FIPS 140-2 Level 2 Certified USB Memory Stick Cracked

January 8th, 2010 admin

Kind of a dumb mistake: The USB drives in question encrypt the stored data via the practically uncrackable AES 256-bit hardware encryption system. Therefore, the main point of attack for accessing the plain text data stored on the drive is the password entry mechanism. When analysing the relevant Windows program, the SySS security experts found a rather blatant flaw that…


Originally posted on Schneier

 
  Related Posts
Microsoft warns of Windows 7 security hole
Microsoft warns of Windows 7 security hole
Microsoft has confirmed reports of a security flaw in its Windows operating system that hackers could use to temporarily destabilize Windows 7 PCs. The software giant also acknowledged that blueprints for exploiting the flaw are now available online. At issue is a so-called “denial-of-service” vulnerability in the component of Windows... 
Secret Questions
Interesting research: Analysing our data for security, though, shows that essentially all human-generated names provide poor resistance to guessing. For an attacker looking to make three guesses per personal knowledge question (for example, because this triggers an account lock-down), none of the name distributions we looked at gave more than 8 bits... 
Microsoft plugs 15 holes in Windows, Office
Microsoft plugs 15 holes in Windows, Office
Microsoft on Tuesday released software updates to fix at least 15 security flaws in Windows, Windows Server and Microsoft Office. One of the patches addresses a flaw so serious that users could find their Windows PCs compromised just by visiting booby-trapped Web sites. Richie Lai, director of vulnerability research for patch management firm Qualys,... 
Eating a Flash Drive
How not to destroy evidence: In a bold and bizarre attempt to destroy evidence seized during a federal raid, a New York City man grabbed a flash drive and swallowed the data storage device while in the custody of Secret Service agents, records show. The article wasn’t explicit about this — odd, as it’s the main question any reader... 
Privacy Violations by Facebook Employees
I don’t know if this is real, but it seems perfectly reasonable that all of Facebook is stored in a huge database that someone with the proper permissions can access and modify. And it also makes sense that developers and others would need the ability to assume anyone’s identity. Rumpus: You’ve previously mentioned a master password,... 
Hackers exploit Adobe Reader flaw via comic strip syndicate
Hackers exploit Adobe Reader flaw via comic strip syndicate
Hackers broke into an online comic strip syndication service Thursday, embedding malicious code that sought to exploit a newly discovered security flaw in Adobe Reader and Acrobat, Security Fix has learned. On Monday, Adobe Systems Inc. said it was investigating reports that criminals were attacking Internet users via a previously unknown security... 
SCADA System’s Hard-Coded Password Circulated Online for Years
SCADA System’s Hard-Coded Password Circulated Online for Years
A sophisticated new piece of malware that targets command-and-control software installed in critical infrastructures uses a known default password that the software maker hard-coded into its system. The password has been available online since at least 2008, when it was posted to product forums in Germany and Russia. The password protects the... 
Do you sign your code?
The lab has a survey request. As Windows 7 gains market share, code signing is becoming more important for software developers. A byproduct of more clean code being signed is that malware authors now have greater incentives to get their stuff signed in order to prevent it from being easily distinguished from legitimate software. With this in mind,... 
SCADA System’s Hardcoded Password Was Circulating Online For Years
SCADA System’s Hardcoded Password Was Circulating Online For Years
A sophisticated new piece of malware that targets command and control software installed in critical infrastructures uses a known default password that the software maker hard coded into its system and that has been available online since at least 2008 when it was posted to product forums in Germany and Russia. The password protects the database... 
Quantum Cryptography Cracked
Impressive: This presentation will show the first experimental implementation of an eavesdropper for quantum cryptosystem. Although quantum cryptography has been proven unconditionally secure, by exploiting physical imperfections (detector vulnerability) we have successfully built an intercept-resend attack and demonstrated eavesdropping under realistic... 
  Related Tweets from Twitter

There was an error processing the Feed, if this is your page, please check the information provided in your profile.

  Related News from Digg
No comments yet.
You must be logged in to post a comment.
TOP