Evil maid goes after PGP whole disk encryption
Alexander Tereshkin · 2010
Full disk encryption systems are widely used to protect the information from unauthorized access. A common application of such systems is laptop hard drive and removable media encryption, because these can be easily lost or stolen. Indeed, if we assume that an encryption system used by the FDE software is cryptographically strong, correctly implemented and properly used, and that the attacker does not possess a key for the stolen media then the data is safe. However, given physical access to the laptop (which is powered off to ensure that no keys remain in memory), an attacker can do other things besides stealing it: for example, he can modify its disk contents (e.g. an FDE loader code), leaving the laptop to the unsuspecting owner. Next time, when the password or a key will be provided by the owner, the code left by the attacker may silently record the decryption key and send it to the attacker. This type of physical attacks is called "Evil Maid" because such attacks can be easily conducted by a hotel maid when the owner leaves a laptop unattended in the room for a short period of time. This is why it is essential for a FDE system to assure the user that the system that just booted is actually the system that he or she wanted to boot (i.e. the trusted one) and not some modified system (e.g. compromised by an MBR virus). This is called trusted boot. Trusted boot can be implemented using either a Static Root of Trust or a Dynamic Root of Trust.