The cold-boot attack is able to retrive my encryption password from RAM if someone had physical access to my computer. Can't an attacker get the password for my encrypted Persistent volume out of RAM while my machine is running, over the network? Tails has a firewall, but of course so does every computer; they don't seem to stop intrusions occuring regularly.

Can't an attacker get the password for my encrypted Persistent volume out of RAM while my machine is running, over the network?

Yes it is possible and has been carried out successfully in labs.

But the real question is: if the data you are working on is ultra-sensitive, why do you stay connected to the internet? You should first make sure there is no access to the internet, work on your ultra-sensitive data, once you are finished, re-established internet access.

Comment by Anonymous Mon 31 Dec 2012 03:59:58 AM CET