Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




4 posts

Wannabe Geek
Inactive user


Topic # 52941 7-Dec-2009 20:47
Send private message

Someone has just found a way to find your Windows 7 BitLocker password:

http://arstechnica.com/microsoft/news/2009/12/first-commercial-tool-cracks-bitlocker.ars

And I thought BitLocker was going to be all that.

Create new topic
4937 posts

Uber Geek
+1 received by user: 1314

Trusted
Microsoft

  Reply # 280171 7-Dec-2009 22:00
Send private message

calm down - this is not a traditional crack. This "attack" needs physical access to the machine at runtime. However, this is not a classical vulnerability.

Microsoft is aware of it, but at the end of the day security is a journey and not a destination and physical security is a big part of the solution too.

19282 posts

Uber Geek
+1 received by user: 2600
Inactive user


  Reply # 280172 7-Dec-2009 22:07
Send private message

Good god some people over react

Worlds going to end tomorrow people

 
 
 
 


167 posts

Master Geek


  Reply # 280176 7-Dec-2009 22:22
Send private message

johnr: Good god some people over react

Worlds going to end tomorrow people



If thats the case can you let me out of my contract.
/s

3770 posts

Uber Geek
+1 received by user: 215

Trusted

Reply # 280195 7-Dec-2009 23:32
Send private message

patznz:
johnr: Good god some people over react

Worlds going to end tomorrow people



If thats the case can you let me out of my contract.
/s


Sarah Palin for President in 2012. World is going to end that year anyways.




Do whatever you want to do man.

  

424 posts

Ultimate Geek
+1 received by user: 2


  Reply # 280197 7-Dec-2009 23:36
Send private message

I can see how this is a problem if you get your laptop stolen while it's in Sleep mode (or running of course). Remember when MIT or whoever discovered that ram unplugged didn't erase its memory in seconds? I can see organisations needing highly secure laptops having memory that self destructs when someone accesses it, ie takes off the memory compartment lid.

PGP help refers to an issue where a memory cell that has been at the same state for some time, develops a static charge. Using a special device, you strip off the plastic covering of a chip and use a charge detector to see what the key that was in memory was.  This is when everything is turned off. PGP gets around this by inverting the bits every second, so no static charge develops.

8020 posts

Uber Geek
+1 received by user: 386

Trusted
Subscriber

  Reply # 280215 8-Dec-2009 00:53
Send private message

You need a memory dump from a running system where you have admin access for it to work, same "flaw" applies to every full disk encryption because the encryption keys have to be stored in ram.

53 posts

Master Geek


  Reply # 280250 8-Dec-2009 08:27
Send private message

oh noes *runs*

xpd

8309 posts

Uber Geek
+1 received by user: 1090

Mod Emeritus
Trusted
Subscriber

  Reply # 280321 8-Dec-2009 10:56
Send private message





XPD^ / @DemiseNZ / Gavin

 

Internet : Voyager (VDSL)         Mobile : 2Degrees

 

Data Backed up by Backblaze

 

xpd.co.nz


4937 posts

Uber Geek
+1 received by user: 1314

Trusted
Microsoft

  Reply # 280449 8-Dec-2009 17:11
Send private message

birdmanz: Someone has just found a way to find your Windows 7 BitLocker password:

http://arstechnica.com/microsoft/news/2009/12/first-commercial-tool-cracks-bitlocker.ars

And I thought BitLocker was going to be all that.



Windows Security Blog re BitLocker 'hack' claims http://bit.ly/7trj9Y "a relatively low risk to folks who use BitLocker in the real world"

19282 posts

Uber Geek
+1 received by user: 2600
Inactive user


Reply # 280472 8-Dec-2009 18:46
Send private message

c71931f:
johnr: Good god some people over react

Worlds going to end tomorrow people




We are all going to dieeeee....


No point in paying this months power bill then

2776 posts

Uber Geek
+1 received by user: 119


  Reply # 280487 8-Dec-2009 20:18
Send private message

Is this the same bitlocker vulnerability they discovered a couple of months back, or something different?




Create new topic



Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Phone prices rising as users move upmarket
Posted 24-Nov-2017 17:16


Talking net neutrality on RNZ Nine-to-Noon
Posted 24-Nov-2017 12:11


Air New Zealand experiments with blockchain technology
Posted 23-Nov-2017 15:39


Symantec selects Amazon Web Services to deliver cloud security
Posted 23-Nov-2017 10:40


New Zealand Ministry of Education chooses Unisys for cloud-based education resourcing management system
Posted 22-Nov-2017 22:00


Business analytics software powers profits for NZ wine producers
Posted 22-Nov-2017 21:52


Pyrios strikes up alliance with Microsoft integrator UC Logiq
Posted 22-Nov-2017 21:51


The New Zealand IT services ecosystem - it's all digital down here
Posted 22-Nov-2017 21:49


Volvo to supply tens of thousands of autonomous drive compatible cars to Uber
Posted 22-Nov-2017 21:46


From small to medium and beyond: Navigating the ERP battlefield
Posted 21-Nov-2017 21:12


Business owners: ERP software selection starts (and finishes) with you
Posted 21-Nov-2017 21:11


Why I'm not an early adopter
Posted 21-Nov-2017 10:39


Netatmo launches smart home products in New Zealand
Posted 20-Nov-2017 20:06


Huawei Mate 10: Punchy, long battery life, artificial intelligence
Posted 20-Nov-2017 16:30


Propel launch Disney Star Wars Laser Battle Drones
Posted 19-Nov-2017 21:26



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.