Hacker News new | past | comments | ask | show | jobs | submit login
Possible vulnerability in TrueCrypt 5.1 (heise-online.co.uk)
1 point by gongfudoi on March 14, 2008 | hide | past | favorite | 1 comment



This vulnerability exists in all programs that save their passwords in memory and on all OSs, the system doesn't even have to hibernate for the vulnerability to happen, it's enough that the password gets transfered to cache.

If you want to expose the password, just ignore the program, consume a ton of memory from the machine and the password will be written into the cache as the machine scrambles to shift less frequently used memory to the cache.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: