On TV.com: Latest DEXTER Renewed My Faith
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 36 of 40:
Next »
« Previous
But what about 'back door' holes?
As with the Clipper chip, it would be easy to have a back door in this encryption chip scheme and/or its BIOS/ROM etc.

We could see a nasty scenario whereby some poor user looses a lifetime's work when he/she loses or forgets the password. Seagate will say the data is irrecoverable, so will everybody else. In the meantime, the snoops will be transparently reading away as if encryption had never happened--AND quite content to let the poor unfortunates suffer for fear of revealing that they read everything.

The ONLY way hard disk drive encryption can work satisfactorily is for:

(a) The chip's technical parameters to be open, published and standardized a bit like the PGP algorithm is now (i.e.: the chip's encryption algorithm would be fully published and open to public scrutiny).

(b) The chip's silicon would need to be reverse-engineered to check for 'back-door' holes and any other potential security breaches. Some method of authenticating and certifying that the correct chip is actually installed needs to be deployed.

(c) Drive motherboards (which holds the encryption chip) must be continuously under surveillance and continuously authenticated to ensure that the correct chip is installed and is operational according to the standard, and also that at no time can the chip be bypassed. Similarly, at all times, the chip needs to under continuous authenticated surveillance to ensure it doesn't change.

(d) The encryption algorithm needs to be authenticated on-the-fly to ensure that the algorithm is not modified, added to or bypassed whilst in use.

(e) ALL user data MUST ALWAYS go via the encryption chip and that there is neither a method of bypassing the encryption nor bypassing the chip. Active monitoring will advise if the status changes.

(f) The drive needs anti-tamper technology installed (both physical and electronic) with active monitoring.

(g) Ideally, the chip would be socketed. This would allow the user to install his/her own chip with a user-installed algorithm etc. and thus be fully under control of the user and its operation fully verifiable.

There is nothing special about what I'm saying here, these measures are not over-the-top, rather they are just the normal rules and procedures required to encrypt, authenticate (verify) and to ensure there are no security leaks associated with the drive's security.

NOTE: this is just the drive's security. How to secure an operating PC is another matter entirely.

To date, the information about Seagate's drive security is so vague that one can but help wonder if this were not a scheme to lull average users into thinking they have secure drives whilst those in the know will have easy access.

In the meantime:

(a) Don't trust stuff you don't want seen by putting it on a hard disk, and;

(b) if you must store important info on your drive then use proven and well-tested encryption such as PGP or Blowfish etc. to secure it.
Posted by: Irritated_User   Posted on: 11/04/06 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

even Seagate is screwed by M$  Linux Geek | 10/30/06
So Linux doesnt  HexHammer67 | 10/30/06
It's all about the naughty bits  Yagotta B. Kidding | 10/30/06
I see where your going but  HexHammer67 | 10/30/06
Linux has the same problem ... sort of ...  George Mitchell | 10/30/06
I must have missed something.  D-cat | 11/01/06
You didn't miss anything....  TasteeWheat | 11/13/06
actually  T2mg2003 | 11/02/06
Crap  Yagotta B. Kidding | 10/30/06
The encryption is...  Linux_Fanboy | 10/30/06
The biggest problem...  ViRaL1 | 10/30/06
No, the biggest problem  Yagotta B. Kidding | 10/30/06
Oh Yeah...  D-cat | 11/01/06
Hmmm, interesting but...  No_Ax_to_Grind | 10/30/06
Encryption method ...  George Mitchell | 10/30/06
That's not the point  Yagotta B. Kidding | 10/30/06
Did you actually read the article?  George Mitchell | 10/30/06
Yup.  Yagotta B. Kidding | 10/30/06
Lost In Post  HexHammer67 | 10/30/06
I Share the Concerns  sorrentino@... | 11/01/06
i bet...  T2mg2003 | 11/02/06
Right on the point. And there's more too.  Irritated_User | 11/04/06
Who else has the keys?  terry flores | 10/30/06
Nobody, if you lose the password...  Linux_Fanboy | 10/30/06
What about this stuff?  norwegian | 10/31/06
I think it sucks because...  Linux_Fanboy | 10/31/06
You mean just like they can already do now?  Spoon Jabber | 10/31/06
Read the previous post please...  Linux_Fanboy | 10/31/06
You make a big assumption that Seagate is "honest"  terry flores | 10/31/06
Post says:  Spoon Jabber | 11/01/06
Right! Only trust encryption to yourself. Reckon it smells very fishy.  Irritated_User | 11/04/06
Malware?  a1comp@... | 11/01/06
now if you're using this at home...  nix_hed | 11/02/06
Just Another Sneaky  Ole Man | 11/01/06
Price Premium  tretolac | 11/01/06
But what about 'back door' holes?  Irritated_User | 11/04/06
Whatever happened to the ZDNet TalkBack Preview Mode?  Irritated_User | 11/04/06
What this really is..  John_Doe69 | 11/06/06
Wesite Design Thoughts  solutions@... | 04/01/07
Wesite Design Thoughts Redux  solutions@... | 04/01/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

SmartPlanet

Click Here