Thursday, August 16, 2012

Infiltrate the Vault

Omar Choudary (via Dave Dribin):

During the past year Joachim Metz, Felix Grobert and I have been analysing this encryption mechanism. We have identified most of the components in FileVault 2’s architecture and we have also built an open source tool that can read volumes encrypted with FileVault 2. This tool can be useful to forensic investigators (who know the encryption password or recovery token) that need to recover some files from an encrypted volume but cannot trust or load the MAC OS that was used to encrypt the data. We have also made an analysis of the security of FileVault 2.

They’ve published a paper and the code.

1 Comment RSS · Twitter

Leave a Comment