Jump to content

Major SSD hardware encryption flaws discovered

2 hours ago, Speed Weed said:

Next will be IMac because IMac uses SSD as well. 

https://www.apple.com/mac/docs/Apple_T2_Security_Chip_Overview.pdf 

 

Apple’s encryption scheme is tied down to the file system and hardware. I’m sure someone will find bugs and exploits to the T2 chip. 

 

927A42B2-03BA-4FC7-9D51-6B7FFC6A3EAE.png

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Don't use encryption on my disks but this is still bad. Don't own a confirmed impacted disk tho at least. Only have Kingston and Intel SSDs atm

I spent $2500 on building my PC and all i do with it is play no games atm & watch anime at 1080p(finally) watch YT and write essays...  nothing, it just sits there collecting dust...

Builds:

The Toaster Project! Northern Bee!

 

The original LAN PC build log! (Old, dead and replaced by The Toaster Project & 5.0)

Spoiler

"Here is some advice that might have gotten lost somewhere along the way in your life. 

 

#1. Treat others as you would like to be treated.

#2. It's best to keep your mouth shut; and appear to be stupid, rather than open it and remove all doubt.

#3. There is nothing "wrong" with being wrong. Learning from a mistake can be more valuable than not making one in the first place.

 

Follow these simple rules in life, and I promise you, things magically get easier. " - MageTank 31-10-2016

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

I wonder if the crucial MX500 is affected.

Specs: Motherboard: Asus X470-PLUS TUF gaming (Yes I know it's poor but I wasn't informed) RAM: Corsair VENGEANCE® LPX DDR4 3200Mhz CL16-18-18-36 2x8GB

            CPU: Ryzen 9 5900X          Case: Antec P8     PSU: Corsair RM850x                        Cooler: Antec K240 with two Noctura Industrial PPC 3000 PWM

            Drives: Samsung 970 EVO plus 250GB, Micron 1100 2TB, Seagate ST4000DM000/1F2168 GPU: EVGA RTX 2080 ti Black edition

Link to comment
Share on other sites

Link to post
Share on other sites

That moment when both of your main machines use affected drives :/ oh well, I wasn't using hardware encryption anyway - and after this I think I never will. Software encryption is still fail safe at least.

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

10 hours ago, captain_to_fire said:

https://www.apple.com/mac/docs/Apple_T2_Security_Chip_Overview.pdf 

 

Apple’s encryption scheme is tied down to the file system and hardware. I’m sure someone will find bugs and exploits to the T2 chip.

Probably already has. Or at least people are looking into it.

 

It's kind of funny how people go batshit crazy over published vulnerabilities while they are only the tip of the iceberg. It's kind of scary to watch something like Def Con presentations, the glimpse to the world of hacking, and there's mostly white and grey hats, black hats are the scary part because they don't talk about what they know. Something like the SSH vulnerability has been there probably for years before someone found it and published it, story doesn't tell how many has found it in the past and kept it as their own knowledge.

Link to comment
Share on other sites

Link to post
Share on other sites

14 hours ago, Ryan_Vickers said:

Is there a full list of the models affected?

Edit: found this in the source

image.png.110330268e49e5996564a326b3e1745e.png

So, 850 Pro isn't affected, but 850 Evo is? Interesting.

Link to comment
Share on other sites

Link to post
Share on other sites

i got a 840 EVO and an 850 EVO. Damn if only i was this on the bullseye while playing the loto 

.

Link to comment
Share on other sites

Link to post
Share on other sites

21 minutes ago, RejZoR said:

So, 850 Pro isn't affected, but 850 Evo is? Interesting.

It isn't known whether the 850 Pro is affected. They were essentially reverse-engineering the drives because this is all proprietary, so it's a lot of work to check each drive.

Link to comment
Share on other sites

Link to post
Share on other sites

12 hours ago, rcmaehl said:

When @Sakkura beats you by 9 minutes on posting. Feels bad man.

What would your catchy title have been? I'm always curious

 

Nevermind I found it. 

Quote

Scandalous SSDs! Your NAME BRAND Encrypted SSDs are unlockable using " "

 

"Put as much effort into your question as you'd expect someone to give in an answer"- @Princess Luna

Make sure to Quote posts or tag the person with @[username] so they know you responded to them!

 RGB Build Post 2019 --- Rainbow 🦆 2020 --- Velka 5 V2.0 Build 2021

Purple Build Post ---  Blue Build Post --- Blue Build Post 2018 --- Project ITNOS

CPU i7-4790k    Motherboard Gigabyte Z97N-WIFI    RAM G.Skill Sniper DDR3 1866mhz    GPU EVGA GTX1080Ti FTW3    Case Corsair 380T   

Storage Samsung EVO 250GB, Samsung EVO 1TB, WD Black 3TB, WD Black 5TB    PSU Corsair CX750M    Cooling Cryorig H7 with NF-A12x25

Link to comment
Share on other sites

Link to post
Share on other sites

In order to exploit this, do they need physical access to the machine?

 

Link to comment
Share on other sites

Link to post
Share on other sites

34 minutes ago, LozzyTheLemming said:

In order to exploit this, do they need physical access to the machine?

 

I would imagine so.  Not to mention that that's the only situation in which you'd encounter (be blocked by) the hardware encryption in the first place.

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

And like that I will never buy a Crucial SSD. That's inexcusable on their part,ike really?

 

Do they need physical access to the drive for this to happen? Or can it be remote?

Link to comment
Share on other sites

Link to post
Share on other sites

Guess I'm screwed if something happens then.  I'm using Bitlocker on a 960PRO and an 840EVO in my gaming rig. 

The NAS also has a bunch of encrypted 850PROs and MX200s, so I'll need to check if FreeNAS uses hardware or software encryption.  Hopefully it's the latter.  

 

EDIT: Yay, my NAS' encryption is software-based indeed.  So I only have my gaming rig to worry about. 

Time to look into my game library and decide if I'm still willing to deal with Windows and all it's BS.

Link to comment
Share on other sites

Link to post
Share on other sites

Thank god I was move to veracrypt for my storage drives a while back because I need drive to unblock-able on both window and linux OS.

Magical Pineapples


 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Link to comment
Share on other sites

Link to post
Share on other sites

Another thing plaguing the 840 EVO.

Our Grace. The Feathered One. He shows us the way. His bob is majestic and shows us the path. Follow unto his guidance and His example. He knows the one true path. Our Saviour. Our Grace. Our Father Birb has taught us with His humble heart and gentle wing the way of the bob. Let us show Him our reverence and follow in His example. The True Path of the Feathered One. ~ Dimboble-dubabob III

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×