Does not hibernate completely void the meaning of filevault?

Hi,
A though about encryption and mac os sleep modes. In leopard under some
circumstances (depending on settings and so on) the contents of RAM is
written to /var/vm/sleepimage (pmset -g), either to save battery power
or to prevent loss of data when battery is about to run out when already suspended/sleeping.
I was under the impression that when using encrypted swap, this hibernation image would also be encrypted with the users password, but I made some tests and this seems not to be the case. After hibernate and restart, the memory is restored and the running programs restarted, disk images mounted etc, without any need for the user to give a password (independently of auto-login). So - it seems all what is needed to read the cleartext data is saved on disk (or RAM?)
I found some info on the web about the different sleep modes, and I though that could be the problem. It turned out I had sleep mode 5, which means means cleartext sleepimage (I verified this - my mails are there...), but with mode 3 or 1, the image is encrypted but apparently the encryption key/password is also stored?
I think most users don't realize this ... what good is filevault or other encrypted images if the application data and open user sessions (with mounted filesystems) are stored to disk together with the key?
Many users may not even know about the hibernate feature and are not given an option to disable it. Afaik the image is quietly written, automatically (at least) when battery is running out.
Please tell me I got it all wrong - this seems to bad to be true. If someone has some details on what keys are used for the encrypted swap and hibernate it would be very interesting. In linux the typical solution (I always did this myself) is to have random new keys generated at each boot for the swap file, and a user prompt for decrypting the hibernation file.
cheers, Johan
somewhat related; http://db.tidbits.com/article/9115

just some details; (man pmset)
0001 (bit 0) enables hibernation; causes OS X to write memory state to hibernation image at sleep time. On
wake (without bit 1 set) OS X will resume from the hibernation image. Bit 0 set (without bit 1 set) causes
OS X to write memory state and immediately hibernate at sleep time.
0010 (bit 1), in conjunction with bit 0, causes OS X to maintain system state in memory and leave system
power on until battery level drops below a near empty threshold (This enables quicker wakeup from memory
while battery power is available). Upon nearly emptying the battery, OS X shuts off all system power and
hibernates; on wake the system will resume from hibernation image, not from memory.
hibernatemode is set to 3 (binary 0011) by default on supported portables.
Ironically, hibernate is also called 'Safe sleep'
mode 0 means off
your settings:
defaults read /Library/Preferences/SystemConfiguration/com.apple.PowerManagement
Here's the apple doc on the subject - no hint that 0 should be used to be safe.
http://images.apple.com/server/macosx/docs/LeopardSecurity_Config20080530.pdf
Message was edited by: johan.lundberg

Similar Messages

  • System does not allow to void the payment on same day

    Dear All,
    System does not allow to void the payment on same day in R12. e.g. If payment is made on 18-NOV-2010, system does not allow to void on 18th. We can void payments if void date is greater than payment date.
    Please let me know if you have any information to void payments on same day.
    Thanks in Adavnce.
    Thanks,
    Astik

    Hello Victor,
    the data collection method CCMS_OS_COLLECT is an ABAP report as you can see in the method overview in rz21. This report is used to collect the operating system data and send it to the CCMS.
    As soon as you install the sapccm4x agent on an instance the agent will take over the data collection for the operating system subtree (this is also described in [note 522453 |http://service.sap.com/sap/support/notes/522453]. Important: point 4. of the note!). I.e. as soon as the agent is responsible for the data collection you will see the mentioned CCMS_Cpu_Collect_c.
    If the MTE doesn't display data you should check if the agent is running.
    Regards, Michael

  • "Execution period does not lie completely within the shift "

    Dear Fds,
    While operation confirmation when i insert shift, i m getting the warning msg "Execution period does not lie completely within the shift " how to remove this?
    Thanks in advance
    Nishj

    Hi Nishj,
    My suggestion is in OPK4, second tab 'Individual entry general', in shift proposal select current shift, so that the system will automatically take the shift and no need of manually giving that. In this case i think you will not face the error.
    Have you have already decided to give the shift manually, please check and revert back.
    As per my knowledge in operation wise confirmation shift will not be displayed in standard SAP. Please let me know if you are using any exit.
    Regards,
    Krishna Chandra

  • Data folder can not be opened in finding " AirPort Time Capsule " The operation can not be completed because the original item for " data" does not exist .

