Live data from Hacker News

Autothysis SSD drives impede unauthorised access

securedrives.co.uk

41–50 of 58 posts

Re: Autothysis SSD drives impede unauthorised access

#42

I can't really see the usage scenario. If you want to transmit data securely between A and B, use public key cryptography and the internet [1]. If you want to protect data at rest, use full disk encryption. If you want protect the data on a running PC against theft, then you also have to consider all the data in the RAM (caches etc.). And if you, somehow, can prevent the attackers from getting that, then you can agai…

>I can't really see the usage scenario. ... If you want to protect data at rest, use full disk encryption.

It's pretty easy to think of scenarios that FDE does not protect against but this product could.

1) While cloning, modify the bootloader to load a software keylogger when the computer starts.

2) After cloning, install a hardware keylogger.

Re: Autothysis SSD drives impede unauthorised access

#44
post #41

The obvious thing to get around the "fragmentation" would be to leave the chip on the PCB and cut the traces. Then connect your own wires or an upside-down socket from above. Anything I'm missing?

That it physically destroys the chips if you open the case? Or (optionally) if you unplug the SATA cable?

Re: Autothysis SSD drives impede unauthorised access

#45
post #30

I can't really see the usage scenario. If you want to transmit data securely between A and B, use public key cryptography and the internet [1]. If you want to protect data at rest, use full disk encryption. If you want protect the data on a running PC against theft, then you also have to consider all the data in the RAM (caches etc.). And if you, somehow, can prevent the attackers from getting that, then you can agai…

Some jurisdictions force people to decrypt their drives under pain of contempt of court. Some jurisdictions use rubber-hose cryptanalysis. Full disk encryption protects against neither. This protects against both.

No more than zeroizing the key would.

Re: Autothysis SSD drives impede unauthorised access

#46

I'd like to know if the self-destruct mechanism still functions at very low temperatures. Given that one known attack on data in RAM is to flash freeze it (Cold Boot Attack) it is natural to think about lowering the device temperature to the point where chemical reactions wouldn't and mechanical devices would jam.

That probably won't work on its own, but as part of a nutritious breakfast...

First thing I'd try: LN₂ over the case entry sensors followed by that fun expandy foam stuff.

It probably wouldn't work first time, but next try I'd know where to short/aim. Or shortcut that with X/gamma so I have a drill point.

Re: Autothysis SSD drives impede unauthorised access

#47
post #36

Does anyone have any insights on how the actual physical destruction takes place? I would assume it is a chemical triggered by a shorted fuse? A quick glance at the laws in California make it a felony to simply have in your possession "any sealed device containing dry ice or other chemically reactive material that is assembled for the purpose of causing an explosion." The definitions for other types of destructive de…

Perhaps not an explosion within the meaning of applicable California statutes. Looking at the pix that show chip fragmentation, I don't see evidence of reactive chemistry. No melted edges, no deposition of combustion products, no missing material that would suggest propulsive transport incident to a micro explosion caused by detonation of a tiny blob of, for example, lead styphnate or some other primer-like compound.…

Very nearly. Overcurrent spike to Vcc. Simple and obvious. (How'd they get a patent? GCHQ already certified drives that do this, from Stonewood? They use the Eclypt 600 series for their own TOP SECRET data.)

Re: Autothysis SSD drives impede unauthorised access

#48
post #7
post #2

Does this offer more security than hardware encryption e.g. in latest Intel and Samsung drives? These drives can transparently encrypt all the content with 256-bit AES; the password is ATA password. They lost me at "Firstly the encryption key is flipped". What does this mean?

I always wonder why this kind of drive-internal encryption comes up in serious discussions. To me it makes no sense whatsoever: I have no way of checking if the drive actually encrypts the data, I don't know what happens to my password, where is it stored, who else gets access to it (or my data), etc. How can anyone consider this "transparent" encryption to be secure?

And that is before you consider back doors and the like

Re: Autothysis SSD drives impede unauthorised access

#50
post #30

I can't really see the usage scenario. If you want to transmit data securely between A and B, use public key cryptography and the internet [1]. If you want to protect data at rest, use full disk encryption. If you want protect the data on a running PC against theft, then you also have to consider all the data in the RAM (caches etc.). And if you, somehow, can prevent the attackers from getting that, then you can agai…

Some jurisdictions force people to decrypt their drives under pain of contempt of court. Some jurisdictions use rubber-hose cryptanalysis. Full disk encryption protects against neither. This protects against both.

How does this protect me from them not touching my computer at all, walking me in to a different room, tying me to a chair, and... uh... "asking politely while showing me a warrant" for me to decrypt the device and disable any security features?
Post reply on HN