Analyzing and breaking an externally encrypted HDD
syscall.eu
syscall.eu
And if the pin implementation is this hackneyed, I have a feeling that the so-called encryption is anything but.
This is a warning to people with access to highly sensitive data. But for everyday stuff, you do need to keep the value of your data in perspective.
It took a security researcher 40 hours to crack this thing. Should you store state secrets on this? No, it can be cracked by a determined adversary. Would I feel safe storing my personal financial data on a device like this one? Meh, sure, good enough.
Maybe I might understand if this was some kind of server SSD but even then im not sure it would make sense.
In fact Microsoft's own BitLocker dropped reliance on hardware encryption to workaround this same problem. And now that the performance impact is minimal it makes sense to default to software.
I'm not even convinced these companies can implement the core functions of their firmware properly. Why would anyone trust their proprietary cryptography solution? It's just insane.
Totally. I'd be super curious to know is anyone's just tried plugging the hard drive into another controller. Won't surprise me at all if the "security" here is just not starting the USD drive controller without the correct pin being entered. There isn't any evidence here for enough hardware to turn that pin into an encryption key and encrypt/decrypt data on the fly. (I guess it's possible that's all built into the USB controller?)
Currently, there is some person with $260M in Bitcoin on an encrypted drive.
https://www.techradar.com/news/ironkey-maker-couldnt-unlock-...
I am sure they would be willing to split it.