Live data from Hacker News

Autothysis SSD drives impede unauthorised access

securedrives.co.uk

51–58 of 58 posts

Re: Autothysis SSD drives impede unauthorised access

#51
post #15
post #14

Huge problem with these schemes: If my data is valuable, I have two fears: (1) theft, (2) loss. If my drive is built to self-destruct, it decreases fear #1 but increase fear #2. What do I do then? Back up my data elsewhere? But that defeats the purpose of the high security drive. Do I get more than one high security drive? That still puts a lot of trust in the design -- if there were a systemic flaw that caused them…

Presumably the use case would be you want to transfer secret information from a secure location via an insecure channel to another secure location (e.g. in a diplomatic bag perhaps?). This is for people who care more about knowing that the data was transferred securely than whether it goes through at all. There would likely be a master (backed up) copy on an internal air-gapped machine.

Or when data is temporarily removed / copied from the highest security locations.

E.g. I was part of maintenance on a defence system once that in itself wasn't very important, but it was kept in an air-gapped concrete bunker with a faraday cage deep inside the office building. Offices outside were used for top secret data during processing, but when people were done working on something, storage would happen in the "bunker".

I'd imagine drives like these would be popular for the offices.

Re: Autothysis SSD drives impede unauthorised access

#52

I have not (yet?) evaluated this device. I do however have a couple of initial comments. Only the (TI) security processor itself had a FIPS 140-2 Level 3 crypto engine. However this device as a whole has no certifications I am aware of, FIPS, CESG or anywhere else (let's leave aside for a moment the flaws of the certification processes). Given its claims, the threat model and what it tries to do, that is actually sur…

I'm far from being a hardware expert, but I thought it was curious that they used CBC rather than something like XTS. Is there a reason that CBC is more appropriate when used at the hardware (as opposed to filesystem) level, or is this simply just a rather suspect choice?

Re: Autothysis SSD drives impede unauthorised access

#53
post #21

Earlier quoted context omitted.

Do they check the internals of a laptop's hard drive nowadays? :-)

chemical scans probably will detect it.

Chemical scans would probably be pretty hard-pressed to detect thermite, which is after all just aluminium and iron oxide powder. Even the magnesium starter is non-sniffable.

Re: Autothysis SSD drives impede unauthorised access

#55
post #6

1. Use a GSM yammer to prevent self-destruction by SMS. 2. Steal the laptop and get out of the range of the token quickly to prevent self-destruction via the token. I could not find how drive and token communicate but you can probably jam it, too, for example Bluetooth. 3. Keep the battery charged to prevent self-destruction by low battery level and set up a femto cell - without connection to the real GSM net, of cou…

Indeed.

This is all very neat, but it appears these folks haven't heard of X-ray microscopy - I don't see why, with a sufficiently high resolution scan, you couldn't see the physical state of the NAND switches on the chip, without opening the packaging, or doing anything else to trigger it.

16nm gates, 10nm resolution achieved - this is probably "good enough", although would require some work as the resolution is barely better than the NAND cell size.

Although you could remedy this by wrapping the thing in lead, within the case - which maybe they have. Be interesting to see the RoHS statement.

http://en.wikipedia.org/wiki/X-ray_microscope

Re: Autothysis SSD drives impede unauthorised access

#56

I have not (yet?) evaluated this device. I do however have a couple of initial comments. Only the (TI) security processor itself had a FIPS 140-2 Level 3 crypto engine. However this device as a whole has no certifications I am aware of, FIPS, CESG or anywhere else (let's leave aside for a moment the flaws of the certification processes). Given its claims, the threat model and what it tries to do, that is actually sur…

I'm far from being a hardware expert, but I thought it was curious that they used CBC rather than something like XTS. Is there a reason that CBC is more appropriate when used at the hardware (as opposed to filesystem) level, or is this simply just a rather suspect choice?

Probably it was already in the microcontroller they're using. XTS was only FIPS-approved in 2010, iirc. Plenty of other things use CBC, and XTS also has plenty of pitfalls for the unwary who think it works magic (particularly when it comes to the adaptive ciphertext observation/modification class of attacks, in the absence of integrity protection).

Speaking of magic, I've just realised one big potential problem that's been bugging me about this, which finally leaped out at me.

Destruct is controlled via SMS? That is to say, unless they've been unbelievably careful about shielding and optoelectronic coupling (and from the photos, they haven't) there's almost certainly a GSM transceiver, inside the security boundary, near the data paths.

Oops.

Those familiar with EMSEC will know why this could present a Big Problem™. My first port of call, attacking one of these, rather than stealing it, would probably be to sit in the car park with a femtocell and a directional antenna, and make sure the device gets really loud GSM reception. And see what crosstalk gets modulated back. :)

(If you don't think this is a realistic attack for you, why are you in the market for Mission Impossible gadgets anyway? Use TrueCrypt or dm-crypt or DiskCryptor or something. At least you can analyse how they work more easily.)

Similarly, if it's made by, or spiked by, a malicious actor, it's got scope to go kleptographic on your ass and covertly transmit your data. Need to be careful about that.

Re: Autothysis SSD drives impede unauthorised access

#57
post #6

1. Use a GSM yammer to prevent self-destruction by SMS. 2. Steal the laptop and get out of the range of the token quickly to prevent self-destruction via the token. I could not find how drive and token communicate but you can probably jam it, too, for example Bluetooth. 3. Keep the battery charged to prevent self-destruction by low battery level and set up a femto cell - without connection to the real GSM net, of cou…

Thats all well and good, Provided you know I have one of these drives. I wouldn't exactly advertise that fact.

Re: Autothysis SSD drives impede unauthorised access

#58
post #30

Earlier quoted context omitted.

Some jurisdictions force people to decrypt their drives under pain of contempt of court. Some jurisdictions use rubber-hose cryptanalysis. Full disk encryption protects against neither. This protects against both.

How does this protect me from them not touching my computer at all, walking me in to a different room, tying me to a chair, and... uh... "asking politely while showing me a warrant" for me to decrypt the device and disable any security features?

I'm not sure but there might be a destruct key. Give them that, and have them nuke the drive for you :)
Post reply on HN