BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] CipherShed: TrueCrypt fork
- Subject: [Discuss] CipherShed: TrueCrypt fork
- From: bogstad at pobox.com (Bill Bogstad)
- Date: Wed, 1 Oct 2014 23:48:27 +0200
- In-reply-to: <542C2714.60705@gmail.com>
- References: <542B63A8.50406@gmail.com> <542C1625.9000009@gmail.com> <CAJFsZ=oZh7Gzo69mTydO-SUNknZhqs06gQOH=h9naOiwCXfDRg@mail.gmail.com> <542C2714.60705@gmail.com>
On Wed, Oct 1, 2014 at 6:08 PM, Richard Pieri <richard.pieri at gmail.com> wrote: > On 10/1/2014 11:19 AM, Bill Bogstad wrote: >> Because you trust the firmware provided by the disk drive manufacturer? You >> clearly aren't wearing your tin foil hat today. >... > > There is a clever SED attack: hotplug. If you disconnect the SATA data > cable without disconnecting power then you can plug the drive into a > different host and the data will be readable. Nice. I'll have to remember that one. >This is easily foiled > simply by turning off the computer when physical security is low. > > In short, SEDs do everything that software encryption can do, they do it > faster, and they do it better. Actually, they don't do everything that (open source) software encryption does. They don't let you (or you an agent of your choice) audit the encryption algorithms/implementation to verify that everything is being done to spec. Now I admit that I've suggested in another thread that for MOST people ultimate security isn't required, but that doesn't meant that it isn't sometimes a good idea. In this case, it is more like not trusting firmware programmers not to screw things up inadvertently rather then being concerned about backdoors inserted by 3 letter agencies. Bill Bogstad
- Follow-Ups:
- [Discuss] CipherShed: TrueCrypt fork
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] CipherShed: TrueCrypt fork
- References:
- [Discuss] CipherShed: TrueCrypt fork
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] CipherShed: TrueCrypt fork
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] CipherShed: TrueCrypt fork
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] CipherShed: TrueCrypt fork
- Prev by Date: [Discuss] key server
- Next by Date: [Discuss] Shellshock
- Previous by thread: [Discuss] CipherShed: TrueCrypt fork
- Next by thread: [Discuss] CipherShed: TrueCrypt fork
- Index(es):