Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If the computer is suspended at the time it's seized, does it become easier to recover the FDE key from the computer's memory? Or is that encrypted with the user password, or something like that? (On stock ubuntu, say.)


If the DRAM is powered on at the time of seizure, recovering the key is eminently possible. If this is an issue for you, completely power off the laptop when transiting customs.

https://en.wikipedia.org/wiki/Cold_boot_attack


If you can dump the contents of memory then you have the key (after all, the CPU has to be able to encrypt and decrypt the material, so it has to be available).


Pedantically, if there's an HSM/similar hardware in play, the CPU only asks for material to be encrypted/decrypted and doesn't have the key in system RAM to be able to do so itself.

MacOS machines with a T2 chip keep the encryption key in the T2 chip so it isn't in system RAM.


Apparently it's possible to keep the key in the debug registers: https://en.wikipedia.org/wiki/TRESOR




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: