dcinematools.com

Monday
Feb 06th
Text size
  • Increase font size
  • Default font size
  • Decrease font size
Home Security In the News FIPS 140-2 Level 2 Certified USB Memory Stick Cracked

FIPS 140-2 Level 2 Certified USB Memory Stick Cracked

email print PDF

Encrypting USB Flash memory from Kingston, SanDisk and Verbatim. Kingston, SanDisk and Verbatim all sell quite similar USB Flash drives with AES 256-bit hardware encryption that supposedly meet the highest security standards. This is emphasised by the FIPS 140-2 Level 2 certificate issued by the US National Institute of Standards and Technology (NIST), which validates the USB drives for use with sensitive government data. Security firm SySS, however, has found that despite this it is relatively easy to access the unencrypted data, even without the required password.
H-Online

This is from the H-Online Article:
NIST-certified USB Flash drives with hardware encryption cracked
Yes; DCI specifies that the euqipment meets FIPs Level 3, not level 2. But 3 huge companies making the same mistake? Hmmm. Plus, this is not just a DCinema issue, this affect everyone who tries to keep their personal or work computer safe, trusting devices and technology of this type. My guess is that there was an Application Note that specified how to make a particular chipset work (which all the manufacturers used.) It was the Application Note that everyone followed and which had the implementation flaw. Just a guess.

The article continues, excepted below. There is also some fine commentary about this issue at: Schnieier on Security.

 

The USB drives in question encrypt the stored data via the practically uncrackable AES 256-bit hardware encryption system. ... the SySS security experts found a rather blatant flaw that has quite obviously slipped through testers' nets. ... the program will, irrespective of the password, always send the same character string to the drive after performing various crypto operations...

Cracking the drives is therefore quite simple. The SySS experts wrote a small tool ... The vulnerable devices include the Kingston DataTraveler BlackBox, the SanDisk Cruzer Enterprise FIPS Edition and the Verbatim Corporate Secure FIPS Edition.

When notified by SySS about this worst case security scenario, the respective vendors responded quite differently. Kingston started a recall of the affected products; SanDisk and Verbatim issued woolly security bulletins about a "potential vulnerability in the access control application" and provided a software update.

Comments (0)
Only registered users can write comments!
 
For the Kids and the Weekend: WonderHowTo SpectraCal 15% discount with 3D Video Pattern Generator

Free International DCinema Business Directory...How To...

DCinemaTools.com is pleased to have added a free feature called The Business Directory. Free to use, free to enter. If a per...

Showbiz Podcast

I imagine that are many who know more about movie equipment than they do about all the fluff and glamor that pays for it all....

  • Free International DCinema Business Directory...How To...

    Friday, 27 January 2012 22:24
  • Showbiz Podcast

    Tuesday, 31 January 2012 15:11
DCinemaToday's Latest:

3Questions: OpenDCP – Now with GUI

The dream of creating DCPs for local commercials and film festivals by artists using simple yet affordable tools just took a ...

DCinema Projectionist and Tech Survey – November 2011

Hello; a friend is giving a presentation at Camera Image Conference at the end of November 2011. We would apprecia...

23 degrees...half the light. 3D What?

3D Luminance Issues—Photopic, barely. Mesopic, often. Scotopic? Who knows...?  We don't mean to be picking on the good ...

3Questions on HI/VI Issues – European Union of the Deaf

There are several groups who represent the varied and specific interests of the community of people with disabilities in...

What Is A Projectionist? In The Digital Age

Marketing Guru Adrian Weidmann says, "Always Solve For Why". In the Digital Cinema Age there are several more Quality Control...

The State of Digital Cinema - April 2010 - Part Zero

This document is Part 0 of an multipart article that details with the basics of today's transition from film-based cinema to ...

The State of Digital Cinema - April 2010 Part Two

Part I of this series ended with generalities about where DCinema has been and how it got here. Since the series is written...

Scotopic Issues with 3D, and Silver Screens

SMPTE and DCI specs notwithstanding, measuring an auditorium is an art, not a science. Even a non-silver screen with gain is ...

The State of Digital Cinema - April 2010 | Part One

As it is in many fields, the world of cinema involves a broad reach of talent and technology that begins with an artistic i...

3Questions - Laser Light Engines

When we think of a digital cinema projector's light path, we non-optical designers consider the lamp and reflector housing, t...

  • 3Questions: OpenDCP – Now with GUI

    Wednesday, 27 April 2011 11:06
    Publish In: Connectivity
  • DCinema Projectionist and Tech Survey – November 2011

    Thursday, 10 November 2011 01:48
    Publish In: Exhibitor News
  • 23 degrees...half the light. 3D What?

    Monday, 16 August 2010 22:27
    Publish In: Consultants
  • 3Questions on HI/VI Issues – European Union of the Deaf

    Wednesday, 12 January 2011 15:06
    Publish In: Articles and News
  • What Is A Projectionist? In The Digital Age

    Thursday, 07 July 2011 09:50
    Publish In: Technique Bin
  • The State of Digital Cinema - April 2010 - Part Zero

    Monday, 26 April 2010 05:44
    Publish In: Consultants
  • The State of Digital Cinema - April 2010 Part Two

    Monday, 26 April 2010 05:39
    Publish In: Consultants
  • Scotopic Issues with 3D, and Silver Screens

    Tuesday, 13 July 2010 18:20
    Publish In: Technique Bin
  • The State of Digital Cinema - April 2010 | Part One

    Thursday, 22 April 2010 12:53
    Publish In: Consultants
  • 3Questions - Laser Light Engines

    Thursday, 06 January 2011 01:28
    Publish In: The Future Holds...

Quick Links

DCinemaToday
Only the news that really counts - plus all the contacts with all the companies
SMPTE
Spanning all the Motion Picture and Television Technologies
ISDCF
An InterSociety Group Dealing with Digital Cinema
 
The European Digital Cinema Forum
 
National Association of Theater Owners
Flash Version Check
UPGRADE YOUR FLASH NOW~!

RSS Feed; Entire Journal

DCinemaTools | Like Tangents In The Rain DCinemaTools | Like Tangents In The Rain

DCinema Events

February 2012
S M T W T F S
29 30 31 1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 1 2 3

Events Search