Study: Disk Encryption Not Secure, Particularly With Laptops

SAN FRANCISCO — A team of researchers has found a major security flaw in several popular disk-encryption technologies that leaves encrypted data vulnerable to attack and exposure, particularly when laptops are in sleep mode.

Researchers from the Electronic Frontier Foundation and Princeton University have cracked several widely used disk encryption technologies, including Microsoft's BitLocker, Apple's FileVault, TrueCrypt and dm-crypt.

Those disc encryption systems are designed to protect sensitive information if a computer is stolen or otherwise accessed, but researchers said data is still vulnerable because encryption keys and passwords stored in a computer's temporary memory, or RAM, don’t disappear immediately after losing power.

"People trust encryption to protect sensitive data when their computer is out of their immediate control," EFF spokesman Seth Schoen said. "But this new class of vulnerabilities shows it is not a sure thing.

“Whether your laptop is stolen or you simply lose track of it for a few minutes at airport security, the information inside can still be read by a clever attacker," he said.

Laptops are particularly vulnerable to attack when they are turned on but locked, or in sleep or hibernation mode entered when the laptop's cover is shut, the EFF said.

Researchers said that even though the machines require a password to unlock the screen, the encryption keys are already located in the RAM, which provides an opportunity for attackers with malicious intent.

For the full paper, "Lest We Remember: Cold Boot Attacks on Encryption Keys," a demonstration video and other background information, click here.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Rights Groups File Amicus Brief Supporting Backpage Defendants

Woodhull Freedom Foundation has joined Foundation for Individual Rights and Expression, Reason Foundation, and Electronic Frontier Foundation in filing an amicus brief in support of an appeal by the former operators of Backpage.com.

UK Lawmaker Calls for Ban on Choking in Online Adult Content

British lawmaker Jessica Asato stated in an interview aired on Sunday that she plans to ask Parliament to outlaw online adult content featuring the act of choking.

Feet4Cash Joins Pineapple Support as Sponsor

Feet4Cash has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

Report: VPN Usage Surges in France After Aylo Restricts Access to Pornhub

France has experienced a surge in virtual private network (VPN) signups after Aylo, which operates Pornhub, Redtube and YouPorn, cut off access to those sites in the country in the wake of new age verification regulations, business news site MENAFN is reporting.

New Creator Directory 'TrustyFans' Launches

TrustyFans, a newly launched directory designed to help fans discover their favorite creators, is now live.

Corey Silverstein to Host Webinar on 'SCOTUS Age Verification Ruling'

Where Does Age Verification Go From Here," to livestream July 10 at 4 p.m. (EDT).

FSC Publishes Guidance on Google Analytics Lawsuits

The Free Speech Coalition (FSC) has published guidance on how adult websites can protect themselves in the wake of several consumer class action lawsuits filed against sites for using Google Analytics.

BranditScan, CreatorTraffic Partner for 'Creators & Agencies' Initiative

BranditScan and advertising network CreatorTraffic have partnered for an initiative to help creators and agencies generate traffic and protect their content.

Teasy Agency Joins Pineapple Support as Supporter-Level Sponsor

Teasy Agency has joined the ranks of over 70 adult businesses and organizations committing funds and resources to Pineapple Support.

Aylo, Pineapple Support Partner for Mental Health Video Series

Aylo has teamed up with Pineapple Support to create a safety video series aimed at educating performers and creators about mental health.

Show More