Live data from Hacker News

Autothysis SSD drives impede unauthorised access

securedrives.co.uk

21–30 of 58 posts

Re: Autothysis SSD drives impede unauthorised access

#21

This is really cool. I wonder if you could make a simple DIY solution using small amounts of explosive?

Might not be the best think to take with you when you board a plane.

Do they check the internals of a laptop's hard drive nowadays? :-)

Re: Autothysis SSD drives impede unauthorised access

#22
post #10
post #9

Earlier quoted context omitted.

'Course, most people need protection against Paul The Pursesnatcher rather than the Mike The Megavillain.

In that case self-destructing chips seems total overkill. Everything beyond simple full disc encryption seems - at least to me - only to make sense if you expect a sophisticated targeted attack.

Yes you are right with regards to encryption. However, law enforcement agencies nowadays make sure to freeze devices like telephones in order to prevent them from locking/logging out. In case of (desktop) computers that are turned on, they make sure to splice the cables and hook them onto batteries in order to preserve their on state. I assume they are also aware of things like this self-destructing drive, but I am not sure what their attack vectors are. Most likely they just beat you until you tell them the code.

In case of traveling with sensitive data however this system is pretty good. Normally you'd be forced to give up the encryption passphrase, but when the data is destroyed there is nothing to give up.

Re: Autothysis SSD drives impede unauthorised access

#23
post #10
post #9

Earlier quoted context omitted.

'Course, most people need protection against Paul The Pursesnatcher rather than the Mike The Megavillain.

In that case self-destructing chips seems total overkill. Everything beyond simple full disc encryption seems - at least to me - only to make sense if you expect a sophisticated targeted attack.

If you are Mike the Megavillain, then the protection this sort of set-up buys you is from Fred the FBI officer who raids your volcano lair for some other purpose, and bags your laptop as part of a general sweep for evidence without really knowing much about technology. By the time Charlie the CSI gets to it, there's nothing left to recover to reveal your even-more-nefarious plots.

Re: Autothysis SSD drives impede unauthorised access

#24

I can't really see the usage scenario. If you want to transmit data securely between A and B, use public key cryptography and the internet [1]. If you want to protect data at rest, use full disk encryption. If you want protect the data on a running PC against theft, then you also have to consider all the data in the RAM (caches etc.). And if you, somehow, can prevent the attackers from getting that, then you can agai…

[deleted]

Re: Autothysis SSD drives impede unauthorised access

#26
post #6

1. Use a GSM yammer to prevent self-destruction by SMS. 2. Steal the laptop and get out of the range of the token quickly to prevent self-destruction via the token. I could not find how drive and token communicate but you can probably jam it, too, for example Bluetooth. 3. Keep the battery charged to prevent self-destruction by low battery level and set up a femto cell - without connection to the real GSM net, of cou…

> GSM Starvation Period – You can specify a period of time in hours that if the Drive cannot access a GSM service within this time period then the Drive will self-destruct. This protects against the removal of the GSM service in an attempt to circumvent the security features of the Drive.

you forgot one, and it makes jamming more difficult.

Re: Autothysis SSD drives impede unauthorised access

#27
post #6

1. Use a GSM yammer to prevent self-destruction by SMS. 2. Steal the laptop and get out of the range of the token quickly to prevent self-destruction via the token. I could not find how drive and token communicate but you can probably jam it, too, for example Bluetooth. 3. Keep the battery charged to prevent self-destruction by low battery level and set up a femto cell - without connection to the real GSM net, of cou…

[deleted]

Re: Autothysis SSD drives impede unauthorised access

#28

This is really cool. I wonder if you could make a simple DIY solution using small amounts of explosive?

If you don't care about the safety of anyone involved and don't wish to go into a government building with your laptop, I'm sure thermite would be a lot more effective for its weight than a civilian acquirable explosive.

A thin layer of thermite, a magnesium starter, and a ceramic holster to keep the thermite firmly against the drive during the burn should work. Two thousand degrees of burning iron a few millimeters away from the nand should thoroughly annihilate it.

Re: Autothysis SSD drives impede unauthorised access

#29
post #13
post #6

1. Use a GSM yammer to prevent self-destruction by SMS. 2. Steal the laptop and get out of the range of the token quickly to prevent self-destruction via the token. I could not find how drive and token communicate but you can probably jam it, too, for example Bluetooth. 3. Keep the battery charged to prevent self-destruction by low battery level and set up a femto cell - without connection to the real GSM net, of cou…

They also sell devices called Data Security Protocol Switches (DSPS) which completely prevent your method from working. "A Signal Proximity (SP) option means that any registered AutothysisDSP computer hard drive that leaves the vicinity of the DSPS signal will automatically self-destruct. This protects against theft and someone walking out the room with a computer. Likewise if a jamming of the DSPS signal is tried in…

Ok, now I wonder: couldn't you harass people using this technology by jamming the DSPS signal until they give up on it and choose something else? I bet that these hard drives are costly enough so that it becomes a problem fast.

Re: Autothysis SSD drives impede unauthorised access

#30

I can't really see the usage scenario. If you want to transmit data securely between A and B, use public key cryptography and the internet [1]. If you want to protect data at rest, use full disk encryption. If you want protect the data on a running PC against theft, then you also have to consider all the data in the RAM (caches etc.). And if you, somehow, can prevent the attackers from getting that, then you can agai…

Some jurisdictions force people to decrypt their drives under pain of contempt of court. Some jurisdictions use rubber-hose cryptanalysis. Full disk encryption protects against neither. This protects against both.
Post reply on HN