Gentoo Archives: gentoo-user

From: Hans-Werner Hilse <hilse@×××.de>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Can RAM render useless the encryption of the / and swap partitions?
Date: Fri, 05 Oct 2007 11:53:28
Message-Id: 20071005133839.a83efe0e.hilse@web.de
In Reply to: Re: [gentoo-user] Can RAM render useless the encryption of the / and swap partitions? by Liviu Andronic
1 Hi,
2
3 On Thu, 4 Oct 2007 20:33:40 +0200 "Liviu Andronic"
4 <landronimirc@×××××.com> wrote:
5
6 > On 10/4/07, Alan McKinnon <alan@××××××××××××××××.za> wrote:
7 > > On Thursday 04 October 2007, Hans-Werner Hilse wrote:
8 > > > However, it makes sense to clean up memory after having
9 > > > critical data in it -- e.g. a reboot doesn't necessarily clean up
10 > > > RAM.
11 > >
12 > > Yes, this is very true
13 >
14 > BUT
15 >
16 > On 10/4/07, Alan McKinnon <alan@××××××××××××××××.za> wrote:
17 > > Pray tell, how does RAM manage to retain data when the power is off?
18 >
19 > ...and...
20 > On 10/4/07, Volker Armin Hemmann
21 > <volker.armin.hemmann@××××××××××××.de> wrote:
22 > > In practice, after power is cut, everything in ram is lost.
23 >
24 > So, my eternal question, is it realistic for the "lost" RAM data to be
25 > recovered? That is, after system shutdown, does the data still
26 > physically reside on the RAM and can someone with a decent technology
27 > and know-how recover it? In other words, is this a serious breach in
28 > any encrypted system?
29
30 No, it isn't. Well, I didn't had the full circuit design of today's
31 DRAMs in mind, and yes, since there's the resistor, the capacitor will
32 lose its load (very) soon (/me scratches his head, wasn't there
33 something asymptotically in that graph? But in any way, it would be a
34 difference of very few electrons on the sides of the capacitor) --
35 that's not a security breach.
36
37 But: We are talking about _powering_ _off_ the DRAM. You are talking
38 about shutting down. That might be two different things and completely
39 depend on hardware design. Make shure that RAM's gonna get powered off
40 and you're save. So pulling the plug should give you a warm good
41 feeling in that regard. Doing a "sudo halt", however, _might_ have
42 other consequences and we cannot make a general assumption on that.
43 Even pulling the plug might have problems: There's such thing as
44 battery-buffered RAM (although I think they've used it mainly in the
45 pre-Flash era).
46
47 The thing is: You never can guarantee security, that's absolutely
48 impossible (well, of course you can, but you would automatically be
49 wrong). You can do all your best, but that's about it. Having security
50 is a thing you can falsify, but never verify, since theorys can't be
51 verified without dogmas (and there are no accepted dogmas that would
52 help here).
53
54 -hwh
55 --
56 gentoo-user@g.o mailing list

Replies

Subject Author
Re: [gentoo-user] Can RAM render useless the encryption of the / and swap partitions? Randy Barlow <randy@×××××××××××××××××.com>
Re: [gentoo-user] Can RAM render useless the encryption of the / and swap partitions? Liviu Andronic <landronimirc@×××××.com>