HomeSecurityMicrosoft's Bitlocker is compromised due to poor SSD encryption

Microsoft's Bitlocker is compromised due to poor SSD encryption

SSDInadequate computer security can sometimes have bad consequences, researchers from the Netherlands have discovered. They first found that there were vulnerabilities in the built-in encryption of several SSD models from Samsung and Crucial, which allowed them to access data without a password. Then, things got even worse, as they found that Windows 10 Bitlocker has SSD encryption enabled by default, when it is available. This means that if you had one of these SSDs and were using Bitlocker, attackers with access to your computer could easily access your files.

The drives affected by the issues are the Crucial MX100, MX200, and MX300, as well as Samsung’s T3 and T5 portable SSDs and 840 EVO and 850 EV internal SATA SSDs. To gain access, the researchers first reversed their firmware and found what they call a “pattern of critical issues.” A drive could be unlocked with “almost any password,” the researchers said, as the validation system didn’t work. They also used a blank string as the password, meaning you could decrypt it by simply pressing the “Enter” key.

The problem is serious, and Microsoft has made it even worse. Bitlocker, which lets you encrypt your files in Windows 10, defaults to built-in disk encryption, not its own system. This means that if you decide to use Bitlocker for extra security and you own one of the aforementioned drives, you essentially have zero protection.

Researchers believe Microsoft should be more careful, as reports of bad hard drive encryption systems have been circulating for years.

The Dutch researchers also urged drive manufacturers to use open source encryption systems, such as VeraCrypt, which are very effective. Furthermore, modern CPUs are programmed to decode the standard AES-NI encryption, so there is no speed advantage to using an SSD system.

The researchers gave manufacturers a six-month grace period, and both have issued software patches to address the reported flaws where possible. Samsung has advised users to install third-party encryption software rather than its own firmware or Bitlocker. The researchers are also asking organizations and consumers who have used Bitlocker or SSD encryption to take appropriate action.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS