Researchers at Radboud University in the Netherlands have discovered that widely used data storage devices with self-encrypting drives do not provide the expected level of data protection. A malicious expert with direct physical access to widely sold storage devices can bypass existing protection mechanisms and access the data without knowing the user-chosen passwordIn general, a password is an arbitrary string of characters including letters, digits, or other symb... More.
Which models are affected?
- Crucial (Micron) MX100, MX200 and MX300 internal hard disks
- Samsung T3 and T5 USB external disks
- Samsung 840 EVO and 850 EVO internal hard disks
As not all disks available on the market have been tested, there is possibility there is more affected range of models.
Is the remote attack possible (via internet)?
No. Attacker has to have direct physical access to disk.
I am using BitLocker for encryptionTurning data into a form that cannot be understood without the right key. More, am I affected?
On computers running Windows, a software component called BitLocker handles the encryptionTurning data into a form that cannot be understood without the right key. More of the computer’s data. In Windows, the kind of encryptionTurning data into a form that cannot be understood without the right key. More that BitLocker uses (i.e. hardware encryptionTurning data into a form that cannot be understood without the right key. More or software encryptionTurning data into a form that cannot be understood without the right key. More) is set via the Group Policy. If available, standard hardware encryptionTurning data into a form that cannot be understood without the right key. More is used. For the affected models, the default setting must be changed so that only software encryptionTurning data into a form that cannot be understood without the right key. More is used. This change does not solve the problem immediately, because it does not re-encrypt existing data. Only a completely new installation, including reformatting the internal drive, will enforce software encryptionTurning data into a form that cannot be understood without the right key. More.
I am using other tool for encryptionTurning data into a form that cannot be understood without the right key. More (e.g. VeraCrypt), Am I affected?
Probably not. Tools such a VeraCrypt use software encryptionTurning data into a form that cannot be understood without the right key. More
You can learn how to use VeraCrypt during the Digital Self-defense workshop
Are there security patches?
There is firmware update for Crucial disks and Samsung T3 and T5 models. Samsung EVO are unpatched, Samsung recommends installing encryptionTurning data into a form that cannot be understood without the right key. More software that is compatible with your system (e.g. VeraCrypt).
How to force BitLocker to use software encryptionTurning data into a form that cannot be understood without the right key. More?
- Open the Local Group Policy Editor by entering “gpedit.msc” in the Run dialog.
- Head on to “Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption\Fixed Data Drives.”
- Double-click the “Configure use of hardware-based encryptionTurning data into a form that cannot be understood without the right key. More for fixed data drives” option in the right panel.
- Select the “Disabled” option there and click “OK” to save the new setting.
- Before software encryptionTurning data into a form that cannot be understood without the right key. More will be used, after you change these policies you must first completely decrypt the drive and then enable BitLocker again to use software encryptionTurning data into a form that cannot be understood without the right key. More.
(sources: Radboud University, The Hacker News)
