Re: the cold-boot attack

markus reichelt <[email protected]>
Newsgroups gmane.linux.cryptography
Organization still stuck in reorganization mode
Message-ID <[email protected]>
* Jacob Appelbaum <[email protected]> wrote:

> Our paper is clear.

Link?

As already stated numerious times, if theres root access (eg full
access to a machine's memory, including a virtual machine) it's a
piece of cake to get one's hands on the key. Key scrubbing in
loop-AES only slightly complicates the issue, but as it has been
publicly proven to work to snatch ssh keypairs from memory, it's just
emphasising an attack vector that exists by design. And all the other
publicly known linux crypto implementations suffer from it.

IIRC, key scrubbing has been implemented in loop-AES because some
Gutmann paper mentioned possible key recovery from imprinted RAM
patterns.

Please, before stating your claims be sure to clearly point out your
attack vector.

-- 
left blank, right bald
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)

iD8DBQFHvgZBLMyTO8Kj/uQRAksBAJ4u7BRYjeiRiPvSo+WG5JUbCtquAgCfXGRb
Pvqpa2fnC1Woegw6418PPH8=
=I20L
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.