FileVault 2 insecure during sleep state on 2011 Air

This security vulnerability in FileVault 2 on Lion that arose back in July 2011
http://www.frameloss.org/2011/09/18/firewire-attacks-against-mac-os-lion-filevau lt-2-encryption/
http://img.frameloss.org/wp-content/uploads/2011/09/Lion-Memory-Acquisition.pdf
was something that was easy to fix on the older Macbook Air simply by changing a couple of settings.  Specifically this setting:
sudo pmset -a destroyfvkeyonstandby 1 hibernatemode 25
but on the new 2011 Macbook Air that setting causes a freeze up upon closing the clam shell.  In fact any hibernation on the 2011 Macbook Air seems to lead to an unstable state that often fails in this same freeze up.  The general 2011 macbook air hibernation freezeup phenomena is documented yet unresolved in different thread:
https://discussions.apple.com/message/16786155#16786155
Since you can't hibernate on the 2011 Macbook Air you can't achieve a secure FileVault 2 hibernate/sleep state where the key is stored only on disk and not in RAM.  This means on the 2011 macbook air if an attacker gains access to your Air in sleep state he can retreive your crypto key and unlock your whole drive using tools that have been published since July and are linked above.  You're only secure if the machine was powered all the way off.
As far as I can tell this is a major unaddressed security vulnerability which almost defeats the purpose of using FileVault 2 in the first place.  I hope this problem is not being ignored because of pressure from law enforcement or something silly like that.  It's one thing to make your system insecure by default.. but to make it incapable of being secured while at the same time branding it as a security product is just plain false advertising.
here is how to fix it:
If FV2 encryption is turned on then the Air should no longer support sleep it should hibernate instead, remove the FileVault key from RAM, power off the RAM.  In other words this command which you already have built into the OS should be made to function the same way it does on the older air and should be default for all FV2 users:
pmset -a destroyfvkeyonstandby 1 hibernatemode 25
Sure it'll slow down wakeup but the SSD helps make that less noticeable and that's what it takes in order to do full disk crypto.  You'll still have the fastest secure full-disk crypto laptop if you fix this.   As I said earlier this command can be issued on the older Macbook Air and it will lead to a secure system.  It needs to be fixed for the new macbook air before filevault can be secure during sleep or hibernation.
I'd love to hear tha tthis is being addressed. 

Why do you think that this method is safer compared to
pmset -a hibernatemode 0
This way, all the content is stored in Ram, nothing gets written to the disk, so the key never leaves the Ram.
Newer research indicates, that you can no longer (since 10.7.2) read the content of the Ram via Firewire unless a user is logged in and the screen is unlocked:
http://ilostmynotes.blogspot.com/2012/01/firewire-and-dma-attacks-on-os-x.html
The advantage of this method would be, that the wake up is faster and a shorter password for login can be used for quick unlock. (A password of a user who is not allowed to decrypt the disk because his password is too weak to withstand automated brute force attacks, but is strong enough against a human in front of the keyboard)

Similar Messages

  • Charging iPod nano on an Intel iMac during Sleep Mode by Firewire

    Hi everybody,
    I have a question concerning the iPod nano. I know that you can not sync the iPod by Firewire but you can charge it. I also know that charging the nano via USB during Sleep mode is NOT possible. However I had a 3G IPod (connected by Firewire) and it was possible to charge it when the Imac was in Sleep mode. And here comes my question:
    There is a special cable for iPods, which has both Firewire AND USB. Is it possible to connect the IPod simultaneously by Firewire and USB to the Imac with the result, that the nano will charge during sleep mode (Firewire) AND is able the sync music (USB) ???
    Thank you

    Hi lora,
    Don't do it! See this post:
    Using the iPod Dock Connector to FireWire and USB 2.0 Cable
    Which states this: "Important: Never connect both the FireWire and the USB 2.0 connector to your computer at the same time. Doing so can cause unexpected behavior."
    Good luck,
    maz

