• Passerby6497@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    edit-2
    11 hours ago

    That actually is correct, because if you power your system down ahead of time, this attack is meaningless since there is only a VERY short window where this attack works. From your link:

    Attackers execute cold boot attacks by forcefully and abruptly rebooting a target machine and then booting a pre-installed operating system from a USB flash drive, CD-ROM or over the network.

    If your attacker only has your cold machine that’s been off since well before you hit the checkpoint, they can’t do shit with that attack. At best they can boot the system up to verify your system operates as intended, but you don’t have to provide any of the credentials to finish booting or unlock the TPM to load the key material into memory.

    • chameleon@fedia.io
      link
      fedilink
      arrow-up
      4
      ·
      7 hours ago

      To add to that, even the original paper written with 1999-2007 era SDRAM/DDR/DDR2 is not optimistic about the scenario of a machine that was already powered down at regular operating temperatures:

      with the fastest exhibiting complete data loss in approximately 2.5 seconds and the slowest taking an average of 35 seconds

      And that only got worse with more advanced RAM, not to mention that they lost almost all of the data far quicker than that with only a couple % of bits surviving that long. For all practical intents and purposes, cold boot against an already-powered-down machine is a myth, the cooling has to be applied while it’s on.