    Hi
    I have a " AirPort Time Capsule " (firmware 7.7.3) When I try to open the data folder in "finder". Then I got the message  " The operation can not be completed because the original item for " data" does not exist". I have a lot of data and I can understand why I get this message?
    Anyone who can help? Thanks..
    Br. Bo

    Get a USB drive of 2TB or more.. assuming your TC is 2TB. Either preformatted Mac or plug into your Mac and format it standard Mac OS Extended Journaled in disk utility.
    Do a full archive of the TC. You do this using airport utility. Do not click the erase disk.. I marked in green.. just the archive.. that is to backup the internal disk to the USB disk. It is not fast.. take it that the process will go at around 40-50GB/hr.
    Once you complete the archive .. it is a direct image of the data on your TC.. you can then plug it into your computer directly.. and then try and open the files you lost.. if you cannot open them.. open disk utility and fix the permissions.
    http://osxdaily.com/2015/01/13/repair-disk-permissions-mac-os-x/
    Or try the methods apple recommends..
    OS X Yosemite: Set permissions for items on your Mac
    It is possible to fix things on the USB drive because it is locally mounted.. but you cannot fix it on TC which is network drive.

  • Project professional 2010: Physical % Complete field does not roll-up to the summary tasks

    Hi,
    I have a project plan which I need to set the physical % complete fields of it in order to use it for earned value over time report. I have assigned costed resources to come of the tasks, set all project task's earned value method to physical % complete,
    and finally set a baseline. However, the physical % complete still does not get calculated for the summary tasks! It is always zero! 
    I have created another project with only 3 tasks and 3 resources, did the same as above, and was able to get calculated values for the physical % complete.
    I followed the same procedure in both projects. In one I was able to get the physical % complete value of the summary tasks while it was always zero in the other! What may be the problem? 
    Regards,
    George 

    Hi Julie,
    This is what I am seeing as necessary to make Physical % complete roll up to the summary level task.
    BEFORE tasks are entered, set the "Default Task Earned Value method" to Physical % complete. File > Options, Advanced.  This will set both the summary and detail tasks to that method.
    Add tasks
    Add resources with costs.
    Assign resources to tasks.
    Baseline the file
    Take a look at the Tracking table and enter progress in the Physical % complete field for subtasks. The value should roll up.
    Sadly I don't know of anyway to force the change after the tasks have been added.  You can certainly add the Earned Value Method field to a task view to confirm all is set - but I have never been able to switch mid-flight and get it to work correctly.
    I did, however, just try an experiment.  I created a file that did not work correctly - Physical % complete was not rolling up.  I inserted it into a blank project that had the option set correctly without linking.  After a bit of tweaking
    (outdenting all tasks to be able to delete the "extra summary task", saving a baseline), it now appears to be working correctly.
    I hope this helps.

  • Muse Site does not display completely, amazingly, in Safari.  In Chrome, Firefox and IE, however, the site is displayed correctly ...

    Muse Site does not display completely, amazingly, in Safari.  In Chrome, Firefox and IE, however, the site is displayed correctly ...
    Kari

    Hi Aish
    The site URL is: http://hotelegerkingen.businesscatalyst.com
    The page
    http://hotelegerkingen.businesscatalyst.com/räume --- preise.html
    and
    http://hotelegerkingen.businesscatalyst.com/menus.html
    not show the whole content (only in Safari)
    Thanks for the support!
    Regards ,
    Kari
    H·B·H Communications & Events
    Karl Wälle
    [email protected]
    Breitensteinstrasse 96
    8037 Zürich
    Fon +41 44 447 40 90 (direct 99)
    Mobile +41 79 964 65 12
    Fax +41 44 447 40 89
    [email protected]
    www.hbh-com.ch<http://www.hbh-com.ch>
    Am 14.08.14 17:31 schrieb "Aishvarya Raj Rastogi" unter <[email protected]<mailto:[email protected]>>:
    Muse Site does not display completely, amazingly, in Safari.  In Chrome, Firefox and IE, however, the site is displayed correctly ...
    created by Aishvarya Raj Rastogi<https://forums.adobe.com/people/aishvarya+rastogi> in Help with using Adobe Muse CC - View the full discussion<https://forums.adobe.com/message/6640545#6640545>

  • I have down loaded a track which was initially missing 1min 30 seconds. iTunes enabled my to reload the rack which is complete on the PC. However, syncing with my Ipad2 does not seem to replace the incomplete version with the full version. Thanks S

    I have down loaded a track which was initially missing 1min 30 seconds. iTunes enabled me to reload the rack which is now complete on the PC. However, syncing with my Ipad2 does not seem to replace the incomplete version with the full version.  Can anyone out there help?
    Thanks S

    Thanks for the response. Unfortunately, I've un-checked the track and re-synced the Ipad as suggested, but then re-checking and re-syncing han no effect. The track is still missing the final minute and a half or so. I've tried it twice, but the effect is the same.
    Any other ideas? Would un-checking the entire music collection and staring again work, or is that a road to disaster?

