A team of three security researchers are debunking the myths surrounding the popular Western Digital My Passport hard drives, which are advertised as providing on-the-fly encryption for all stored data.
For a few years, people who wanted privacy and security often chose the Western Digital My Passport as their portable hard drive. This device is not only small, good-looking, and full of features, but it also provides built-in security features, both in its software and hardware.
Some of its two most important features were the fact that users could protect their hard drives using a password and that all data written to those drives was encrypted in real time.
According to a recent investigation into the inner workings of various My Passport, the hard drives appear to contain a number of security vulnerabilities that allow attackers to bypass both the built-in encryption and password-based authentication system.
As the researchers explain, some of the models out of the six analyzed easily gave up after a simple brute-force attack, thus allowing the attacker to break their encryption.
Furthermore, password control could also be easily bypassed, allowing any attacker to install fully functional backdoors for infected devices.
As the scenario worsens, all WD models analyzed allowed attackers to take over the firmware update mechanism via the "evil maid" and "badUSB" attacks and install their own malicious code.
“The weakest model from a security perspective is the INIC-3 608 bridge,” the researchers say. “The chip does not support hardware accelerated AES encryption. […] A single command sent to the device will reveal the KEK [Key-Encrypting Key], even if the drive is in a locked state.”
For its part, Western Digital says it is already looking into some security issues.

