RE: [Full-disclosure] Firewire Attack on Windows Vista

看板Bugtraq作者時間18年前 (2008/03/11 03:00), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串10/10 (看更多)
>>You're mistaken in thinking that we're conflating sleep and hibernate modes. >>Microsoft's response of using two factor authentication is silly. It doesn't actually stop our attacks. In certain circumstances, it may shorten the window of attack for a specific type of user but it's mostly irrelevant. Consider a mail server with an encrypted drive, no proximity sensor or two factor authentication is going to help you. A seizure will still result in someone getting the keys that are in memory - unless you're using some sort of secure crypto co-processor (which no one is). From your own paper: > Microsoft ... recommends configuring BitLocker in "advanced > mode," where it protects the disk key using the TPM along with a password or a key on a removable > USB device. However, even with these measures, BitLocker is vulnerable if an attacker gets to the system > while the screen is locked or the computer is asleep (though not if= it is hibernating or powered off).=20 So in other words, hibernate does make a difference, especially if you follow their guidelines. Larry Seltzer eWEEK.com Security Center Editor http://security.eweek.com/ http://blogs.pcmag.com/securitywatch/ Contributing Editor, PC Magazine larry.seltzer@ziffdavisenterprise.com
文章代碼(AID): #17rOLU00 (Bugtraq)
討論串 (同標題文章)
文章代碼(AID): #17rOLU00 (Bugtraq)