WWDC rumor roundup: Retina display Macs, iCloud photo sharing, new iOS Maps

  • Filing details Apple's plans for Retina-ready resolution-independent OS X

  • Apple said to be ordering 4" screens for next iPhone

  • Steve Jobs wanted to build 'iCar,' Apple board member says

  • Free Overnight Shipping on all Macs, lowest prices of the year: Mac Price Guide updated May 18th. (Find the best prices on Macs)
    Wednesday, February 1, 2012

    Forensics vendor warns Mac OS X FileVault vulnerable to decryption

    By Daniel Eran Dilger

    Published: 04:12 PM EST (01:12 PM PST)


    Passware, a vendor of forensics tools for recovering data for law enforcement, has issued a warning that its forensics tools can bypass the security of FileVault disk encryption in Mac OS X if the computer is left powered on, recovering decryption keys from memory.

    While catering to law enforcement, the company issued a warning to home users "of the vulnerabilities of Mac encryption solutions and advises users to shut down their computers especially when working with confidential data."

    When a system using full disk encryption is powered on, even if the disk is later left encrypted its contents can reportedly be recovered by analyzing the data stored in memory, which Passware notes includes the keys to decrypt FileVault.

    The company says its process for decrypting a FileVault disk "takes no more than 40 minutes – regardless of the length or complexity of the password."

    Passware's president Dmitry Sumin stated in a release that "live memory analysis opens up great possibilities to password recovery and decryption. Every user should be aware that even full disk encryption is insecure while the data rests in computer memory."

    The company earlier explained that the security risk is easy to overcome by simply turning off the computer instead of putting it to sleep, and disabling the "Automatic Login" setting. This way, passwords will not be present in memory and cannot be recovered.

    Sumin wrote last summer, "I am a Mac user myself, but it's important to understand the limitations of your computer's security, even if you are not a computer forensics expert. If data stored is confidential, it is important to ensure physical security of the computer. One might also consider using additional encryption software."

    Obtaining Mac passwords costs more

    In addition to Mac OS X Lion's FileVault, the company says its forensics tools can decrypt Microsoft's Windows 7 BitLocker and the cross platform TrueCrypt full disk encryption solution, indicating that the problem isn't unique to Apple.

    The company, based in Moscow Russia with offices in Mountain View, California, sells its Passware Kit Forensic for $995 with a year's worth of updates. It says the product can recover hashed passwords with Rainbow Tables, extract passwords from the Mac Keychain, and build a password list from words detected in computer memory to perform a Dictionary attack.

    The company describes the product as being "the first and only commercial software that decrypts BitLocker and TrueCrypt hard disks, and instantly recovers or bypasses Mac and Windows login passwords of seized computers."

    The company also sells a $39 tool to "quickly and easily reset Windows login passwords in a matter of minutes," as well as a $79 package that "recovers passwords for Microsoft Office files, Acrobat documents, email accounts, network connections, Zip and Rar archives and local Windows Administrator" accounts on workstations and servers running Windows 7/vista/SP/2000/NT.

    Filed under : Mac OS X 52 Comments ] 
    Story topics: Security, FileVault   Print ] [ Story Link ] 


    RSS
    RSS
    Mac Connection End of Summer Sale
    MacBook Pro Model
    Apple
    Price
    Discount
    2.4GHz dual 13" MacBook Pro $1,199.00 $1,086.34 $112.66
    2.8GHz dual 13" MacBook Pro $1,499.00 $1,382.19* $116.81
    2.2GHz quad 15" MacBook Pro $1,799.00 $1,629.54* $196.46
    2.4GHz quad 15" MacBook Pro $2,199.00 $1,971.54* $227.46
    2.4GHz quad 17" MacBook Pro $2,499.00 $2,250.39* $248.61
    Early 2011 MacBook Pro Model
    Apple
    Price
    Discount
    2.7GHz dual 13" MacBook Pro $1,499.00 $1,178.59* $320.41
    2.0GHz quad 15" MacBook Pro $1,799.00 $1,503.49* $295.51
    2.2GHz quad 15" MacBook Pro $2,199.00 $1,606.23* $592.77
    2.2GHz quad 17" MacBook Pro $2,499.00 $1,736.78* $762.22
    *Instant 3% AppleInsider Reader Discount Applied With Coupon code:
    APPINSDRMWB32657

    AppleInsider Features
    Hot Forum Topics

    Recent Articles
    AT&T reportedly unlocking iPhones for deployed military personnel
    Analyst cuts AAPL rating on iPhone subsidy backlash, estimates $1B earnings miss
    AT&T to spend $150M on Lumia launch, more than it did with iPhone
    As 'iPad' becomes synonymous with 'tablet,' Apple must protect brand
    Facebook acquires Instagram for $1 billion
    Apple's Tim Cook awarded $378M in 2011, won't see most of it for years
    Apple's next iPhone predicted to have redesigned 'sleek' unibody case
    AT&T's iPhone unlock process accomplished through Apple's iTunes
    Foxconn employee says Apple placing orders for next iPhone to debut in October
    Most of estimated 21M iOS devices in China concentrated in urban areas
    Universal Pictures now available to re-download on Apple's iCloud
    New aerial images of Apple's planned NC fuel cell, solar farms emerge
    UK ad authority moves closer to '4G' iPad investigation
    Apple unlikely to get Samsung device injunction from US court
    Two more top execs exit RIM as company weighs options
    Apple's Ivy Bridge-powered iMacs rumored to debut in June
    Google rumored to launch sub-$250 7-inch tablet in July
    AT&T will allow out-of-contract customers to unlock their iPhone
    Security issue in Facebook, Dropbox iOS apps requires physical access
    HTC profits collapse 70% in face of competition from Apple, Samsung
    Facebook expected to join Apple, Google & Microsoft on Nasdaq
    Users report 3G connection issues with Apple's new iPad
    Samsung announces estimated $40B in revenue, $5B in profit for Q1 2012
    Apple issues second OS X Java update this week
    Qualcomm, Intel provide Apple with source code in patent battle with Samsung
    Apple share price exceeds Google's as its market cap reaches $590 billion
    Intel sinks 'hundreds of millions' of dollars into Ultrabook ad campaign
    Wikipedia joins Apple in migrating from Google Maps to OpenStreetMaps
    Mac shipments slow on absence of new hardware
    Apple may get 80% tax break to build new Texas campus
    Apple may soon begin selling iPad 2 units built in Brazil
    Apple's 'iPanel' called 'far more than a TV,' expected to launch in 2012
    Biographer says Steve Jobs was legitimately infuriated by Android
    Apple exploring face detection to unlock, customize & interact with iOS devices
    Apple interested in wireless power to charge devices on store shelves
    Briefly: iPad refunds; HonHai raising wages; Nokia Lumia estimates
    'Flashback' trojan estimated to have infected 600K Macs worldwide
    Claim construction tilts toward Apple in US patent lawsuit against Samsung
    Apple reportedly 'noodling with' 7.85-inch iPad prototype
    Apple reluctant to settle e-book pricing probe as antitrust specter looms








    AppleInsider RSS Feed
    AppleInsider © 1997-2011
    Please review our Privacy Policy.
    Written/Edited/Compiled by the AppleInsider Staff.