Themes & Channels

Grab our RSS feed !

Stay informed !
Subscribe to our FREE newsletters...
 The Security Newsletter
 The Storage Newsletter

Encrypting HDD Not Safe Anymore

New vulnerability affects Microsoft, Intel, HP and others, discovered iViZ.

iViZ, an on-demand penetration testing company, announced its discovery of a new class of vulnerability at Defcon 16, the world's leading security conference. This vulnerability allows attackers to steal computer boot passwords and bypass the security of pre-boot authentication software like hard disk encryption tools. It affects general computer users, enterprises, governments and can result in unauthorized access or theft of confidential data. Incidentally, in 2007 the global loss due to data theft is estimated to be USD 40 Billion.

"Surprisingly, this vulnerability has been existing for 25 years," says Jonathan Brossard, iViZ lead security researcher and discoverer of this vulnerability. "Programmers unaware of this security hole have coded boot password feature in such a way that user entered text do not get flushed from memory properly leading to inadvertent leakage and theft. Even hard-drive encryption does not help in this case," adds Mr. Brossard. This vulnerability affects Microsoft Bitlocker on the latest TPM (but not Vista SP1), Truecrypt, Intel/HP BIOS and several others.

As a part of responsible disclosure practice, iViZ has already briefed all the affected vendors. "We appreciate vendors like Microsoft, Intel, HP taking a proactive approach in providing fixes to users. iViZ is committed to initiatives making the web safe and would continue to conduct research that helps to secure organizations worldwide," said Bikash Barai, CEO of iViZ.


Vulnerability details

News Options >

AddThis Social Bookmark Button

print this news Print this news

Check-out our sister site !
StorageNewsletter, the Daily Breaking News for the Worldwide IT Storage Industry

Into IAM ?

iam_small

The IAM 2008 Series

SecurityNewsletter interviews major Identity & Access Management players to give you the lead on what IAM will be in 2008.

Don't Miss Out !