  • High-pitched beep/sound during sleep and shut down modes

    I just wish to check whether is it normal that there's high pitched beep (not very loud but can be heard in a quiet room) which seems to be from the LED or AC Adapter during sleep mode. The beep sounds continuous when the computer has been shut down or in off mode while the main plug of where the ac adapter is connected to is still on. Is this normal? My computer works fine. Battery is charging fine. I just want check whether is this normal. It is has been like that ever since I bought my computer on March 2012.
    HP Pavilion dm4-3005tx Entertainment Notebook PC

    Hello Huanwei,
    It appears that you can hear a "high pitched beep" coming from the notebook while it's in sleep mode or even off, when the power adapter is plugged in and "on". I will try to help you with this.
    Normally, this should not happen. Beeping from a computer may happen during start up a few times to indicate components enabling, but any constant beeping or being while the computer is off shouldn't happen.
    Does this occur, if the AC adapter is not connected to the notebook when it is in sleep mode or off? Do you only notices this, in a specific location? (office, etc.)
    I would suggest, depending on the setup of things. Taking the notebook with no AC to another location in the house. A quiet one, make sure your not near any other electronics (no watches or cell phones either) let the notebook sleep and see if you hear the beeping. If not, then power it off and test again. If no beeping, this is good and the notebook is fine.
    Repeat that same test with the power adapter connected ( again no other electronics around you). Listen while it is "sleeping" and off to see if you can hear the beeping again.
    If you do disconnect the AC from the notebook , but leave that connected to the wall and take the notebook out of that location, go back to see if you can hear beeps again. If you do it could be the AC adapter. If you don't then it could be an issue with that only when it's connected.
    If there was no beeping when the AC was connected in this "testing location", then I would guess it is something else within the house that is beeping (we have seen that before). In which case you'd have nothing to worry about in regard to your notebook.
    Let me know where the above leads.
    Thank you for posting on the HP Forums.
    I worked on behalf of HP.

  • White 24" iMac lockup during sleep mode

    I have recently been having problems with my iMac it won't wake from sleep and has to be unplugged and restarted or every time it goes to sleep it locks up. The light on the front is on but not flashing as it normally does during sleep. I run Onyx frequently and it does not seem to help for long(Maybe 2 days max) I am at the point where I am only using XP in Bootcamp because it seems to run much better than OS X.
    Here are my specs:
    24" iMac 250 GB internal drive, 500 GB firewire 800, 2 GB Ram.
    USB devices: Wacom Intuos 3 tablet, logitech NuLOOQ, HP Deskjet 5940, VXI USB Translator(USB Audio device for speech recognition) Sentinel Safenet Dongle for Lightwave 3d.
    Bluetooth devices:Mighty Mouse and Keyboard, Motorola HT820 headset for Telephony
    I have disconnected everything I can and it still seems to lock up under OS X So it looks like I'm stuck with XP until I can resolve this. >:(....

    First - you aren't disconnecting any device while your computer is asleep are you? This can cause your problem.
    Assuming this isn't the cause, let's do an SMC reset. Shut down the computer. Unplug all cables from the computer, including the power cord and any display cables. Wait at least 15 seconds. Plug the power cord back in, making sure the power button is not being pressed at the time. Then reconnect your keyboard and mouse to the computer. Press the power button on the back to start up your computer. Does it now sleep and awake?
    If not srojtas is right that one of your peripherals may be the culprit but rather than disconnecting one at a time I recommend that you disconnect everything but your ethernet cable (assuming you have one) and your USB mouse and keyboard. Create a new account and set the computer so that you have to choose which account to log into.
    Restart and log in directly into the new account. If it sleeps and wakes up now you know that the issue is your account or one of your devices. One at a time, connect (and install support software for) a device. Does the computer wake and sleep? Move on to the next. You may find the culprit along the way. Removing it may or may not let the computer sleep depending on whether it is the device itself or the software.
    BTW - the device at fault could be a USB or FireWire hub.

