Self-Wiping Hard Drives From Toshiba
Orome1 writes "Toshiba announced a family of self-encrypting hard disk drives engineered to automatically invalidate protected data when connected to an unknown host. Data invalidation attributes can be set for multiple data ranges, enabling targeted data in the drive to be rendered indecipherable by command, on power cycle, or on host authentication error."
...is going to love these.
Sounds too error prone for me, thanks.
I'll stick with TrueCrypt.
Then I don't have to worry about trying to move the HDD between computers.
...could possibly go wrong?
There's no -1 for "I don't get it."
In Soviet Russia drive wipes you.
I mean, of course they wouldnt offer a backdoor solution to law enforcement agencies, nah.
A Deskstar drive could clean up after itself after sh!tting the bed...
This one is way cooler.
It actually releases acid into the hard-drive platters:
http://www.deadondemand.com/products/enhancedhdd
If they've implemented this properly then you could send a remote command wirelessly that would wipe the hard-drive.
I'm pretty sure this is a forensic investigators nightmare...
Microsoft developed fool-proof methods to trash entire hard drives long ago...
Damn_registrars has no butt-hole. Damn_registrars has no use for a butt-hole.
I can only imagine how many IT support types will accidentally wipe these things. How sad and hilarious this will be!
A slashdotter who didn't build his own computer is like a Jedi who didn't build his own lightsaber.
Nothing like having a ticking time bomb built right into your hardware. The first time some cosmic ray flips some bit that the drive queries to determine which host its attached to you lose all of your data. Nice. Hope you remembered your backups.
I read the internet for the articles.
For storage in devices like printers, etc., where there might be a large amount of storage to facilitate print queuing, etc., I can see how something like this coul be useful. For instance, one of the options on these devices is to self-wipe on power cycle. For companies worried about security, this might be worthwhile in their printers, where the storage itself might be for the purpose of convenience, but they would rather be safe than sorry, and data destruction is of ultimately no consequence because the source for that data is found elsewhere. That way, they can dispose of their printers in relative peace of mind, because if someone powers on the printer to see what it has on it, then poof, no more data. Or even do the "unknown host" thing, and then all you have to do is make it clear to IT that you don't want the valid host (the printer) to survive the disposal process, so if they want to play with some baseball bats in a field to the point of smashing the drive controller... then that's fine with corporate.
Self wiping drives - I had a few of those YEARS ago. They had the added feature that when they were erasing themselves,they alerted the user via a loud screeching sound.
[Insert pithy quote here]
Is Hitachi going to sue over infringement of there own self wiping tech included in the Deskstar series? It had the added benefit of wiping it randomly so even you could snoop on your data, though.
What a ... blog. Yeah. Just go to toshiba.com and read the press release from the source, instead of the cut and pasted partial version at the ... blog:
http://sdd.toshiba.com/techdocs/MKxx61GSYG_release.pdf
They claim it uses AES256.. How do you know its not some kind of simple XOR? Probably their exotic "crypto erasure scheme" which they don't discuss is simply deleting the AES256 key. Where would you store the key? How about in the partition table? How long until there's a patch to linux fdisk to read the key, or at least not overwrite it when partitioning, and then how long until someone uses a loopback crypto file system support until linux to read a drive assuming you previously know the AES256 key?
Also, those drives are small. The last time I bought a 160 GB drive was in the mid 00s. Wouldn't it be hilarious if the low capacity was because everything is stored twice, once "encrypted" for the (l)user and once unencrypted for government special access "only"?
This is just all speculation on top of speculation, yet it all seems strangely likely.
"Science flies us to the moon. Religion flies us into buildings." - Victor Stenger
...
These drives are intended for embedded application like copy machines and medical equipment. That equipment now has major security holes once it is disposed of. NOT intended for PCs or data center use. HOWEVER, for secure laptops -- they are ideal. If the laptop gets stolen, now, it is trivial to circumvent OS-enforced security and get to the data. In an environment were data backup is handled by the corporate system, if the laptop fails or is lost or the user forgets his password, you ABSOLUTELY want the data in that machine gone forever. Legitimate users of the data will get it, through the proper channels, from corporate backup.
I will create a sig when innovation restarts in the U.S.
Laptop theft is at an all time low. In unrelated news, kidnappings are on the rise.
It seems to me that, increasingly, the legislative drive is to criminalize a failure to decrypt data, rather than actually needing the data as evidence. The idea is to give the failure to decrypt data a higher penalty than the actual crime for which you are being prosecuted, thus coercing you into decrypting the data. I mean, why bother trying to crack, break, or coerce the decryption factors when you can just build a stronger case?
