send private message

Someone has just found a way to find your Windows 7 BitLocker password:

http://arstechnica.com/microsoft/news/2009/12/first-commercial-tool-cracks-bitlocker.ars

And I thought BitLocker was going to be all that.

Create new topic
4935 posts

Uber Geek
+1 received by user: 1314

Trusted
Microsoft

  Reply # 280171 7-Dec-2009 22:00
Send private message

calm down - this is not a traditional crack. This "attack" needs physical access to the machine at runtime. However, this is not a classical vulnerability.

Microsoft is aware of it, but at the end of the day security is a journey and not a destination and physical security is a big part of the solution too.

19282 posts

Uber Geek
+1 received by user: 2600
Inactive user


  Reply # 280172 7-Dec-2009 22:07
Send private message

Good god some people over react

Worlds going to end tomorrow people

 
 
 
 


167 posts

Master Geek


  Reply # 280176 7-Dec-2009 22:22
Send private message

johnr: Good god some people over react

Worlds going to end tomorrow people



If thats the case can you let me out of my contract.
/s

3743 posts

Uber Geek
+1 received by user: 205

Trusted

Reply # 280195 7-Dec-2009 23:32
Send private message

patznz:
johnr: Good god some people over react

Worlds going to end tomorrow people



If thats the case can you let me out of my contract.
/s


Sarah Palin for President in 2012. World is going to end that year anyways.




Do whatever you want to do man.

  

424 posts

Ultimate Geek
+1 received by user: 2


  Reply # 280197 7-Dec-2009 23:36
Send private message

I can see how this is a problem if you get your laptop stolen while it's in Sleep mode (or running of course). Remember when MIT or whoever discovered that ram unplugged didn't erase its memory in seconds? I can see organisations needing highly secure laptops having memory that self destructs when someone accesses it, ie takes off the memory compartment lid.

PGP help refers to an issue where a memory cell that has been at the same state for some time, develops a static charge. Using a special device, you strip off the plastic covering of a chip and use a charge detector to see what the key that was in memory was.  This is when everything is turned off. PGP gets around this by inverting the bits every second, so no static charge develops.

8019 posts

Uber Geek
+1 received by user: 384

Trusted
Subscriber

  Reply # 280215 8-Dec-2009 00:53
Send private message

You need a memory dump from a running system where you have admin access for it to work, same "flaw" applies to every full disk encryption because the encryption keys have to be stored in ram.

53 posts

Master Geek


  Reply # 280250 8-Dec-2009 08:27
Send private message

oh noes *runs*

xpd

Geek,gamer,father
8195 posts

Uber Geek
+1 received by user: 1072

Mod Emeritus
Trusted
Subscriber

  Reply # 280321 8-Dec-2009 10:56
Send private message





XPD / @DemiseNZ / Gavin
 
Corsair Carbide SPEC-02 / Corsair VS550 / G.SKILL Ripjaws X 8GB / Zotac 760GTX AMP! / ASUS H81M-E / Intel Pentium K Anniversay G3258 @3.9Ghz

 

Logitech G400S Mouse / SteelSeries Apex Raw Keyboard / Logitech G933 Headphones / Samsung S23C300L Monitor / Zalman Z-Machine Mouse Mat

 

Internet provided by : Voyager - VDSL 65/28  -  Musical Support by : Like A Storm - Visual Entertainment by : Plex and Steam and Overwatch


4935 posts

Uber Geek
+1 received by user: 1314

Trusted
Microsoft

  Reply # 280449 8-Dec-2009 17:11
Send private message

birdmanz: Someone has just found a way to find your Windows 7 BitLocker password:

http://arstechnica.com/microsoft/news/2009/12/first-commercial-tool-cracks-bitlocker.ars

And I thought BitLocker was going to be all that.



Windows Security Blog re BitLocker 'hack' claims http://bit.ly/7trj9Y "a relatively low risk to folks who use BitLocker in the real world"

19282 posts

Uber Geek
+1 received by user: 2600
Inactive user


Reply # 280472 8-Dec-2009 18:46
Send private message

c71931f:
johnr: Good god some people over react

Worlds going to end tomorrow people




We are all going to dieeeee....


No point in paying this months power bill then

2753 posts

Uber Geek
+1 received by user: 114


  Reply # 280487 8-Dec-2009 20:18
Send private message

Is this the same bitlocker vulnerability they discovered a couple of months back, or something different?




Create new topic



Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Symantec protects data everywhere with Information Centric Security
Posted 21-Sep-2017 15:33


FUJIFILM introduces X-E3 mirrorless camera with wireless connectivity
Posted 18-Sep-2017 13:53


Vodafone announces new plans with bigger data bundles
Posted 15-Sep-2017 10:51


Skinny launches phone with support for te reo Maori
Posted 14-Sep-2017 08:39


If Vodafone dropping mail worries you, you’re doing online wrong
Posted 11-Sep-2017 13:54


Vodafone New Zealand deploy live 400 gigabit system
Posted 11-Sep-2017 11:07


OPPO camera phones now available at PB Tech
Posted 11-Sep-2017 09:56


Norton Wi-Fi Privacy — Easy, flawed VPN
Posted 11-Sep-2017 09:48


Lenovo reveals new ThinkPad A Series
Posted 8-Sep-2017 14:37


Huawei passes Apple for the first time to capture the second spot globally
Posted 8-Sep-2017 10:45


Vodafone initiative enhances te reo Maori pronunciation on Google Maps
Posted 8-Sep-2017 10:40


Voyager Internet expand local internet phone services company with Conversant acquisition
Posted 6-Sep-2017 18:27


NOW Expands in to Tauranga
Posted 5-Sep-2017 18:16


Windows 10 Fall Creators Update coming Oct. 17
Posted 4-Sep-2017 14:10


Garmin introduce Garmin vivoactive 3
Posted 1-Sep-2017 18:38



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.