<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Evil Maid</title>
	<atom:link href="http://pthree.org/2009/10/23/evil-maid/feed/" rel="self" type="application/rss+xml" />
	<link>http://pthree.org/2009/10/23/evil-maid/</link>
	<description>Linux.  GNU.  Freedom.</description>
	<lastBuildDate>Fri, 17 May 2013 20:46:35 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.6-beta2-24176</generator>
	<item>
		<title>By: Aaron Toponce : How Travelers Can Protect Their Data</title>
		<link>http://pthree.org/2009/10/23/evil-maid/#comment-110583</link>
		<dc:creator>Aaron Toponce : How Travelers Can Protect Their Data</dc:creator>
		<pubDate>Sun, 03 Jan 2010 15:56:18 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=1175#comment-110583</guid>
		<description><![CDATA[[...] CDROM, network or USB. This step is necessary to hopefully avoid the Evil Maid attack, something I&#8217;ve already blogged about here. In summary, the Evil Maid attack is booting your computer from a USB or CDROM, replacing your [...]]]></description>
		<content:encoded><![CDATA[<p>[...] CDROM, network or USB. This step is necessary to hopefully avoid the Evil Maid attack, something I&#8217;ve already blogged about here. In summary, the Evil Maid attack is booting your computer from a USB or CDROM, replacing your [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles Curley</title>
		<link>http://pthree.org/2009/10/23/evil-maid/#comment-110441</link>
		<dc:creator>Charles Curley</dc:creator>
		<pubDate>Sat, 07 Nov 2009 14:22:03 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=1175#comment-110441</guid>
		<description><![CDATA[&quot;Mossad reportedly used a Trojan to hack into a Syrian official&#039;s laptop while he stayed in a London hotel.&quot;

http://www.theregister.co.uk/2009/11/06/mossad_syria_trojan_hack/

OK, probably not everyone here is a Syrian official, but still...]]></description>
		<content:encoded><![CDATA[<p>&#8220;Mossad reportedly used a Trojan to hack into a Syrian official&#8217;s laptop while he stayed in a London hotel.&#8221;</p>
<p><a href="http://www.theregister.co.uk/2009/11/06/mossad_syria_trojan_hack/" rel="nofollow">http://www.theregister.co.uk/2009/11/06/mossad_syria_trojan_hack/</a></p>
<p>OK, probably not everyone here is a Syrian official, but still&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron</title>
		<link>http://pthree.org/2009/10/23/evil-maid/#comment-110377</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Mon, 26 Oct 2009 08:48:02 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=1175#comment-110377</guid>
		<description><![CDATA[@Kevin DuBois- Maybe, maybe not. Do you trust that assumption? :)]]></description>
		<content:encoded><![CDATA[<p>@Kevin DuBois- Maybe, maybe not. Do you trust that assumption? <img src='http://pthree.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin DuBois</title>
		<link>http://pthree.org/2009/10/23/evil-maid/#comment-110376</link>
		<dc:creator>Kevin DuBois</dc:creator>
		<pubDate>Mon, 26 Oct 2009 00:56:52 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=1175#comment-110376</guid>
		<description><![CDATA[Yeah, but if they&#039;re skilled enough to do this attack, they&#039;re probably not gonna be cleaning hotel rooms for a living... 

