Slashdot Mirror


Of Encrypted Hard Drives and "Evil Maids"

Schneier has a blog piece about Joanna Rutkowska's "evil maid" attack, demonstrated earlier this month against TrueCrypt. "The same kind of attack should work against any whole-disk encryption, including PGP Disk and BitLocker. ... [A] likely scenario is that you leave your encrypted computer in your hotel room when you go out to dinner, and the maid sneaks in and installs the hacked bootloader. ... [P]eople who encrypt their hard drives, or partitions on their hard drives, have to realize that the encryption gives them less protection than they probably believe. It protects against someone confiscating or stealing their computer and then trying to get at the data. It does not protect against an attacker who has access to your computer over a period of time during which you use it, too."

10 of 376 comments (clear)

  1. surprise by jacquesm · · Score: 5, Informative

    physical access > digital security

    1. Re:surprise by malakai · · Score: 5, Informative

      My god the mod's today suck. All of these "Then don't leave yourself logged in" responses are getting +mod.

      This attack has NOTHING to do with you leaving your session authenticated and open. It's about a boot-loader level phish scheme.

      Basically, you come back to your laptop which you left off, you boot it up not noticing anything out of place, and you log in an unlock your drives. Meanwhile, little did you know that the intruder put a very small OS on to your laptop which runs your primary OS as a virtual OS. It's got low level hooks to all the basic INT's and can read any memory without chance of any program within your primary OS (now virtualized) detecting it.

      Then you log off and go out to dinner. The maid comes in, boots up, hits a key-sequence, and dumps a log to a USB drive. In that log somewhere is your password to your encrypted drives. Game over dude... game fucking over.

  2. At the next defcon... by purpledinoz · · Score: 5, Funny

    I'm imagining a bunch of geeks dressed up in maid outfits.

    1. Re:At the next defcon... by Anonymous Coward · · Score: 5, Funny

      Holy crap slashdot, you scare me! That was not sold out when I posted it.

  3. Fine line between security and paranoia by elrous0 · · Score: 5, Interesting

    Seriously, if you're worried about some hacker assassin breaking into your house or office and installing a bootloader, you're either doing something REALLY secretive (in which case the computer probably shouldn't even be on a network to upload any data back in the first place) or you're the kind of person who thinks Obama has your name on an "important persons" list and is coming for your guns. If someone has physical access to your machine and has the skills to install a bootloader, you're pretty much boned anyway, encryption or not (encryption isn't going to stop a simple keylogger). That's nothing new. Fortunately, for the vast vast majority of us, there are very few hacker black operatives who are running around breaking into hotel rooms just so they can get a single Visa number from Bob the dipshit middle manager. Newsflash Bob, YOU'RE NOT THAT IMPORTANT!

    Oh, and I love how the article calls the prospect of a ninja hacker hotel maid sneaking a bootloader onto your laptop and then sneaking back into your room later to retrieve the data a "likely scenario." What hotels is this guy staying at anyway?

    --
    SJW: Someone who has run out of real oppression, and has to fake it.
    1. Re:Fine line between security and paranoia by Umuri · · Score: 5, Insightful

      Offhand, i'd say any prominent high-class hotel that might be used by foreign businessmen on a trip.

      I mean, you do have a point, bob the middle manager isn't that important. However there are quite a few business people who this really would be that important to. Corporate espionage is high, and you know china has been doing focused attacks over the network.

      Sneakernet is always faster, so if they can train up a few pretty women, pay them a decent programmers wage to have them steal stuff that is the work of 10 engineers or even hundreds, that's a pretty sound economic payoff don't you think?

      I think stuff like this has it's purpose, and those who really are at risk need to be educated about it. For the other 95% of us, i think it's useful info to be aware about, just like don't leave your purse out visible in your car. Sure it probably won't happen, but there are always people who would.

      --
      You never realize how much manually made unmanaged "linked" lists suck, till you have src.link.link.link.link...
    2. Re:Fine line between security and paranoia by oldspewey · · Score: 5, Insightful

      Bob the middle manager isn't that important, but Bob routinely sends email to Dave the director and Charles the CxO. By trojaning Bob's computer you can start to build a pretty decent profile of the corporate activities going on within, and above, Bob's department ... including travel schedules of some other bigger fish in the corporate pond.

      Do this to 3 or 4 Bobs, and pretty soon you'll have an understanding of the corporate org chart, upcoming projects, and most importantly you'll be able to target your future EvilMaid attacks with pinpoint accuracy.

      --
      If libertarians are so opposed to effective government, why don't they all move to Somalia?
  4. And that's the lesser evil by Thanshin · · Score: 5, Funny

    You could have found the evil bartender.

    You leave your laptop at the hotel and you go out to take a beer. There, you meet the evil bartender, who because of a common past becomes your friend and starts inviting you to more and more beer. Then he closes the bar and you both go to a strip club where you meet the evil bartender's girlfriend and her friend who we shall call "Foxette".

    The next morning, you wake up in an unknown appartment with Foxette and a guy you don't even know. You quickly get out of there and go to work, with such a massive headache than when asked about the laptop's full disk encription, you answer is "the what?".

  5. Re:Bucket List by Gulthek · · Score: 5, Funny

    The hypnotoad security tool protects against the all-knowing frog attack, but comes with its own drawbac--ALL GLORY TO THE HYPNOTOOL.

  6. Re:My bootloader is on USB by russotto · · Score: 5, Funny

    If someone wants your information that bad, they just need a pair of pliers to succeed with the attack.

    1) Step one: apply pliers to target's scrotum.
    2) Ask them once to access the laptop.
    3) If any resistance is given, squeeze the pliers just a tad.

    Now, leave it to a bunch of nerds to come up with technical workarounds and miss the real point.

    Workaround 1) Make sure only women have the information.
    Workaround 2) Preventative castration
    Workaround 3) Shoot anyone with pliers who comes within 10 feet
    Workaround 4) Duress code which releases false information. (this one's likely practical but only as a delaying tactic; it's going to hurt a lot when the interrogator finds the information doesn't verify)