Researchers break into Windows encryption feature
By Asavin Wattanajantra,
Researchers can break into BitLocker, the disk encryption feature available in Windows 7, Vista and Server 2008.
German experts from the Franhofer Institute for Secure Information Technology (SIT) revealed five attack strategies against BitLocker and the way its Trusted Platform Module (TPM) sealing mechanism works.
In certain circumstances, the researchers claim that dedicated hackers could “circumvent the protection and break confidentiality with limited effort".
"Our attacks neither exploit vulnerabilities in the encryption itself nor do they directly attack the TPM," the researchers claim in a report.
“They rather exploit sequences of actions that Trusted Computing fails to prevent, demonstrating limitations of the technology.”
One attack took advantage of the boot process, where BitLocker needs to interact with the user to obtain a password or a key file from a USB memory stick, or both.
The program code interacting with the user is unencrypted, so an attacker with physical access is able to modify it.
The hacker could replace the original BitLocker boot code with a manipulated version, and spoof the user interaction with BitLocker.
The researchers made it clear that that they were using ‘targeted attacks’, where an attacker would devote considerable effort in trying to access data on a disk, for example in corporate espionage.
BitLocker is better designed to withstand real-world ‘opportunistic attacks’ for example, if a computer was stolen and somebody was trying to access the data to see what they could get.
Paul Cooke from Microsoft confirmed as much in a blog post. He said: "This research is similar to other published attacks where the owner leaves a computer unattended in a hotel room and anyone with access to the room could tamper with this computer.
"This sort of targeted attack poses a relatively low risk to folks who use BitLocker in the real world."
He added: "These sorts of targeted threats are not new and are something we've addressed in the past; in 2006 we discussed similar attacks, where we've been straightforward with customers and partners that BitLocker does not protect against these unlikely, targeted attacks."
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Public Sector Analysis & Insight
Striving to solve the security skills crisis
The Cyber Security Challenge is doing a fine job, but flat registration growth and weak Government funding are cause for concern, Tom Brewster discovers.
- 2011: The year in news
- Are the cookie laws crumbling already?
- UK rural broadband: too little, and too late
- How the Data Protection Act's death will punish the UK economy
- Education: glad to be a geek
- Plugging public sector data leaks
- Going for Gold - IT at the London Olympics
- Fujitsu: out to steal HP market share
- What will Windows Mango mean for business?
Latest Public Sector Reviews
HTC Flyer review: First Look
- HP TouchPad review: First Look
- RIM BlackBerry PlayBook review - First Look
- MWC 2011: Acer Iconia A100 and A500 reviews – first look videos
- MWC 2011: HP TouchPad review - first look video
- MWC 2011: RIM BlackBerry PlayBook review - first look video
- MWC 2011: HP Pre3 review - first look video
- MWC 2011: Motorola Pro review - first look video
- MWC 2011: HTC Flyer tablet review - first look video
- MWC 2011: Samsung Galaxy Tab 10.1 review – first look video
advertisement
Most popular
- Will someone rid me of these troublesome Macs?
- Symantec hackers: We've released pcAnywhere source code
- BT considering Ofcom price cap appeal
- Google sends in Bouncer to sort out malicious apps
- ACTA: the basics, the controversies, and the future
- Trendnet firmware flaw exposes private videos
- Anonymous publishes FBI hacking call
- Head to Head: Mac OS X 10.7 Lion vs Windows 7
- VeriSign admits 2010 hack
- Nokia Lumia 710 review
Latest News Videos in Public Sector
Q&A: David Elton, PA Consulting Group
CIOs are increasingly influential, but have to juggle "dual roles", study finds.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.




