Skip to main content
  1. Home
  2. Computing
  3. News

Encryption on some portable drives proves less secure than you’d expect

Add as a preferred source on Google

Encryption is a hot-button topic at the moment. If you’re a government official, it’s the bane of the intelligence world and a tool for terrorists. If you’re a whistleblower, freedom fighter, or journalist, it can be your lifeline to those that can help you. If you’re just an average citizen, it can be a way to give you a little bit more privacy than the current climate of technology offers.

But some devices that are designed to help Joe Consumer keep his files safe and secure from prying eyes while on the move are far from capable. In fact, some have been found to be easy enough to crack open that they don’t even require a password — making it rather redundant to create and memorize a long and complicated one.

Recommended Videos

This was discovered as part of an investigation by a group of security researchers into the levels of security on portable hard drives like Western Digital’s My Passport and My Book series. It turns out they are very lax, as those looking into it discovered multiple ways that the data could be removed quite painlessly.

Published in a report titled, “got HW crypto? On the (in)security of a Self-Encrypting Drive series,” the results paint a poor picture of Western Digital’s security, but also suggest that the standards within the industry are far from high.

While there are several security measures in place, like locking down the USB connection until a password is entered and salting the password, they don’t go very far in protecting the data. In one case, the random data used for the password hash is taken from the current time on a computer clock, making it very easy to guess. Although as Ars Technica points out, that particular flaw was patched out some time ago, not everyone will have updated their devices.

In another, much more egregious instance, the hash of the default password was found on some drivers when a user-generated code had only been changed once — making it a breeze for security researchers to crack it. Another problem was that some devices allowed for the copying of the password hash off the device, making it possible to crack it away from the drive in question.

In some instances, the Western Digital firmware itself was vulnerable to attack, though this and other problems were less prevalent in newer versions of the drives.

Although this isn’t necessarily an indication of every external drive with automated encryption being poorly protected, it does suggest that claims of high-security on such devices should be taken with a pinch of salt. For those wanting true protection, full-disk encryption is still a much safer bet.

Jon Martindale
Jon Martindale covers how to guides, best-of lists, and explainers to help everyone understand the hottest new hardware and…
MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses
AMD Ryzen CPU inside a socket installed on a motherboard

Spectre has been haunting CPU security since 2018, and MIT researchers have now found another way to make it misbehave. The new TONTOU attack can bypass some of the defenses Intel and AMD have added over the years by exploiting a tiny gap in how those protections work. The research comes from Daniël Trujillo and Mengjia Yan at MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL). Their findings show that even after a processor wipes or isolates information used by its branch predictor, there can be a brief window before that information is actually used. TONTOU, short for Time-of-Neutralization to Time-of-Use, attacks precisely that gap.

The tiny gap that TONTOU exploits

Read more
Microsoft accidentally gave Windows 11 users another OneDrive app, and you can’t easily remove it
Microsoft says the wider-than-intended rollout was an accident, but removing the app currently means removing OneDrive too.
Microsoft OneDrive Featured Graphic

Windows 11 users have been getting a new OneDrive app whether they asked for it or not. The problem? Microsoft says it wasn't supposed to happen. Microsoft has confirmed that its OneDrive Photos app was rolled out to Windows 11 PCs more broadly than intended, including enterprise machines where the app isn't even designed to work. The company says it is now working on a fix, but there's an awkward catch: users currently can't uninstall OneDrive Photos without removing the main OneDrive app too.

So, what exactly got installed?

Read more
Apple Reminders sucked for project management until I learned this feature
Your checklist deserves better. Here's how to turn Reminders into a proper Kanban board.
Apple reminders on Mac

For the longest time, I used Apple Reminders only for capturing quick tasks. Thanks to its Siri integration, Reminders let me add tasks quickly so nothing would fall through the cracks. However, when it came to managing big projects, I always moved to a more powerful task manager like OmniFocus or Things 3. 

That changed the day I stumbled onto the Column view. Apple added this feature with the iOS 17 and macOS Sonoma updates, and somehow I completely missed it. But once I discovered and got the hang of it, Reminders finally started to feel like a real project management tool instead of a glorified sticky note.

Read more