Quote from: MrVidalia on May 25, 2012, 07:42 amI thought with FDE hibernate was secure? So that's certainly not the case?My understanding is that if you set Truecrypt to dismount encrypted volumes e.g USB sticks, TC containers then the data contained is safe but in the nature of things if the computers suspended state is kept in RAM and your hard drive is encrypted ipso facto the encryption key is also stored in RAM and can be recovered.The method used involves restarting the machine and booting to a malicious OS (on a USB drive or other removable media) which has been programmed to pull the entire contents of your RAM - the data degrades quickly once your computer has been shut down but while it's on... :)V.