Study: Disk Encryption Not Secure, Particularly With Laptops

SAN FRANCISCO — A team of researchers has found a major security flaw in several popular disk-encryption technologies that leaves encrypted data vulnerable to attack and exposure, particularly when laptops are in sleep mode.

Researchers from the Electronic Frontier Foundation and Princeton University have cracked several widely used disk encryption technologies, including Microsoft's BitLocker, Apple's FileVault, TrueCrypt and dm-crypt.

Those disc encryption systems are designed to protect sensitive information if a computer is stolen or otherwise accessed, but researchers said data is still vulnerable because encryption keys and passwords stored in a computer's temporary memory, or RAM, don’t disappear immediately after losing power.

"People trust encryption to protect sensitive data when their computer is out of their immediate control," EFF spokesman Seth Schoen said. "But this new class of vulnerabilities shows it is not a sure thing.

“Whether your laptop is stolen or you simply lose track of it for a few minutes at airport security, the information inside can still be read by a clever attacker," he said.

Laptops are particularly vulnerable to attack when they are turned on but locked, or in sleep or hibernation mode entered when the laptop's cover is shut, the EFF said.

Researchers said that even though the machines require a password to unlock the screen, the encryption keys are already located in the RAM, which provides an opportunity for attackers with malicious intent.

For the full paper, "Lest We Remember: Cold Boot Attacks on Encryption Keys," a demonstration video and other background information, click here.

Related:  

Copyright © 2025 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

'White-Hot' Party Set to Kick Off XBIZ Miami

XBIZ is pleased to announce that the annual White-Hot Party, the official opening bash of XBIZ Miami, is set for Monday, May 19, at Mynt Lounge in South Beach.

AEBN Publishes Popular Searches for March, April

AEBN has announced the top search terms for March and April from its straight and gay theaters in all 50 states and the District of Columbia.

Takedown Piracy Adds 'Search Max' Feature

Takedown Piracy has launched Search Max, a search engine for detecting, verifying, and removing Google infringements.

Sex Workers' Group Fights Proposed Swedish Ban on 'Remote' Sexual Services

The European Sex Workers’ Rights Alliance (ESWA) has launched a campaign against a Swedish government proposal to expand current laws against purchasing sexual services to apply to acts performed remotely by cammers, streamers and custom content creators.

FSC: Arizona Governor Signs Controversial Age Verification Law

Free Speech Coalition has released a statement regarding Arizona Governor Katie Hobbs signing the state's age verification bill into law.

NCOSE Sues 4 Adult Websites Under Kansas Age Verification Law

The National Center on Sexual Exploitation (NCOSE), a conservative anti-pornography organization, has sued four adult websites in Kansas under the state's age verification law.

Sarina Havok, Robin Coffins Launch New Site Through Grooby's Blue.xxx

Sarina Havok and Robin Coffins have launched their new membership site, SarinaAndRobin.com, through Grooby's website management company Blue.xxx.

SpankChain Pauses SpankPay, SpankMatch

SpankChain has paused SpankPay, its adult crypto payment platform, and SpankMatch, its adult networking platform.

Sen. Mike Lee Tries Again to Criminalize All Porn With Interstate Obscenity Definition Act

Republican Senator Mike Lee of Utah has introduced the Interstate Obscenity Definition Act, which would redefine almost all visual depictions of sex as obscene and therefore illegal.

Ofcom Investigates 2 Adult Sites for AV Noncompliance

U.K. media regulator Ofcom is investigating two adult sites for failure to comply with age assurance requirements under the Online Safety Act, which Ofcom is charged with enforcing.

Show More