  • 24" iMac has buzzing sound every 5 min during sleep after upgrading to is x lion

    I have a 24" iMac purchased new in 2009.  Haven't had a problem and usually put it to sleep mode at night with no problem.  I recently upgraded to OS X Lion and started noticing 2 problems during sleep mode.  One is a constant humming noise that wasn't there before, as if the computer is still running.  Second problem is that every 5 to 10 min or so, a slight buzzing sound pops up.
    The noise poses as a real problem during the night as I have the iMac in my bedroom.  I'm forced to completely shut down very evening to avoid the noise.  Can anyone help?  Thank you in advance.

    I have a similar problem on my early 2008 macbook pro. After the audio driver is idle for a minute or so (after an itunes playlist or youtube video ends) the headphone jack output starts buzzing horribly, to the point where i have to turn off my soundsystem or play a muted song to “wake up“ the card and stop the buzzing. This must be due to different power management parameters in Lion, as it started immediately after the upgrade and disappeared after I reformatted and returned to Snow Leopard. Maybe there is a way to force the audio hardware to stay active?

  • Battery Drain During Sleep

    100% battery life when I unplugged my laptop and brought it to work this morning. 5 hours later I pull it out of my backpack and I have 88% battery life. Why?? Reading on here about hard drives not sleeping. Is that the problem?
    I've never been thrilled with the battery life (it's a 10/2008 MBP 15") Two weekends ago I didn't use it at all or plug it in. When I opened it, it had put itself in that save/sleep state where it had to "restore" where i last was. In the grayed out screen I could see 78% battery which would have been what it was the last time I had it open. So really? not even opening it for two or three days and it will use up 78% of the battery??
    Right now? 78% battery says I'll get 1:55 minutes. sighh

    look - I've owned 5 mac laptops from a 540c to my current 2.83Ghz Uni MBP.
    NONE of them had this issue - EXCEPT this one.
    I could put any of my other machines to sleep with 90% battery and wake them up 2 days later and find them with 86%... this one - if I leave it sleeping overnight with no plug attached, it is DEAD in the morning.
    is this going to be just another one of those problems which Apple pretends doesn't exist?
    I already had the hinges on my TiBook fall apart and the ATI card on my last MBP (2.16 17") go completely dead... now this - admittedly less serious but still very annoying issue.
    I'm waiting for a solution Apple...
    but I'm not holding my breath.
    -bennett

  • Why doesn't Mail apply rules during sleep?

    I often wake up the MBP in the morning to find that Apple Mail has not applied any rules to incoming mail. I can fix it easily by selecting all the new mail and applying rules. In normal, waking operation it applies rules automatically. But past versions of Mail always applied rules during sleep, too. Why now? Is there some way to make it apply rules?

    Exact same problem, only since switch from SL to ML. Have to tell the machine to never sleep???

  • Scheduled system wakeup from a Sleep state while lid closed

    I'm wanting to backup my Ti Power Book data using the .Mac Backup 3 (BU3) application at 2am each day.
    On my desktop system which is a Power Mac G5 I perform a BU3 every day at around 2am. The Energy Saver is configured to wake my Power Mac from a sleep state at 2am and not go back to sleep until some 1 hr of inactivity. Shortly after 2am I have various scheduled BU3 Plans that execute. This is working flawlessly for me.
    I now want to do the same thing for my Power Book - but with its lid/screen closed. I've tried the same setup as for my Power Mac and the Power Book will wakeup at 2am but very quickly returns to sleep mode because its lid is closed which stops the BU3 from executing. I do not want to leave the Power Book's lid open at night time.
    Is there a way to meet my requirements ?

    Hi, Barry. No, there isn't — unless you connect an external monitor, keyboard and display to the Powerbook as described in this article.

  • Optical drive being accessed during sleep

    I close the lid, put it to sleep and my optical drive keeps being accessed. Its erratic; 1,2 or 3 times a minute - sometimes it doesn't start for 35 minutes, sometimes it stops after a while. No outside devices attached. Its annoying to say the least.
    Anyone else have this problem? I talked to technical at applecare several times and they had no record of anyone else having this issue.

    I've made some progress. I figured that was happening (and shouldn't be happening) was that something was momentarily waking the computer which does a optical disk access when it wakes.
    I disabled wifi and that didn’t do it and then I disabled Bluetooth – I use a Logitech Bluetooth mouse – and that stopped the problem.
    Further details if anyone is interested: when I close the computer case and put my mouse on top of the macbook there is no problem. No optical drive accesses. When I put the mouse on my wooden desktop the problem starts. I turned the mouse upside down (case closed – sleep state) and after a while a little red led started blinking in a small window. When I put my finger over the window the optical drive was accessed. The mouse is sending something to the computer and it wakes. It shouldn’t wake but it does.
    macbook pro Mac OS X (10.4.7)

  • Resume from sleep speed - 2011 Air

    2011 Mac Air Core i7 - 256 gig HDD - LION
    When i close lid for air to sleep, then i re-open it takes about 3-4 seconds.
    At first I see a black screen and my cursor, a about 3 seconds then the desktop.
    What is your speed - I have a friend with a 2010 Mac Air and it resumes instantly!!
    PS My startup disk wasnt selected, i did this and it made no difference.
    Is my Air a Dudd ?

    Good find! I think you're absolutely right.
    I just opened my Air after not using it for a couple of days and noticed the slow wake from sleep often and thought by myself "I thought this thing is supposed to wake quickly because of the SSD?".
    I use my 2011 Air mostly as a 2nd machine and so it's often been sleeping for a couple of hours.
    The difference between waking the Air a couple of minutes after sleeping it and when it's been lying around for a couple of hours are night-and-day and the support article explains why this is the case.

  • MB Battery drain during sleep

    I have a MacBook IntelDuo (not 2) that I just purchased in October.
    I noticed that the battery still drains during sleep. If I put the computer to sleep for 4 hours, it drops by about 15% - 20%.
    I had a iBook (white g3 500mhz) and I could put it to sleep for days without the battery barely draining at all.... espeically in OS9 (over a week unplugged and asleep and had 25% battery left). Once I switched to OSX the battery drained a bit faster.
    Drain is expected, but this seems like a much bigger drain than older systems. What could still be running when it's asleep?

    When you put it to sleep, do you notice a steady white light? If so, then only your display is sleeping.
    You can change sleep settings in System Preferences > Energy Saver.
    Your battery will drain if only your display is sleeping. Your computer is still on if you see the light.

  • Battery drains during sleep!

    My almost 2 year old battery for my 15" PB G4 keeps losing its' charge when sleeping. After fully charging, I put it to sleep by closing the lid (and confirming the flashing LED).
    A few hours later when on the train, it won't wake up, until I get home and plug it in, only to realize that the battery had drained.
    Here's my coconut:
    Current battery charge 1168
    Max battery charge 3089
    Current battery cap 3089 (70%)
    Original battery cap 4400
    cycles 191
    age 22 mo
    Any suggestions? Do I need a new battery?
    Thanks.
    PB 1.67 15 Superdrive   Mac OS X (10.4.6)  

    I realize this is an older thread, but I was searching around the forum on this topic because I've been finding that one of my PowerBook batteries has been draining quickly during sleep (on planes, not trains!). I thought you might find my situation similar and informative.
    On a more recent thread, I found a couple of suggestions that have led me to believe that my "problem battery" is just plain old. I've looked at the battery info in the System Profiler (under Hardware > Power), and confirmed that fully charged, my battery's capacity is a meager 877 mAh (19% of the original 4400) and it's been through 169 cycles. It's a battery I bought with the PowerBook, so it's over two years old.
    Considering the massive drop in capacity, I think it's time for a new battery...

