Saw this on the ISC today. A team of researchers at Princeton has discovered that the secret keys used to encrypt and decrypt data by most whole-disk encryption products stores the key in the system's memory (no surprise there) and that those bits of memory hold their data for up to a few minutes after the PC is turned off (BIG surprise). I haven't read the whole paper yet, but the abstract seems to imply that they were able to recover secret data from disks encrypted with a host of popular products including Vista's BitLocker and TrueCrypt.
Links:
ISC Diary
Paper
Project home page
Links:
ISC Diary
Paper
Project home page