On TV.com: LOST Fans are Annoying
BNET Business Network:
BNET
TechRepublic
ZDNet

September 2nd, 2008

Microsoft downplays BitLocker password leakage

Posted by Ryan Naraine @ 8:04 am

Categories: Botnets, Browsers, Complex Attacks, Data theft, Denial of Service (DoS), Exploit code, Locally Running Web Servers, Microsoft, Passwords, Patch Watch, Pen testing, Research, Vulnerability research, Windows Vista

Tags: Password, Microsoft Corp., BitLocker, BIOS, Hardware, Components, Ryan Naraine

Microsoft downplays BitLocker passwork leakageMicrosoft is downplaying the severity of a password leakage issue in BitLocker, the full disk encryption feature built into Windows Vista, insisting that a real world attack scenario is “very unlikely.”

According to an advisory from iViZ, the password checking routine of Microsoft Bitlocker fails to sanitize the BIOS keyboard buffer after reading passwords, resulting in plain text password leakage to unprivileged local users.

Technical details:

  • Bitlocker’s pre-boot authentication routines use the BIOS API to read user input via the keyboard. The BIOS internally copies the keystrokes in a RAM structure called the BIOS Keyboard buffer inside the BIOS Data Area. This buffer is not flushed after use, resulting in potential plain text password leakage once the OS is fully booted, assuming the attacker can read the password at physical memory location 0×40:0×1e.

Here’s the response from Microsoft’s Bill Sisk:

“We recognize that the claim detailed in the presentation by the researcher about BitLocker is correct…This theoretical attack is only possible in targeted situations, and while probable, [it's] very unlikely.”

“Like all full volume encryption products BitLocker has a key-in memory when the system is running in order to encrypt/decrypt data, on the fly, for the drive/s in use. If a system is in ‘Sleep mode’ it is, in effect, still running.”

The security issue is reportedly fixed in Windows Vista Service Pack 1.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 5 Talkback(s)
Ryan or Bill?
Is your comment directed at Ryan Naraine who wrote the article or to Microsoft's Bill Sisk who is quoted in the article?... (Read the rest)
Posted by: Alzie Posted on: 09/05/08 You are currently: a Guest | | Terms of Use
Semantics...  jasonp@... | 09/03/08
Ryan or Bill?  Alzie | 09/05/08
It's fixed in SP1?  wolf_z | 09/03/08
The key word is "reportedly" in this sentence.  phatkat | 09/03/08
RE: Microsoft downplays BitLocker password leakage  notsofast | 09/03/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here