  • Battery Drainage During Sleep

    I saw a few posts on this issue but haven't seen anything in a while. My battery drains too quickly during sleep mode. Has apple addressed this yet. If not has anyone found a fix for it. It's really the only thing that has bugged me about this new laptop.
    Any help would be appreciated.
    Cheers

    No official fix for now.
    You have to manage the sleep yourself! If it's a short sleep, just close the lid as usual and forget your 2% comsumption. If it's a long sleep (a hibernation), use something like deepsleep (http://deepsleep.free.fr/) and be patient during the wake up.
    Yet a little effort and apple will be as worst as linux to manage power...

  • Battery drained during sleep

    My new 13'' MBA seems to use quite some battery power during sleep -much more than I experienced with my 15''MBP.
    I am used to never shutting down my Macbooks, but simply close the lid to put it to sleep. Usually, I find the battery to be less than I left, but today I found the battery to be fully drained.
    Am I missing something with the power settings? Doesn't the 30 day stand by time refer to "shutting down the lid" and preserving battery life for days?

    Hi
    Have you applied the Firmware update? If so, try resetting the PRAM.
    http://support.apple.com/kb/ht1379
    Adam

  • Mac Mini Intel Snow leopard often dies during sleep. What to do next?

    During sleep the screen goes blank on a light grey color and I can only shut down using the power button. I am using an apple blue tooth keyboard and a logitech USB remote mouse. I have run Disk Repair w Utilities and also the MUG has tried Disk Warrior but problem persists. The Mac Mini is about 3 years old. It occasionally also crashes in Safari or Word. Please advise. Am worried about losing files, but so far so good.

    I assume you have a current backup, so I would start by erasing the drive and reinstalling OS X.
    Drive Preparation
    1.  Boot from your OS X Installer Disc. After the installer loads select your language and click on the Continue button.  When the menu bar appears select Disk Utility from the Utilities menu.
    2. After DU loads select your hard drive (this is the entry with the mfgr.'s ID and size) from the left side list. Note the SMART status of the drive in DU's status area.  If it does not say "Verified" then the drive is failing or has failed and will need replacing.  SMART info will not be reported  on external drives. Otherwise, click on the Partition tab in the DU main window.
    3. Under the Volume Scheme heading set the number of partitions from the drop down menu to one. Set the format type to Mac OS Extended (Journaled.) Click on the Options button, set the partition scheme to GUID (for Intel Macs) or APM (for PPC Macs) then click on the OK button. Click on the Partition button and wait until the process has completed.
    4. Select the volume you just created (this is the sub-entry under the drive entry) from the left side list. Click on the Erase tab in the DU main window.
    5. Set the format type to Mac OS Extended (Journaled.) Click on the Options button, check the button for Zero Data and click on OK to return to the Erase window.
    6. Click on the Erase button. The format process can take up to several hours depending upon the drive size.
    Upon completion quit DU and return to the installer. Install OS X. When completed you can restore your data from the backup.

Maybe you are looking for

  • How Do I Get my music on more than one computer

    my whole family of 4 has ipods my brother got the first ipod and we have dial up so went to my grandparents house to get his first songs and to make is account and its under a family members email but the songs are on my gmas labtop and my gpaws comp

  • How to add an attachment to a google calendar event when uisng safari

    how to add an attachment to a google calendar event when uisng safari?

  • What Soundcard do I have?

    Hello all, I own a 15 inch 2.66 Ghz i7 Macbook Pro. I am interested in getting involved with audio production with this computer and was wondering what soundcard the Macbook Pro is currently equipped with and whether or not I should consider upgradin

  • Intel graphic and gnome crash

    Hi. My father has laptop with intel graphic. Today I update system for him and system is crashing...I tried start gdm from console and startx and is the same... showing "something is wrong" and logout to console... any ideas what can be wrong ? What

  • Merging folders in Mac OS X: A solution...

    This is not a question, but a solution I discovered. For unknown reasons, Apple has never adopted one of the basic features in Windows; to allow two folders to merge without deleting any content. Mac geeks may use the terminal, but if you're not a sa