There are several examples of this on Slashdot.
Such a drive could just provide you with a straight path to more severe and less-defensible prosecution! The drive seems more useful in the context of preserving corporate and financial secrets from theft rather than protecting one's self from law enforcement.
And by the way, if the aforementioned legislative push bothers you as much as it does me, donate to the EFF; this shit has to stop.
A bad blocks scan at the weekend showed my year-old Toshiba hard drive has invalidated at least a hundred sectors so far.
I have had several maxtor and WD drives that wiped themselves. What's the big deal?? ;-)
That's amazing! I'm still teaching my 3-year-old how to self-wipe.
Someone wake me when they've invented something really useful, like the self-wiping ass.
If my wife goes looking on my computer, it will wipe all the p0rn from the drive and keep me out of trouble then?
Just sayin...
Self wiping drives, what could possibly go wrong? But it should also be noted that Western Digital has been making self wiping drives for years, although they are not as selective or precise about when they wipe your data.
I'm an American. I love this country and the freedoms that we used to have.
So steal/confiscate the whole machine. The only thing this does is it makes legitimate data recovery harder and may even cause unintended data loss. This is not how to do it. Amateur-crypto at best.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
hackers will love this install a malware / virus that says pay up or we will flip the bit that will kill the data.
Damn Small Linux (a boot & eject distro) booted from read only media, save your shit to an external truecrypt USB drive (hidden offsite)!
I killed da wabbit -Elmer Fudd
Consumer products that do everything - INCLUDING wiping your ass!
Self-wiping my ass!
The US simply does not manufacture items like hard drives. I am certain that law enforcement as well as government good squads in many nations will not tolerate any form of personal security including a self wiping drive. So when it comes to back doors and over rides it may well be governments other than our own that can peek into these drives at will. And I doe believe that any software or hardware that is effective in securing ones' data will usually be from a source either infiltrated or owned by government agencies.
I'm not so sure how much I would like to protest the situation as I understand that covert electronic modes have already been effective for our forces in war actions.
Nothing at all, except a motherboard failure now means you lost all your data.
Restore from backups.
ASS! Oh, wait a minute, in a way, I guess I do.
They got that capability the day the rm(1) command was compiled.
Wake me up when they've invented a self-wiping ass. I'd get in line for that.
today is spelling optional day.
Back in the 90's, I had a series of 3 Toshiba laptop drives that destroy themselves in over the course of 14 months.
Haven't bought a Toshiba product since.
I'd not trust encryption from Toshiba. Not one single *bit*.
I will NEVER EVER EVAR buy another Toshiba product as long as I live. They screwed me once, Never again. Fuck Toshiba. /posted using my Toshiba laptop. It actually works okay, but they farked me over on the "docking station" they tried to sell me. NEVER buy a laptop without making sure there is a functional docking station for it - if you want a docking station.
I urge all of those still reading this to NEVER buy anything from Toshiba again, not even a USB stick.
a self wiping ass.
-- Boycott Shell
This raises the bar in terms of effort required to safely capture the data. If the system is effective then the drive electronics have to be bypassed. That is, either transplant new control electronics into the drive frame or transplant the platters. Clearly beyond the means of the average thief and raises the cost/effort level for law enforcement. That is unless Toshiba provides a "Law Enforcement SDK".
OTOH, the sword cuts two ways: not only does the drive provide protection from unauthorized access, it also puts the data under constant risk. Any data on the drive has a veritable Damocle's sword hanging over it. The possibility of accidentally triggering the destruct mode seems very real. Think about some of the false positive issues with that used to occur with Windows licensing where a minor system change made Windows think it was on a new installation. Happened to me several times and put me on the phone to Microsoft. ie: I added ram once, going from a single 512M to 2x1G and my activation cancelled; another time I upgraded the video card. Innocent but triggered the software detector.
Reminds me of Dr. Strangelove for some reason. I have an image of Slim Pickins riding my Toshiba disk into a mushroom cloud of destruction. Sorry, off topic. Damn OCD ;->
So these drives can wipe themselves after taking a dump?
Hmm, I wonder if Microsoft is behind it. What better way to enforce 'piracy'. Some poor sap using a pirated copy of Winders finds they can't pass WGA and then the drive gets wiped. Would insure 99.9% compliance and MSFT would make Billions...
So long as it plays the mission impossible song and emits smoke while wiping I'm sold!
oh~~~~
If this PC dead, such as the mainboard or CPU or other parts, Will the data dead together