Several versions of self-encrypting hard drives from Western Digital are riddled with so many security flaws that attackers with physical access can retrieve the data with little effort, and in some cases, without even knowing the decryption password, a team of academics said. . The paper, titled got HW crypto? On the (in)security of a Self-Encrypting Drive series, recited a litany of weaknesses in the multiple versions of the My Passport and My Book brands of external hard drives. The flaws make it possible for people who steal a vulnerable drive to decrypt its contents, even when they're locked down with a long, randomly generated password. The devices are designed to self-encrypt all stored data, a feature that saves users the time and expense of using full-disk encryption software. . Seagate's self-encrypting disks exhibit critical vulnerabilities that permit illicit access to stored data, undermining the effectiveness of their encryption.. Western Digital Security Flaws, Self-Encrypting Drive Issues, Data Breach Risks. . LinuxSecurity.com Team
Cryptographic researchers have identified flaws in Secure Shell (SSH) which might allow hackers to obtain information about a user's password or traffic being sent using the secure protocol. SSH has two weaknesses which might be exploited by traffic analysis that looked . . . . Cryptographic researchers have identified flaws in Secure Shell (SSH) which might allow hackers to obtain information about a user's password or traffic being sent using the secure protocol. SSH has two weaknesses which might be exploited by traffic analysis that looked at the timing of keystrokes, according to a paper published by University of California, Berkeley researchers on the subject. Firstly, if a block cipher is used, transmitted packets are packed with only an eight-bit boundary, which reveals the approximate size of original data. The second issue is that while in interactive mode every keystroke a user types is sent in a separate IP packet after a key is pressed, which gives information on a user's typing. The link for this article located at TheRegister is no longer available. . Security analysts discover vulnerabilities in SSL protocols, enabling cybercriminals to intercept credentials and confidential communication.. SSH Vulnerabilities, Traffic Analysis Risks, Cryptographic Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.