Canned Air and FileVault

by Matt, matt@smalldog.com

The Internet is abuzz with a story about freezing RAM to “capture” its contents in order to obtain encryption keys. This technique is completely effective, and affects all computers and all operating systems—it’s an inherent limitation of RAM itself.

RAM, or random access memory, is considered “volatile” memory, because once removed from power, its data dissipates and the chip eventually becomes completely devoid of data. The data dissipates quite slowly with some memory, but very quickly in others. Non-volatile RAM is designed so that the data does not dissipate at all when removed from power.

It was discovered early this week that simply freezing volatile RAM chips using a can of compressed air turned upside down can dramatically slow, or temporarily completely stop, the dissipation of data from RAM chips. I’m not going to describe the process here, but you can find videos and articles of the process all over the internet.

The immediate implication for Mac users is that this reduces the efficacy of FileVault, Apple’s disk encryption system. Whenever data is encrypted, it is essentially locked, and can only be decrypted with a key. These encryption keys are generally long strings of letters and numbers, and are stored in RAM while the computer is powered on. When power is removed from the machine, the data dissipates slowly; when properly shut down or put to sleep, this data is erased. Freezing the RAM, removing it, and reinserting into another computer with special software, one can easily obtain the encryption key and access to encrypted files.

This is one advantage of the MacBook Air: its RAM is soldered to the main logic board and can’t be removed without damaging the memory itself.

by Matt, matt@smalldog.com

Similar Posts

  • Happy Birthday, Walden

    Walden was published 152 years ago today, on August 9, 1854. Walden is one of my favorite books. I’ve read it a few…

  • AppleCare + is an Essential Value

    You may have received an iPad, iPhone or iPod touch for the holidays. These devices all come with a 1-year warranty and 90…

  • Bocce Time!

    The bocce seasons has yet gotten underway at Small Dog this year! You may think why in the world are they playing bocce…

  • My Take on Microsoft's Zune Take 4

    Today Microsoft revealed the Zune. It is a pretty cool looking and sounding device – it will give the iPod a slight run…

  • The iPod is so wrong! It's so stupid!*

    From a comment on the MacRumors message board, the day the original 5GB iPod was released. Anticipation is building for great new Mac…

  • Protecting Your Online Reputation

    Your online reputation includes the content returned when your name or email address is queried in Google, Yahoo, or the new people-search websites…