<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; appelbaum</title>
	<atom:link href="http://hackaday.com/tag/appelbaum/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Sun, 12 Feb 2012 08:27:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; appelbaum</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>HOPE 2008: Cold boot attack tools released</title>
		<link>http://hackaday.com/2008/07/18/hope-2008-cold-boot-attack-tools-released/</link>
		<comments>http://hackaday.com/2008/07/18/hope-2008-cold-boot-attack-tools-released/#comments</comments>
		<pubDate>Sat, 19 Jul 2008 01:45:00 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[appelbaum]]></category>
		<category><![CDATA[coldboot]]></category>
		<category><![CDATA[hope]]></category>
		<category><![CDATA[jacobappelbaum]]></category>
		<category><![CDATA[memory]]></category>
		<category><![CDATA[princeton]]></category>
		<category><![CDATA[thelasthope]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/07/18/hope-2008-cold-boot-attack-tools-released/</guid>
		<description><![CDATA[The team from Princeton has released their cold boot attack tools at The Last HOPE. Earlier this year they showed how to recover crypto keys from the memory of a machine that had been powered off. Now they&#8217;ve provided the tools necessary to acquire and play around with your own memory dumps. The bios_memimage tool [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2305&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img width="450" vspace="4" hspace="4" height="160" border="0" src="http://hackadaycom.files.wordpress.com/2008/07/had_boot-1.jpg?w=450&#038;h=160" alt="" /><br />The team from Princeton has <a href="http://citp.princeton.edu/memory/code/">released their cold boot attack tools</a> at <a href="http://www.mahalo.com/The_Last_HOPE_Conference">The Last HOPE</a>. Earlier this year they showed how to recover crypto keys from the <a href="http://www.hackaday.com/2008/02/21/breaking-disk-encryption-with-ram-dumps/">memory of a machine that had been powered off</a>. Now they&#8217;ve provided the tools necessary to acquire and play around with your own memory dumps. The bios_memimage tool is written in C and uses PXE to boot the machine and copy the memory. The package also has a disk boot dumper with instructions for how to run it on an iPod. There&#8217;s also efi_memimage which implements the BSD TCP/IP stack in EFI, but it can be problematic. aeskeyfind can recover 128 and 256bit AES keys from the memory dumps and rsakeyfind does the same for RSA. They&#8217;ve also provided aesfix to correct up to 15% of a key. In testing, they only ever saw 0.1% error in there memory dumps and 0.01% if they cooled the chips first.</p>
<p><span id="more-2305"></span></p>
<p>We saw another interesting tool today: <a href="http://www.coreboot.org/Coreinfo">coreinfo</a> is a library for the custom BIOS coreboot. Using it you can examine the memory directly without any damage.</p>
<p>The Q&amp;A session at the end of [Jacob Appelbaum]&#8216;s talk included a discussion of possible countermeasures. We&#8217;re convinced that this won&#8217;t be solved until there&#8217;s a fundamental change to RAM design. One of the interesting suggestions we heard was building a &#8220;RAM condom&#8221;. It would be a riser card that the RAM plugs into. When the case intrusion system triggered it would blank the RAM. It&#8217;s an interesting idea; anyone want to build it?</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2305/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2305/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2305/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2305/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2305/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2305/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2305/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2305/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2305/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2305/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2305&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/07/18/hope-2008-cold-boot-attack-tools-released/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/07/had_boot-1.jpg" medium="image" />
	</item>
	</channel>
</rss>
