<?xml version="1.0"?>
<rss version="2.0">
<channel>
  <title>Markus&#039; Blog - theinvisiblethings tag</title>
  <link>http://www.tower-net.de:80/blog/tags/theinvisiblethings/</link>
  <description>Frenzied programming..., tech..., climbing..., sports..., mountain..., nature... and futile notes</description>
  <language>en</language>
  <copyright>Markus Kolb</copyright>
  <lastBuildDate>Wed, 20 Jul 2011 18:43:00 GMT</lastBuildDate>
  <generator>Pebble (http://pebble.sourceforge.net)</generator>
  <docs>http://backend.userland.com/rss</docs>
  
  <image>
    <url>http://www.tower-net.de/blog/favicon.ico</url>
    <title>Markus&#039; Blog</title>
    <link>http://www.tower-net.de:80/blog/</link>
  </image>
  
  
  <item>
    <title>Encrypted harddisks are not safe</title>
    <link>http://www.tower-net.de:80/blog/2009/10/18/1255819020000.html</link>
    
      
        <description>
          The harddisk encryption is only defense against simple theft.&lt;br /&gt;
A spy can install a tool on Alice&#039;s unattended computer and get to know the password for her encrypted disk.&lt;br /&gt;
Afterwards the spy Bob knows the password and can boot Alice&#039;s computer with its encrypted harddisk or can copy all the unencrypted disk data.&lt;br /&gt;
The so called &amp;quot;&lt;a href=&#034;http://theinvisiblethings.blogspot.com/2009/10/evil-maid-goes-after-truecrypt.html&#034;&gt;Evil Maid Attack&lt;/a&gt;&amp;quot; by Joanna Rutkowska replaces the boot code on disk to sniff Alice&#039;s password and continues with boot afterwards.&lt;br /&gt;
If the boot is protected by BIOS, Bob has to connect the encrypted disk to an own computer to install the tool.&lt;br /&gt;
If the encryption is hardware based there might be possibilities to hack the BIOS for a password sniffer. But this kind of encryption is much safer because Bob has to know a lot specifics about Alice&#039;s computer. Bob might run out of time doing his work without getting nabbed by Alice.&lt;br /&gt;
Mmh. I&#039;ve to check the laptop of our team. I&#039;m interested in how safe its encryption is ;-)
        </description>
      
      
    
    
    
    <category>tech</category>
    
    <comments>http://www.tower-net.de:80/blog/2009/10/18/1255819020000.html#comments</comments>
    <guid isPermaLink="true">http://www.tower-net.de:80/blog/2009/10/18/1255819020000.html</guid>
    <pubDate>Sat, 17 Oct 2009 22:37:00 GMT</pubDate>
  </item>
  
  </channel>
</rss>

