H L Data Storage Store Banner 970x90
Breaking News

MSI and Asus announces X670E motherborads AMD introduces Ryzen 7000 series, new chipsets and technologies CORSAIR introduce VOYAGER a1600 Gaming & Streaming Laptop AMD Advantage Edition Phison Announces Strategic PCIe Gen5 Relationship with AMD and Micron at Computex 2022 Apacer Unveils COMPUTEX 2022 Event Series

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Researchers Discover Security Flaws in Samsung and Crucial SSDs

Researchers Discover Security Flaws in Samsung and Crucial SSDs

PC components Nov 7,2018 0

Researchers at Radboud University in the Netherlands have discovered that popular SSDs featuring self-encrypting technology do not provide the expected level of data protection.

A malicious expert with direct physical access to widely sold storage devices can bypass existing protection mechanisms and access the data without knowing the user-chosen password, the researchers said.

These flaws exist in the encryption mechanism of several types of solid state drives of two major manufacturers, namely Samsung and Crucial. The vulnerabilities occur both in internal storage devices (in laptops, tablets and computers) and in external storage devices (connected via a USB cable). The storage devices affected include popular models that are currently widely available.

The researchers say that if sensitive data needs to be protected, it is in advisable to use software encryption and not rely solely on hardware encryption. On computers running Windows, BitLocker provides software encryption, and data may not be secure.

The researchers identified these security issues using public information and SSDs. Although it is quite difficult to discover these problems from scratch, once the nature of the issues is known, there is a risk that the exploitation of these flaws will be automated by others, making abuse easier. The researchers at Radboud University of course will not release such an exploitation tool.

The models for which vulnerabilities have actually been demonstrated in practice are:

  • Crucial (Micron) MX100, MX200 and MX300 internal disks;
  • Samsung T3 and T5 USB external disks;
  • Samsung 840 EVO and 850 EVO internal disks.

On computers running Windows, a software component called BitLocker handles the encryption of the computer's data. In Windows, the kind of encryption that BitLocker uses (i.e. hardware encryption or software encryption) is set via the Group Policy. If available, standard hardware encryption is used. For the affected models, the default setting must be changed so that only software encryption is used. This change does not solve the problem immediately, because it does not re-encrypt existing data. Only a completely new installation, including reformatting the internal drive, will enforce software encryption. As an alternative to reinstallation, the VeraCrypt software package can be used.

Both manufacturers were informed of this security problem in April 2018 by the National Cyber Security Centre (NCSC) of the Netherlands. The university provided details to both manufacturers to enable them to fix their product. The manufacturers will provide detailed information to their customers about the affected models.

For non-portable Samsung SSDs, Samsung recommends installing encryption software (freeware available online). For portable SSDs, the company recommends updating the firmware on the SSDs.

There is no official response from Micron/ Crucial yet.

Tags: SSDsSAMSUNGCrucial Technologyencryption
Previous Post
Nokia Signs EUR 2 billion Frame Agreements With Chinese Operators
Next Post
LG G7 Fit Smartphone Brings Features From the G Series to a Wider Audience

Related Posts

  • Samsung Electronics Showcases New Era of Micro LED Technology at ISE 2022

  • Samsung Electronics Introduces Industry’s First 512GB CXL Memory Module

  • Samsung Unveils 6G Spectrum White Paper and 6G Research Findings

  • Samsung Unveils New PRO Endurance Memory Card Optimized for Surveillance and Dashboard Cameras

  • Samsung’s Rugged T7 Shield Portable SSD Offers Durability and Fast Sustained Performance for Creative Professionals and Consumers On-the-Go

  • Samsung and Western Digital Collaborate To Kindle More Robust Data Storage Ecosystems

  • Samsung Electronics Hosts Its First-Ever 6G Forum To Explore the Next-Gen Communications Technologies

  • Samsung and Western Digital Begin Far-reaching Collaboration to Drive Standardization of Next-generation Storage Technologies

H L Data Storage Store Banner 300x600

 

Latest News

MSI and Asus announces X670E motherborads
PC components

MSI and Asus announces X670E motherborads

AMD introduces Ryzen 7000 series, new chipsets and technologies
Enterprise & IT

AMD introduces Ryzen 7000 series, new chipsets and technologies

CORSAIR introduce VOYAGER a1600 Gaming & Streaming Laptop AMD Advantage Edition
Gaming

CORSAIR introduce VOYAGER a1600 Gaming & Streaming Laptop AMD Advantage Edition

Phison Announces Strategic PCIe Gen5 Relationship with AMD and Micron at Computex 2022
Enterprise & IT

Phison Announces Strategic PCIe Gen5 Relationship with AMD and Micron at Computex 2022

Apacer Unveils COMPUTEX 2022 Event Series
Enterprise & IT

Apacer Unveils COMPUTEX 2022 Event Series

Popular Reviews

CeBIT 2005

CeBIT 2005

CeBIT 2006

CeBIT 2006

Zidoo Z9S 4K Media Player review

Zidoo Z9S 4K Media Player review

LiteOn iHBS112 review

LiteOn iHBS112 review

Club3D HD3850

Club3D HD3850

Pioneer BDR-2207 (BDR-207M) BDXL burner review

Pioneer BDR-2207 (BDR-207M) BDXL burner review

External USB Slim Recorders Comparison

External USB Slim Recorders Comparison

Crucial P1 NVMe 1TB SSD review

Crucial P1 NVMe 1TB SSD review

  • Home
  • News
  • Reviews
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed