A study published by F-Secure has uncovered a new bug that makes most devices, including those equipped with disk encryption, vulnerable to an attack that could steal personal data within minutes.
As ZDNet reports , F-Secure's findings indicate that modern security measures are sufficient to prevent the theft caused by this new bug.
The attack is a variation of the old cold boot attack, which is a popular technique in the hacking world. This type of attack resets a computer and then steals the data left in RAM.
To steal data through a cold boot attack, physical access to the computer and specialized hardware would be required. Regular computers are not considered a target for such an attack compared to computers that store valuable information such as those belonging to government agencies and businesses.
One of the protection measures developed by hardware manufacturers is the replacement of the contents of RAM after a computer is attacked.
F-Secure researchers have found that they can stop the replacement process, making the computer vulnerable.
According to F-Secure security director Olle Segerdahl, who is involved in the research, “While it is not that easy, it is not difficult enough to find and exploit this flaw, so there is a possibility that some malicious users have already discovered it.”
The researchers said they have alerted major companies like Microsoft, Apple, and Intel about their latest findings. Microsoft updated its Bitlocker Guidance as an additional security measure, while Apple said that all devices using the T2 chip are not vulnerable to these attacks.
