RE: Bitlocker without PIN
Per Thorsheim <[email protected]> Thu, 24 Feb 2011 22:42:14 +0100
| Newsgroups | gmane.comp.security.microsoft |
|---|---|
| Message-ID | <1298583734.22064.38.camel@quad> |
--=-WUmBC9TzSnFpS1S7Bao5 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Actually not. The hardware Firewire controller in your computer has direct memory access. Through the Passware kit you connect 2 computers using firewire. The target computer sees a new Firewire storage device connecting, and nothing else happens on screen. The attacking computer, running Passware Kit, makes a live memory dump of all physical memory over Firewire. Then you'll need a couple of minutes maximum to search the memory dump to recover the Bitlocker key. We're talking about a Firewire FEATURE, not a bug. As I wrote earlier, Passware introduced this at the Passwords^10 conference, and you can see our video recording of their presentation and live demo (as well as others) here: ftp://ftp.ii.uib.no/pub/passwords10/ Yes, we were pretty amazed and scared at the same time when we saw it live. I don't remember, but you'll probably here some comments about superglue at the Q&A at the end of their presentation. Best regards, Per Thorsheim On Thu, 2011-02-24 at 21:25 +0000, Thor (Hammer of God) wrote: > I assume he's talking about after you have logged on and the computer is = locked and you retrieve it from "live" memory a.k.a the memory freezing att= ack. I would actually like to see that work IRL. If it were that easy, yo= u wouldn't need recovery agents :) > -----Original Message----- > From: [email protected] [mailto:[email protected]] = On Behalf Of John Lightfoot > Sent: Thursday, February 24, 2011 12:37 PM > To: 'Per Thorsheim'; 'focus-ms' > Subject: RE: Bitlocker without PIN >=20 > I agree that transparent Bitlocker is a great security tool. >=20 > Per, could you provide more details where you say:=20 >=20 > "Using Passware Forensic Toolkit you can extract the bitlocker key using = live memory dumping through Firewire (either by using an existing Firewire = port, or by inserting an pcmcia/expresscard firewire card). No need to logo= n to Windows there..." >=20 > My understanding of the way Bitlocker works is that when you enable full-= disk encryption, Bitlocker creates a small, unencrypted partition that cont= ains the Windows login module. Once you've entered your credentials and th= ey've been validated, the login module uses them to access the TPM for the = key to decrypt the rest of the hard drive. I do not believe the encryption= key is resident in memory until after the login credentials are verified, = so I don't think the firewire hack or other memory scanning techniques woul= d allow you to retrieve the key prior to authentication. >=20 --=-WUmBC9TzSnFpS1S7Bao5 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEABECAAYFAk1m0LEACgkQsXl+Y9DQrvZR8QCfaM1gevnX+pBJnirmtj6oQzZx e9sAniuyxYKrVEPm2SQihSxmh5M4h0XH =XMC4 -----END PGP SIGNATURE----- --=-WUmBC9TzSnFpS1S7Bao5--