Skip to main content

Encryption on some portable drives proves less secure than you’d expect

Encryption is a hot-button topic at the moment. If you’re a government official, it’s the bane of the intelligence world and a tool for terrorists. If you’re a whistleblower, freedom fighter, or journalist, it can be your lifeline to those that can help you. If you’re just an average citizen, it can be a way to give you a little bit more privacy than the current climate of technology offers.

But some devices that are designed to help Joe Consumer keep his files safe and secure from prying eyes while on the move are far from capable. In fact, some have been found to be easy enough to crack open that they don’t even require a password — making it rather redundant to create and memorize a long and complicated one.

Recommended Videos

This was discovered as part of an investigation by a group of security researchers into the levels of security on portable hard drives like Western Digital’s My Passport and My Book series. It turns out they are very lax, as those looking into it discovered multiple ways that the data could be removed quite painlessly.

Published in a report titled, “got HW crypto? On the (in)security of a Self-Encrypting Drive series,” the results paint a poor picture of Western Digital’s security, but also suggest that the standards within the industry are far from high.

While there are several security measures in place, like locking down the USB connection until a password is entered and salting the password, they don’t go very far in protecting the data. In one case, the random data used for the password hash is taken from the current time on a computer clock, making it very easy to guess. Although as Ars Technica points out, that particular flaw was patched out some time ago, not everyone will have updated their devices.

In another, much more egregious instance, the hash of the default password was found on some drivers when a user-generated code had only been changed once — making it a breeze for security researchers to crack it. Another problem was that some devices allowed for the copying of the password hash off the device, making it possible to crack it away from the drive in question.

In some instances, the Western Digital firmware itself was vulnerable to attack, though this and other problems were less prevalent in newer versions of the drives.

Although this isn’t necessarily an indication of every external drive with automated encryption being poorly protected, it does suggest that claims of high-security on such devices should be taken with a pinch of salt. For those wanting true protection, full-disk encryption is still a much safer bet.

Jon Martindale
Jon Martindale is a freelance evergreen writer and occasional section coordinator, covering how to guides, best-of lists, and…
Amazon is selling this Sansui curved gaming monitor for only $230
A person playing video games on the Sansui ES-G34C5 curved gaming monitor.

You don't have to spend several hundred dollars to get a solid screen for your PC gaming setup. There are affordable monitor deals for gamers on a tight budget. Here's one from Amazon: the Sansui ES-G34C5 curved gaming monitor for only $230, following a 12% discount on its original price of $260. The $30 in savings doesn't look like much, but every dollar saved goes a long way in this hobby, so you should proceed with your purchase quickly to make sure you don't miss it.

Why you should buy the Sansui ES-G34C5 curved gaming monitor

Read more
Microsoft Edge Canary new tab page replaces MSN with Copilot
Microsoft Edge appears on a computer screen with plants and a window in the background.

Microsoft is testing a new Copilot-powered interface in the Canary version of Edge, replacing the MSN feed on the New Tab Page in an attempt to streamline browsing, according to Windows Latest. Users can enable it via experimental flags.

If the new design rolls out to the stable version, Copilot will replace the familiar MSN feed as the first thing you see when you open a new tab. You'll see a compose box in an uncluttered design with a greeting message that asks, "How can I help you today?"

Read more
This 27-inch gaming monitor from Samsung is nearly 50% off
A Samsung 27-inch G65B Curved Gaming Monitor on a white background.

You need a good gaming monitor to keep up with the lightning-fast PC titles on the market. Color accuracy, response time, and input lag are all factors to consider when shopping for a new game display. When it comes to all of the above, one brand that always delivers is Samsung, and it just so happens that one of Samsung’s top monitors is on sale today: 

For a limited time, you can get the Samsung 27-inch Odyssey G65B Gaming Monitor for $360. The MSRP on this model is $700, so you're getting this display at nearly 50% off.

Read more