SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    BitLocker on Self-Encrypted SSDs Blown; Microsoft Advises You Switch to Software Protection
Date    Thursday November 08 2018, @08:46AM
Author    mrpg
Topic   
from the advise-an-advice dept.
https://soylentnews.org/article.pl?sid=18/11/08/0126245

upstart writes:

Submitted via IRC for Bytram

BitLocker on self-encrypted SSDs blown; Microsoft advises you switch to software protection

Yesterday, Microsoft released ADV180028, Guidance for configuring BitLocker to enforce software encryption, in response to a clever crack published on Monday by Carlo Meijer and Bernard van Gastel at Radboud University in the Netherlands (PDF).

[...] The security researchers explain that they were able to modify the firmware of the drives in a required way, because they could use a debugging interface to bypass the password validation routine in SSD drives. It does require physical access to a (internal or external) SSD. But the researchers were able to decrypt hardware-encrypted data without a password. The researchers write that they will not release any details in the form of a proof of concept (PoC) for exploit.

Microsoft's BitLocker feature encrypts all the data on a drive. When you run BitLocker on a Win10 system with a solid state drive that has built-in hardware encryption, BitLocker relies on the self-encrypting drive's own capabilities. If the drive doesn't have hardware self-encryption (or you're using Win7 or 8.1), BitLocker implements software encryption, which is less efficient, but still enforces password protection.

[...] The hardware-based self-encryption flaw seems to be present on most, if not all, self-encrypting drives.


Original Submission

Links

  1. "upstart" - https://soylentnews.org/~upstart/
  2. "BitLocker on self-encrypted SSDs blown; Microsoft advises you switch to software protection" - https://www.computerworld.com/article/3319736/microsoft-windows/bitlocker-on-self-encrypted-ssds-blown-microsoft-advises-you-switch-to-software-protection.html
  3. "Guidance for configuring BitLocker to enforce software encryption" - https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV180028
  4. "PDF" - https://www.ru.nl/publish/pages/909275/draft-paper_1.pdf
  5. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=29991

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, BitLocker on Self-Encrypted SSDs Blown; Microsoft Advises You Switch to Software Protection on 2024-04-27 08:39:05