Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Mostly academia and nation states. Physical access will always be king and this provides one more avenue for adversaries to bypass encryption more easily.


> Physical access will always be king

No. Your wording suggests that once attackers gain physical access, all is lost. It is not true. With a passphrase based full disk encryption, if the passphrase is strong and the machine is powered off, physical access doesn't imply data access.


You still have to defend against cold boot attacks or very sophisticated hardware implants:

https://www.bloomberg.com/news/features/2018-10-04/the-big-h...


Attach a microphone to the device while they are not looking, decode the keys they are pressing from the sounds, figure out what keys are the password, done.

This is _trivial_ for any mildly sophisticated attacker.


You don't even need to attach it, other placements are sufficient as well. An example of how an attack can be performed: <https://github.com/shoyo/acoustic-keylogger>

Room bugged = keyboard keylogged




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: