[Discuss] Cold Boot Attacks on Encryption Keys

Richard Pieri richard.pieri at gmail.com
Sun Nov 10 10:59:30 EST 2013


Edward Ned Harvey (blu) wrote:
> The most obvious solution to me, is to have an authentication server
> (AD/Ldap/Kerberos) which boots using TPM.

But TPM is potentially vulnerable to cold boot attacks, and pre-boot PIN 
systems are vulnerable to bootkit attacks. The only reliable defense 
against these is to maintain good physical security.

-- 
Rich P.



More information about the Discuss mailing list