I have a concern about self-encrypting drives, specifically Seagate Momentus
FDE. While the idea looks quite brilliant, my understanding is that the user is
only prompted for credentials when booting from a cold machine (one that has
been shut down completely). If that's correct, then that presents the following
vector of attack:
Bad Guy catches machine in standby (or hibernate?) mode. Bad Guy wakes machine
& then restarts it, booting to a USB stick (or CD) rather than the HDD. Since
HDD is already authenticated, Bad Guy mounts file system & reads (or writes!)
data directly off of HDD.
Can someone provide technical information that confirms or denies this
potential attack vector? I'm specifically looking at Seagate's Momentus FDE
drive w/ Wave's Embassy Suite, though other vendors would logically suffer the
same vulnerability.
Thanks.
_______________________________________________
FDE mailing list
[email protected]
http://www.xml-dev.com/mailman/listinfo/fde