Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Help Net Security

Nobody was checking the drives that encrypt your laptop

A hardware-based vulnerability was discovered in multiple TCG Opal2-compliant self-encrypting drives (SEDs), where the drives' firmware fails to properly implement encryption, rendering the hardware encryption promise ineffective. The article does not provide specific CVSS scores, affected drive models or firmware versions, or a fixed version. The primary recommendation implied by the researchers' analysis is to verify the actual cryptographic implementation of hardware-encrypting drives before trusting them for data protection.
Read Full Article →

A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož and three colleagues bought 38 of those drives and ran them through a test bench. Brož maintains cryptsetup, the tool that configures disk encryption on most Linux systems. The drives came … More → The post Nobody was checking the drives that encrypt your laptop appeared first on Help Net Security .

Share this article