Many encrypted SSDs can be decoded without a password
Researchers at Redboud University have discovered a vulnerability in some solid-state drives (SSD - Solid State Drive) that can decrypt encrypted hardware without a password.
Carlo Meijer and Bernard van Gastel discovered that they could modify the firmware and use debug tools to change the drive's authentication password. They tested successfully on Crucial and 840 EVO's MX100, MX200, and MX300 SSD drives, Samsung EV3, T3 Portable, and T5 Portable.
Researchers say they can perform reverse engineering on these drives, reprogramming it to authenticate the password despite entering anything. 'In theory, security measures by hardware encryption are said to be equal or better than software. But in fact, we find many drives with weaknesses, allowing data recovery without needing to know the password. '
Windows BitLocker encryption software also automatically switches to hardware encryption if it is available, so it is broken in the same way. Meijer and van Gastel use three techniques to exploit these vulnerabilities.
3 techniques for unlocking an SSD are encrypted
On Crucial's MX100, MX200 and 850 EVO, Samsung's T3 Portable, they hooked up to the drive's JTAG debug interface and edited the password. Type in any password to unlock the drive.
Crucial's MX300 also has a JTAG drive but is turned off by default. Instead they flash the drive with a fake firmware to authenticate using a blank password field. For the remaining drives, they reclaim the Data Encryption Key (DEK) with wear-leveling.
'Assuming DEK is stored without protection, this password is set by the user, and replaced that password with the encrypted variant'. 'Due to wear and tear, new variants are stored somewhere in storage chips, old addresses are considered unused. If not overwritten by other activities, DEK's unprotected variant can be recovered. '
Crucial and Samsung have been notified, Crucial has released patches for the firmware on the failed drive, and Samsung has updated the T3 and T5 Portable drives. With EVO drives, they encourage users to use encryption software.
See more:
- 9 best SSDs for gamers
- Review Samsung 850 EVO 500GB - The best removable SSD on the market today
- 7 mistakes easily 'kill' SSDs
You should read it
- Instructions for USB encryption with VeraCrypt
- Scientists have created the world's first unbreakable encryption chip, including quantum computers
- Detecting a Google Drive vulnerability could allow hackers to trick users into installing malware
- Google reinforced Google Drive data protection encryption
- Top 20 best encryption software for Windows
- What is end-to-end encryption? How does it work?
- New dangerous security vulnerabilities appear on iOS 11.2.6, can read messages without unlocking
- 5 popular encryption algorithms you should know
May be interested
- 4 bad sectors checking and fixing software on SSDs for freeit is frustrating when the computer encounters freezing, not booting or having unreadable information. one of the problems you should check is the presence of any bad sectors on the hard drive.
- How to set password protection folder on Macon macos, the folders are not encrypted directly, but you can set a password to protect it. this is an effective way of protecting folders and files contained therein.
- Intel produced SSD drives shaped rulers, wanted to set a record of storage capacitynow a petabyte of data can fit in a rack of racks.
- Things you need to know about NVMe SSDsnvmee stands for non-volatile memory express. it's a storage interconnect standard that uses the ultra-fast pci express (pcie) bus to communicate with your cpu, instead of the slower sata bus used by standard hard drives and sata ssds.
- The best password managers of 2020 and how to use thema password manager is essentially an encrypted digital vault that stores the login information you use to access apps on mobile devices, websites and other services. besides keeping your identity
- 5 Best SSDs for PS5 in 2024although ps5 officially supports memory expansion, not all ssds work well with this console.
- How to send encrypted email on Android using OpenKeychaintoday's article will show you how to encrypt email on android using openkeychain. the best thing is that openkeychain is completely free. using openkeychain for email encryption is quick, easy and effective.
- Trick to find encryption password on windows laptopwhile using the computer, you will log in with accounts and passwords on many different services both on the computer and on the website. but this login information is actually encrypted and stored on the computer. taimienphi will guide you to view encrypted passwords on your windows using available tools or software such as encryptedregview, credentialsfileview or vaultpasswordview.
- Apple updated the password revealing patch from the Disk Utility functionapple has just released an emergency update for macos high sierra to fix errors that expose passwords that are encrypted in apfs format via password hint feature.
- Should I choose SATA or PCIe SSD?the article will help you distinguish sata and pcie ssds and what you need to know when choosing to buy ssds.