RE: Bitlocker without PIN

Per Thorsheim <[email protected]> Thu, 24 Feb 2011 22:42:14 +0100
Newsgroups gmane.comp.security.microsoft
Message-ID <1298583734.22064.38.camel@quad>
--=-WUmBC9TzSnFpS1S7Bao5
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Actually not. The hardware Firewire controller in your computer has
direct memory access. Through the Passware kit you connect 2 computers
using firewire. The target computer sees a new Firewire storage device
connecting, and nothing else happens on screen. The attacking computer,
running Passware Kit, makes a live memory dump of all physical memory
over Firewire. Then you'll need a couple of minutes maximum to search
the memory dump to recover the Bitlocker key.

We're talking about a Firewire FEATURE, not a bug.

As I wrote earlier, Passware introduced this at the Passwords^10
conference, and you can see our video recording of their presentation
and live demo (as well as others) here:
ftp://ftp.ii.uib.no/pub/passwords10/

Yes, we were pretty amazed and scared at the same time when we saw it
live. I don't remember, but you'll probably here some comments about
superglue at the Q&A at the end of their presentation.

Best regards,
Per Thorsheim


On Thu, 2011-02-24 at 21:25 +0000, Thor (Hammer of God) wrote:
> I assume he's talking about after you have logged on and the computer is =
locked and you retrieve it from "live" memory a.k.a the memory freezing att=
ack.  I would actually like to see that work IRL.  If it were that easy, yo=
u wouldn't need recovery agents :)


> -----Original Message-----
> From: [email protected] [mailto:[email protected]] =
On Behalf Of John Lightfoot
> Sent: Thursday, February 24, 2011 12:37 PM
> To: 'Per Thorsheim'; 'focus-ms'
> Subject: RE: Bitlocker without PIN
>=20
> I agree that transparent Bitlocker is a great security tool.
>=20
> Per, could you provide more details where you say:=20
>=20
> "Using Passware Forensic Toolkit you can extract the bitlocker key using =
live memory dumping through Firewire (either by using an existing Firewire =
port, or by inserting an pcmcia/expresscard firewire card). No need to logo=
n to Windows there..."
>=20
> My understanding of the way Bitlocker works is that when you enable full-=
disk encryption, Bitlocker creates a small, unencrypted partition that cont=
ains the Windows login module.  Once you've entered your credentials and th=
ey've been validated, the login module uses them to access the TPM for the =
key to decrypt the rest of the hard drive.  I do not believe the encryption=
 key is resident in memory until after the login credentials are verified, =
so I don't think the firewire hack or other memory scanning techniques woul=
d allow you to retrieve the key prior to authentication.
>=20

--=-WUmBC9TzSnFpS1S7Bao5
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEABECAAYFAk1m0LEACgkQsXl+Y9DQrvZR8QCfaM1gevnX+pBJnirmtj6oQzZx
e9sAniuyxYKrVEPm2SQihSxmh5M4h0XH
=XMC4
-----END PGP SIGNATURE-----

--=-WUmBC9TzSnFpS1S7Bao5--