View Single Post
  #4 (permalink)  
Old 02-26-2008, 08:36 PM
shimp
Guest
 
Posts: n/a
Default Re: Should Linux wipe memory more often for better security?

It has been known from the beginning that DRAM holds its state a while
after power is removed. Thats how it works. There is a circuit that
refreshes it every X milliseconds. But it is a big big surprise, at
least to me, that data can recovered up to 10 minutes afterwards!!?

The only real world ramification I can see is that you should completely
powerdown your laptop 10 mins before going through a security
checkpoint. Or unmount crypt stuff and do a memory wipe.

As far as servers sitting alone somewhere, or other scenarios.. if
someone has physical access to a machine there are all kinds of tricks
they can use. I think you need to implement intrusion detection as
another poster said, and rigged to explosives for self destruct. ;)

Reply With Quote