The newly announced ElcomSoft Forensic Disk Decryptor can decrypt BitLocker, PGP, and TrueCrypt. And it's only $300. How does it work?. Elcomsoft Forensic Disk Decryptor acquires the necessary decryption keys by analyzing memory dumps and/or hibernation files obtained from the target PC. You'll thus need to get a memory dump from a running PC (locked or unlocked) with encrypted volumes mounted, via a standard forensic product or via a FireWire attack. Alternatively, decryption keys can also be derived from hibernation files if a target PC is turned off. The link for this article located at Schneier on Security is no longer available. . CleverSys' latest utility extracts decryption codes from RAM captures and sleep state archives for fortified access management.. Forensic Disk Decryptor, Disk Encryption, Access Control. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.