<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0">
  <channel>
    <title>2012 Reports</title>
    <link>http://eprint.iacr.org/forum/list.php?12</link>
    <description><![CDATA[Discussion forum for Cryptology ePrint Archive reports posted in 2012. Please put the report number in the subject.]]></description>
    <language>EN</language>
    <pubDate>Thu, 19 Jul 2012 01:52:43 -0600</pubDate>
    <lastBuildDate>Thu, 19 Jul 2012 01:52:43 -0600</lastBuildDate>
    <category>2012 Reports</category>
    <generator>Phorum 5.1.22</generator>
    <ttl>600</ttl>
    <item>
      <title>2012/374 encryption of hibernatefile (sleepimage) with and without Core Storage in OS X</title>
      <link>http://eprint.iacr.org/forum/read.php?12,677,677#msg-677</link>
      <author>grahamperrin</author>
      <description><![CDATA[Encryption of hibernatefile with Core Storage
=============================================

&gt; 4.2 Plaintext bits in encrypted volume

CVE-2011-3212
 
is mentioned in the following Apple articles: 

HT5002
http://support.apple.com/kb/HT5002

HT5281
http://support.apple.com/kb/HT5281

Encryption of hibernatefile without Core Storage
================================================

From Apple's current manual page for pmset(8): 

&gt;&gt; hibernatefile - change hibernation image file location. 
&gt;&gt; Image may only be located on the root volume. 
&gt;&gt; Please use caution. (value = path)

https://developer.apple.com/library/mac/#documentation/Darwin/Reference/ManPages/man1/pmset.1.html

Preliminary test results show that whilst the man page directs the user to locate the image file on the root volume, it is possible to both: 

a) locate the file elsewhere (say, a JHFS+ Apple_HFS slice alongside the Apple_CoreStorage slice that is used to encrypt OS X); and

b) successfully wake from hibernation. 

A question arises: 

* whether encryption applies to a hibernatefile that is not on the root volume.]]></description>
      <category>2012 Reports</category>
      <guid isPermaLink="true">http://eprint.iacr.org/forum/read.php?12,677,677#msg-677</guid>
      <pubDate>Thu, 19 Jul 2012 01:52:43 -0600</pubDate>
    </item>
  </channel>
</rss>
