Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upWipe RAM on Shutdown #1562
Comments
adrelanos
changed the title from
Wipe all RAM on Shutdown
to
Wipe RAM on Shutdown
Dec 29, 2015
marmarek
added
enhancement
help wanted
C: kernel
C: xen
P: major
release-notes
labels
Jan 6, 2016
marmarek
added this to the Far in the future milestone
Jan 6, 2016
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
tasket
Feb 28, 2016
Good feature, but a little reminder: Some memory controllers scramble addresses and data using prng pattern, such as on Intel Core processors using ddr3. So far haven't seen anyone defeat this, so maybe some users will feel less vulnerable. See pp. 26-29 http://www.slideshare.net/codeblue_jp/igor-skochinsky-enpub
tasket
commented
Feb 28, 2016
|
Good feature, but a little reminder: Some memory controllers scramble addresses and data using prng pattern, such as on Intel Core processors using ddr3. So far haven't seen anyone defeat this, so maybe some users will feel less vulnerable. See pp. 26-29 http://www.slideshare.net/codeblue_jp/igor-skochinsky-enpub |
added a commit
that referenced
this issue
May 31, 2016
added a commit
that referenced
this issue
Jun 7, 2016
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
awokd
Dec 18, 2017
Looks like the kernel is compiled with CONFIG_XEN_SCRUB_PAGES=y. That should result in DomUs getting wiped on memory free operations, including a shutdown. Was this issue filed against the host itself? #2024 refers mostly to VMs.
awokd
commented
Dec 18, 2017
|
Looks like the kernel is compiled with CONFIG_XEN_SCRUB_PAGES=y. That should result in DomUs getting wiped on memory free operations, including a shutdown. Was this issue filed against the host itself? #2024 refers mostly to VMs. |
adrelanos commentedDec 29, 2015
Some stuff that Tails is having in mind.
package:
http://git.tails.boum.org/wiperam/tree/
Tails currently has a few issues with it.
https://tails.boum.org/support/known_issues/index.en.html#index23h2
The other issue is an obvious one. If shutdown fails for software or hardware reasons, RAM shutdown won't be executed.
https://labs.riseup.net/code/issues/6006
And more.
Tails blueprint:
https://tails.boum.org/blueprint/more_efficient_memory_wipe/
Documentation on testing if wiping RAM works:
https://tails.boum.org/contribute/release_process/test/erase_memory_on_shutdown/
Test suite recipe:
https://github.com/vjrj/tails/blob/master/features/erase_memory.feature
Documentation:
https://tails.boum.org/doc/advanced_topics/cold_boot_attacks/index.en.html
Related: