Update Apr 8th, 2008: Please see warning against Keepit.com elsewhere in my blog A company www.Keepit.com offers 2GB of free online backup-space (at least in Denmark) which may be quite nice for many users, may be enough to store your pictures and mail. The client software is not the worlds most advanced I have been told, but again for home users it may be quite sufficient. https://www.keepit.com/dansk/Home Pay and get more :-), should you be willing to pay DKK 29 ($4.5 or €3.9) you get unlimited storage space. Seem like a quite reasonable solution. I have not tried this yet so I am uncertain about security and encryption etc, but I have been told that it indeed uses encryption and your data should thus be safe from prying eyes. keepit.png

First you get the happy news, Truecrypt will now offer system drive encryption, and you go to bed with a big grin on your face..

Sorry for being the carrier of bad news, but you might as well wipe that grin of your face and start rethinking your security plans.. Sure, we are not talking revelation of a super master key for all encryption, but still the guys at Princeton University did a good enough job of making smiles fade..

The idea is; RAM is not erased the second the computer is turned off, it will take anywhere from seconds to minutes before RAM is reset to “0”, and as the encryption key is found in ram (For most software, including Bitlocker and Truecrypt) what these people do is to boot a usb device and dump the entire ram content before it fades… They even slow down the process via an air cooling spray adding almost unlimited time to do their ‘evil’ deed.

Revealing the keys and compromising data will in most cases (not all it would seem) require a rapid response from the potential hacker, the technique require physical access to the computer within minutes after it is turned off (not true for hibernation or sleep mode mind you). However Bitlocker even in some configurations seemed ‘hackable’ even if turned completely off (cold).

Sounds like science fiction, well the you tube video they produced seem somewhat convincing.

Steps you can do to to counteract this;
DONT use hibernation or SLEEP mode.
If possible use the “enter a password” at bootup.
In bios disallow booting from USB.

These steps will not make you 100%  secure, but will make things way more difficult.

For more details;
http://citp.princeton.edu/memory/

Customs
Be careful what you have on your laptop when entering the USA, the security checks are no longer limited to your physical goods, according to the Danish online magazine ComOn.DK quite a lot of people have had to hand over their passwords to their laptops, in order for the Security personnel at the US airports to search their computers.

Disturbing is the only word I can think of.