  • The problem is that I select as a pdf document does not open completely but leaves the mail. Also I can not open more even Ibook other documents already saved

    the problem is that I select as a pdf document does not open completely but leaves the mail. Also I can not open more even Ibook other documents already saved

    http://www.microsoft.com/mac/support
    http://answers.microsoft.com/en-us/mac/forum/macword?auth=1
    http://answers.microsoft.com/en-us/mac/forum/macoffice2011-macword/microsoft-wor d-for-mac-2011-will-not-open-error/ecc42616-6f49-40bb-b8f5-e21c711ea359

  • When I send email i get the recipient was rejected by the server because it does not allow relaying whats this mean??

    When i send an email i get this response " the recipient was rejected by the server because it does not allow relaying" whats this mean and how do i fix it??

    Go into Settings>Mail, Contacts, Calendars>your account>Outgoing mail Server SMTP>Primary Server then turn Server ON and fill in both User Name + Password under Outgoing Mail Server.

  • Hi... i have iphone 5. my phone shows me the apple broken and does not work well . what this means? deppy

    hi... i have iphone 5. my phone shows me the apple broken and does not work well . what this means? deppy

    despoina kiato wrote:
    καμία φορά σταματάει να δουλεύει. σβήνει το κινητό και  μου δηχνει το μήλο σπασμένο.  απενεργοποιήτε  μόνο του . αυτό είναι όλο .
    Englidh would help.

  • Complete my album downloads the missing tracks but then does not place it with the existing tracks in iTunes. i have a single song bought sat on its own and an album with a track missing, any ideas?

    complete my album downloads the missing tracks but then does not place it with the existing tracks in iTunes. i have a single song bought sat on its own and an album with a track missing, any ideas?

    I had this same problem and started a thread, but for the most part nobody responded and those who did somehow didn't understand what the problem was.
    http://discussions.apple.com/message.jspa?messageID=11504935#11504935
    I'm sure the problem is sweat getting into the apple supplied headphone "remote." Basically even the smallest drop can slide down the wire and get into the unit.
    Unfortunately I haven't found a solution other than to get a Belkin remote adapter and some sport headphones. This doesn't give you voice over, but you can still control the volume, skip, etc.
    I've been doing this for a couple weeks now and it hasn't had a freak out since.

  • To the purchase of the complete offer "for clients CS" it does not recognize my number of series.as acount it recognizes to me but it does not make to make the purchase me. you can help me?

    to the purchase of the complete offer “for clients CS” it does not recognize my number of series.as acount it recognizes to me but it does not make to make the purchase me. you can help me?

    Hi there,
    This offer is only available to customers who own a Creative Suite edition or individual product in one of the following versions (CS3.x, CS4, or CS5.x, or CS6),  This offer is not available to Education, OEM, or volume licensing customers.
    See T&C here - http://www.adobe.com/offer-terms/cc_complete_offer.html
    ^Ani

  • Your does not appear to me the option of Upgrade existing installation

    Your does not appear to me the option of Upgrade existing installation to a clustered installation
    I am installing sap 4,7 ext: 110 in cluster formed with Windows 2003 enterprise and SQL enterprise 2000, the manual of sap says to me that it installs SQL of local way in the node a of cluster, later mind to install service pack 3 in the node a, later mind to install sap in the node a, after that requests to me that realise upgrade of SQL with the Upgrade option existing installation to a clustered installation but that option does not appear to me qualified

    Here is a short (not necessarily complete) list of Cluster Option Requirements
    - The SQL Server binaries are installed on a local non-
      shared drive (Only Node A).
    - The disc for the database files and the log file are
      belongs to the SQL Server Cluster Group (MSSQL).
    - On node B is no SQL Server with the same name (named
      instance name or default instance name ) installed.
      Check the registry on node B for the branches
      HLM\SOFTWARE\Microsoft\Microsoft SQL Server
       and
      HLM\SOFTWARE\Microsoft\MSSQLServer
      Deinstall the SQL Server on node B, if it exists and
      delete the registry branches on node B, if they still
      exists.
    - The executing user for the setup has appropriate
      rights on both nodes
      (domain administrator).
    - The SQL Server database files (master, msdb, etc.) are
      on a shared disc.
    - Node B is available via private and/or public net.
    - The Cluster service is running on node A and on node B.
    - You are using the right CD (not mat.number 51011908)
      or have set the version by means of the .reg file
      sqlverfix.reg (see node 377430).
    - All needed discs (SQL DB, SQL Log, Quorum) are on
      node A.
    Please check all the requirements and run the cluster upgrade of SQL Server again.
    Best regards
      Clas

  • Method 'publishCatalog' does not match any of the valid signatures for mess

    When I run my client, I get "Method 'publishCatalog' does not match any of the valid signatures for message-style service methods" I know that it means that my web service method should conform to one of those 4 methods (http://ws.apache.org/axis/java/user-guide.html#ServiceStylesRPCDocumentWrappedAndMessage), and I made it conform, yet I still get that error.
    Here's my Service and Client code:
    import org.w3c.dom.Element;
    import org.apache.axis.client.Service;
    import org.apache.axis.client.Call;
    import org.apache.axis.message.SOAPBodyElement;
    import org.apache.axis.utils.XMLUtils;
    import java.io.File;
    import java.io.FileInputStream;
    import java.net.URL;
    import java.util.Vector;
    public class CatalogPublisherServiceClient {
         public static void main(String[] args) throws Exception{
              String endpointURL="http://localhost:8080/axis/services/CatalogPublisherService";
              org.apache.axis.client.Service service = new Service();
              Call call = (Call)service.createCall();
              call.setTargetEndpointAddress(new URL(endpointURL));
              SOAPBodyElement[] reqSOAPBodyElements = new SOAPBodyElement[1];
              File catalogFile = new File("catalog.xml");
              FileInputStream fis = new FileInputStream(catalogFile);
              reqSOAPBodyElements[0] = new SOAPBodyElement(XMLUtils.newDocument(fis).getDocumentElement());
              SOAPBodyElement[] resSOAPBodyElements = (SOAPBodyElement[]) call.invoke(reqSOAPBodyElements);
              SOAPBodyElement resSOAPBodyElement = null;
              for(int i=0; i<resSOAPBodyElements.length; i++){
                   resSOAPBodyElement = (SOAPBodyElement)resSOAPBodyElements;
                   System.out.println(XMLUtils.ElementToString(resSOAPBodyElement.getAsDOM()));
    import javax.xml.parsers.DocumentBuilderFactory;
    import javax.xml.parsers.DocumentBuilder;
    import javax.xml.soap.MessageFactory;
    import javax.xml.soap.SOAPMessage;
    import org.w3c.dom.Document;
    import org.w3c.dom.Element;
    import org.w3c.dom.NodeList;
    import org.w3c.dom.Node;
    import org.w3c.dom.Text;
    import java.util.Vector;
    import java.util.Date;
    import java.text.SimpleDateFormat;
    import org.apache.axis.MessageContext;
    import org.apache.axis.utils.XMLUtils;
    import org.apache.axis.message.SOAPBodyElement;
    public class CatalogPublisherService {
         public SOAPBodyElement[] publishCatalog (SOAPBodyElement[] soapBodyElements) throws Exception {
              Element soapBody = (Element)soapBodyElements[0];
              NodeList productList = soapBody.getElementsByTagName ("PRODUCT");
         int productCount = productList.getLength();
         DocumentBuilderFactory factory = DocumentBuilderFactory.newInstance();
         factory.setNamespaceAware(true);
         DocumentBuilder builder = factory.newDocumentBuilder();
         Document responseDoc = builder.newDocument();
         Element resRoot = responseDoc.createElementNS("http://www.axis03.ws", "CATALOGUPDATE");
         resRoot.setPrefix("CU");
         Element itemCount = responseDoc.createElement("ITEMCOUNT");
         Text itemCountText = responseDoc.createTextNode (String.valueOf(productCount));
         Element dateReceived = responseDoc.createElement("DATERECEIVED");
         SimpleDateFormat sdf = new SimpleDateFormat("MM/dd/yyyy");
         String date = sdf.format(new Date());
         Text dateReceivedText = responseDoc.createTextNode(date);
         //Append the child elements appropriately
         resRoot.appendChild(itemCount);
         itemCount.appendChild(itemCountText);
         resRoot.appendChild(dateReceived);
         dateReceived.appendChild(dateReceivedText);
         SOAPMessage message=null;
         MessageFactory msgFactory = MessageFactory.newInstance();
         message = msgFactory.createMessage();
         SOAPBodyElement[] result = new SOAPBodyElement[1];
         result[0] = new SOAPBodyElement(resRoot);
         return(result);

