PDA

View Full Version : New Passware Can Crack PGP- and BitLocker-Protected Systems


snowdrift
December 4th, 2009, 09:40 AM
If a forensics analyst or thief/adversary has physical access to a running system, it is possible to take advantage of the fact that the contents that are in a computer's memory are accessible through users with administrative privilege and/or specific direct memory access hardware methods (if available).
-- Microsoft

http://blogs.pcmag.com/securitywatch/2009/12/new_passware_can_crack_pgp_and.php

chronomatic
December 4th, 2009, 02:09 PM
Old news. This was first demonstrated almost 2 years ago by Princeton university researchers. (http://citp.princeton.edu/memory/) These guys at "Passware" seem to have simply made the process more automated.

Bottom line: physical access when machine is running == pwnage