Live data from Hacker News

Autothysis SSD drives impede unauthorised access

securedrives.co.uk

1–10 of 58 posts

Re: Autothysis SSD drives impede unauthorised access

#2
Does this offer more security than hardware encryption e.g. in latest Intel and Samsung drives? These drives can transparently encrypt all the content with 256-bit AES; the password is ATA password.

They lost me at "Firstly the encryption key is flipped". What does this mean?

Re: Autothysis SSD drives impede unauthorised access

#4
post #2

Does this offer more security than hardware encryption e.g. in latest Intel and Samsung drives? These drives can transparently encrypt all the content with 256-bit AES; the password is ATA password. They lost me at "Firstly the encryption key is flipped". What does this mean?

Encrypted drives typically store the literal en/decryption key (derived from your password or credentials) and whatever salt is necessary on a chip. Nuking that information effectively makes your data unrecoverable, because it's no longer distinguishable from noise.

I assume "flipped" is a translation error for "cleared" or "randomized", especially given typos like "instantaineously".

Re: Autothysis SSD drives impede unauthorised access

#6
1. Use a GSM yammer to prevent self-destruction by SMS.

2. Steal the laptop and get out of the range of the token quickly to prevent self-destruction via the token. I could not find how drive and token communicate but you can probably jam it, too, for example Bluetooth.

3. Keep the battery charged to prevent self-destruction by low battery level and set up a femto cell - without connection to the real GSM net, of course - to prevent self-destruction by GSM starvation and SMS.

Now you should at least have all the time you need.

Re: Autothysis SSD drives impede unauthorised access

#7
post #2

Does this offer more security than hardware encryption e.g. in latest Intel and Samsung drives? These drives can transparently encrypt all the content with 256-bit AES; the password is ATA password. They lost me at "Firstly the encryption key is flipped". What does this mean?

I always wonder why this kind of drive-internal encryption comes up in serious discussions. To me it makes no sense whatsoever: I have no way of checking if the drive actually encrypts the data, I don't know what happens to my password, where is it stored, who else gets access to it (or my data), etc.

How can anyone consider this "transparent" encryption to be secure?

Re: Autothysis SSD drives impede unauthorised access

#8
post #6

1. Use a GSM yammer to prevent self-destruction by SMS. 2. Steal the laptop and get out of the range of the token quickly to prevent self-destruction via the token. I could not find how drive and token communicate but you can probably jam it, too, for example Bluetooth. 3. Keep the battery charged to prevent self-destruction by low battery level and set up a femto cell - without connection to the real GSM net, of cou…

Well, that at least sets a minimum financial barrier. The main problem with that plan is that you'd have to know that your target has this kind of protection beforehand.

Re: Autothysis SSD drives impede unauthorised access

#9
post #6

1. Use a GSM yammer to prevent self-destruction by SMS. 2. Steal the laptop and get out of the range of the token quickly to prevent self-destruction via the token. I could not find how drive and token communicate but you can probably jam it, too, for example Bluetooth. 3. Keep the battery charged to prevent self-destruction by low battery level and set up a femto cell - without connection to the real GSM net, of cou…

'Course, most people need protection against Paul The Pursesnatcher rather than the Mike The Megavillain.

Re: Autothysis SSD drives impede unauthorised access

#10
post #9
post #6

1. Use a GSM yammer to prevent self-destruction by SMS. 2. Steal the laptop and get out of the range of the token quickly to prevent self-destruction via the token. I could not find how drive and token communicate but you can probably jam it, too, for example Bluetooth. 3. Keep the battery charged to prevent self-destruction by low battery level and set up a femto cell - without connection to the real GSM net, of cou…

'Course, most people need protection against Paul The Pursesnatcher rather than the Mike The Megavillain.

In that case self-destructing chips seems total overkill. Everything beyond simple full disc encryption seems - at least to me - only to make sense if you expect a sophisticated targeted attack.
Post reply on HN