    That's a really helpful answer and not smug at all, thanks Carey.
    I just downloaded a DVD image from my university's MSDN Academic Alliance program, named "Microsoft
    Windows 7 with Service Pack 1 Debug/Checked Build 64-bit (English)", which I wanted to use to install over an existing 32-bit version. I thought the install screen was giving this weird unskippable error described in the OP before I even entered
    a key because the 32-bit key I had used on the HDD was somehow interpreted to be used in an upgrade, but no. Even after I wiped the hard drive, this error persisted.
    Guess I'll go Google some more on how to install my legit copy of Windows, because this self-serving shit sure isn't helping.
    edit: IF YOU GOOGLED THIS AND ARE STILL LOOKING FOR YOUR ANSWER, CHECK HERE:
    http://answers.microsoft.com/en-us/windows/forum/windows_8-windows_install/the-product-key-entered-does-not-match-any-of-the/47e6f575-5792-404b-9b7f-2065bdb91011

  • Optical drive does not work completely.

    My optical drive stopped working today. It is not regonized by the system and does not show up in the ATA Bus in System Profiler.
    I resetted the PRAM and PMU, then checked and the drive was still not found. I then put my computer to sleep and when I woke it up, the drive was there in the ATA Bus list but information was missing. Now it is not there at all.
    There is a disc stuck in the drive. It will not eject. If I restart the computer holding the trackpad button down (to force eject the disc), the system stays on a completely gray screen and never finishes booting.
    The disc was having problems being read on another computer, which is why I put it in the drive. I'm not sure why this has happened, but if anyone has any ideas or tips that they can give me, i'd be more than willing to listen to them.
    Also, I have an eDrive that I made with TechTool Pro, and when I boot up in that the drive is not recognized either. This makes me think that there is a bad connection or a hardware problem. But how is that possible in a Powerbook?
    I do not want to call Apple because I bought my Powerbook two years ago and do not have anymore warranty time left. I can open the machine and look at the drive, but I am guessing that I will not see anything special and it will look normal. I really don't feel like buying another drive, they shouldn't break after two years.
    Maybe there is dirt in it or something?
    When I open Toast, it freezes and never opens. I have to restart my computer to get Toast to close.
    I burned a DVD last night.
    Any help would be appreciated. Thanks.

    I'm not sure if I'm threadjacking here, which probably means I am, but that is not my intent.
    I have seen scattered posts related to this problem and have this problem myself with my 2 1/2 yr old Al PB. Intermittently, the optical drive is not recognized by the system, sometimes with a disc in the drive, sometimes without. System profiler will sometimes list it on the ATA bus, sometimes not. At times it is noted by System Profiler as on the ATA bus, but if I select "disc burning", System profiler either grinds away and never finds anything or says there is no supported device. At one point it froze while playing a DVD and did not recognize the presence of a disc or the drive. A reset of one form or another always corrects the problem (often only after multiple attempts), but this happens several times a week and I shouldn't need to reset PRAM or PMU that often in my opinion. Sometimes just a restart does the trick, but it's all a bit of a pain. No other issues to speak of. Any thoughts? Thanks.
    darth

Maybe you are looking for

  • Converting logo from CMYK to PMS SPOT

    Hello everybody was wondering if you could lend a hand. I have a logo that i wish to conver to pms spot colour as that is what the artwork requirement is, it is currently in CMYK. I am currently using cs5. Edit, Edit Colours,Recolour artwork,  then i

  • Trying to burn my imovie video in a dvd but the option iDVD in the menu share does not appear why?

    need help

  • IWeb legibility problems ??

    I created a website using iWeb 08 cutting and pasting from MS Word Lucida Grande font text on a variety of pages. The pages look good when observed through Safari, Netscape, Camino, and Firefox on my computer. They look good to almost everyone else t

  • New iPad Retina display analysis at Anandtech

    A short but interesting article on the new iPad's Retina display from Anandtech: Pixel density: http://www.anandtech.com/show/5689/the-new-ipad-retina-display-analysis/1 50x magnification of pixels: http://www.anandtech.com/show/5689/the-new-ipad-ret

  • Transfering e-book to e-reader

    When I try to transfer an e-book to my kobo, a message appears saying "no permission to copy book" I have de-authorized and re-authorized my computer but still cannot transfer the book. What do I do next?