‘eyeDisk’ USB drive secured with iris recognition reveals password in plain text
pentestpartners.com
pentestpartners.com
USB drive doesn't have enough processing power so the software running at host implement the iris pattern recognition and authentication.
The problem is, the USB drive store the password and iris pattern value by plaintext and it's readable without unlocking.
Totally useless.
In this case there was no Secure Enclave at all. If you do have a enclave you trust to keep a private key safe, my preference would always be to use a simple (not trivial) password/passcode and depend on strict rate limiting.
The only way to avoid a private key being stored in an enclave is to derive the key from a strong password. This avoids the whole class of key extraction attacks but, now there is a password that can be attacked offline.
If you combine a decent password with an online hardening / rate limiting system then I think you have something which stands a chance. But I’m building a commercial product in exactly this space, so I’m not entirely unbiased.
http://spritesmods.com/?art=diskgenie
http://spritesmods.com/?art=biostick
http://spritesmods.com/?art=securehd
http://spritesmods.com/?art=secustick
There's some patterns with 'secure USB storage', notably that none of them are anything besides a toy.
shots fired
Thankfully, unlike x86, ARM’s 64-bit ISA ditched the dumb parts and is very clean.
Still, the corolary of "the unsafest projects will be the ones with the most amount of overblown claims" seem to stand.