Right? ;-)]]></description>
		<content:encoded><![CDATA[<p>Yeah, but if they&#8217;re skilled enough to do this attack, they&#8217;re probably not gonna be cleaning hotel rooms for a living&#8230; </p>
<p>Right? <img src='http://pthree.org/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron</title>
		<link>http://pthree.org/2009/10/23/evil-maid/#comment-110372</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Sun, 25 Oct 2009 14:25:14 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=1175#comment-110372</guid>
		<description><![CDATA[@me no, it&#039;s not wrong. It will still work against Windows, and it will still work against Bitlocker. Just because you can change the &lt;b&gt;default&lt;/b&gt; settings, daesn&#039;t mean it doesn&#039;t apply to Windows any longer. I didn&#039;t say THIS WILL WORK AAGAINST EVERY KNOWN CONFIGURATION, did I. So, it&#039;s still effective against Windows, and it&#039;s still effective against Bitlocker. Sure, there are ways to mitigate this attack, such as using hard drive passwords or TPM, but the point of that statement is that this attack is platform and software independent.]]></description>
		<content:encoded><![CDATA[<p>@me no, it&#8217;s not wrong. It will still work against Windows, and it will still work against Bitlocker. Just because you can change the <b>default</b> settings, daesn&#8217;t mean it doesn&#8217;t apply to Windows any longer. I didn&#8217;t say THIS WILL WORK AAGAINST EVERY KNOWN CONFIGURATION, did I. So, it&#8217;s still effective against Windows, and it&#8217;s still effective against Bitlocker. Sure, there are ways to mitigate this attack, such as using hard drive passwords or TPM, but the point of that statement is that this attack is platform and software independent.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: me</title>
		<link>http://pthree.org/2009/10/23/evil-maid/#comment-110371</link>
		<dc:creator>me</dc:creator>
		<pubDate>Sun, 25 Oct 2009 11:17:31 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=1175#comment-110371</guid>
		<description><![CDATA[&quot;THIS WILL WORK ON ANY OPERATING SYSTEM AND IS EFFECTIVE AGAINST ANY FILESYSTEM ENCRYPTION SOFTWARE&quot;


WRONG!

Windows Vista and 7 have Bitlocker that can be configured to use TPM chip on motherboard. If you will change anything in boot loader the checksum will change and TPM will notify you about it.

Additionally some laptops like Lenovo Thinkpads use ATA password mechanism that can lock the drive, that mechanism adds complexity to this kind of attack.

TPM works only with Windows and Bitlocker.]]></description>
		<content:encoded><![CDATA[<p>&#8220;THIS WILL WORK ON ANY OPERATING SYSTEM AND IS EFFECTIVE AGAINST ANY FILESYSTEM ENCRYPTION SOFTWARE&#8221;</p>
<p>WRONG!</p>
<p>Windows Vista and 7 have Bitlocker that can be configured to use TPM chip on motherboard. If you will change anything in boot loader the checksum will change and TPM will notify you about it.</p>
<p>Additionally some laptops like Lenovo Thinkpads use ATA password mechanism that can lock the drive, that mechanism adds complexity to this kind of attack.</p>
<p>TPM works only with Windows and Bitlocker.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joseph Scott</title>
		<link>http://pthree.org/2009/10/23/evil-maid/#comment-110361</link>
		<dc:creator>Joseph Scott</dc:creator>
		<pubDate>Fri, 23 Oct 2009 17:40:06 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=1175#comment-110361</guid>
		<description><![CDATA[I agree with Daniel, once physical access has been gained then everything else is just a matter of time.  That isn&#039;t to say that throwing up a few barriers to extend the length of time required to gain control isn&#039;t worth while, they just shouldn&#039;t be viewed as anything more than that.]]></description>
		<content:encoded><![CDATA[<p>I agree with Daniel, once physical access has been gained then everything else is just a matter of time.  That isn&#8217;t to say that throwing up a few barriers to extend the length of time required to gain control isn&#8217;t worth while, they just shouldn&#8217;t be viewed as anything more than that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel T Chen</title>
		<link>http://pthree.org/2009/10/23/evil-maid/#comment-110359</link>
		<dc:creator>Daniel T Chen</dc:creator>
		<pubDate>Fri, 23 Oct 2009 14:55:21 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=1175#comment-110359</guid>
		<description><![CDATA[Right, we&#039;ve pretty much always equated physical access with game over.]]></description>
		<content:encoded><![CDATA[<p>Right, we&#8217;ve pretty much always equated physical access with game over.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jimcooncat</title>
		<link>http://pthree.org/2009/10/23/evil-maid/#comment-110358</link>
		<dc:creator>jimcooncat</dc:creator>
		<pubDate>Fri, 23 Oct 2009 14:15:34 +0000</pubDate>
		<guid isPermaLink="false">http://pthree.org/?p=1175#comment-110358</guid>
		<description><![CDATA[My advice:

Set BIOS to boot only from hard drive
Password protect BIOS setup
Take out two of the screws that hold it together and liberally apply epoxy.]]></description>
		<content:encoded><![CDATA[<p>My advice:</p>
<p>Set BIOS to boot only from hard drive<br />
Password protect BIOS setup<br />
Take out two of the screws that hold it together and liberally apply epoxy.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
