Live data from Hacker News

Self-encrypting deception: weaknesses in the encryption of solid state drives [pdf]

zdnet.com

111–113 of 113 posts

Re: Self-encrypting deception: weaknesses in the encryption of solid state drives [pdf]

#111
post #96
post #74

Earlier quoted context omitted.

If someone lifted your drive - the thing FDE is supposed to protect against - tamper evident seals are not going to offer much in the way of mitigation.

that isn’t what the seals are for.

They keep the data USDA Grade A fresh.

Re: Self-encrypting deception: weaknesses in the encryption of solid state drives [pdf]

#112
post #103

I am the original inventor of self-encrypting drives. My 3-4 page comment is too long so you can read it here www.privust.com/sedlies Which describes the work at RU, its partial truths, and the lying tweets that followed. Robert Thibadeau, Ph.D.

You'll probably get more credibility if that's linked in some way with your page at CMU or your Linkedin profile.

Re: Self-encrypting deception: weaknesses in the encryption of solid state drives [pdf]

#113
post #58

Earlier quoted context omitted.

Are there regulations in any industry which require the name of software authors on binaries/products, or at least the name of someone who approved the security claims made by the device?

Absolutely not.

... but in this particular case, people used their e-mail addresses as PBKDF2 salts, so we do have some idea. ;-)

(Of course, blaming whatever engineer isn't useful.)

Post reply on HN