Feeds.4Sysops
Security Flaws Found in TCG Opal2 Hardware-Encrypted SSDs
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Researchers tested 38 hardware-encrypted SSDs compliant with the TCG Opal2 standard and discovered significant vulnerabilities. Issues included predictable random number generation, flawed PSID reset tokens, and a reused tweak value on some Lenovo OEM drives. These flaws compromise the integrity of the encryption, leading to potential data exposure. While Micron addressed one firmware issue, many other vulnerabilities remain unpatched and unsupported. Millions of laptops and workstations rely on these drives for encryption, raising concerns about widespread security risks. The findings highlight the need for verification rather than blind trust in hardware encryption features.
Key Points: • 38 SSDs tested revealed critical vulnerabilities in hardware encryption. • Flaws included predictable random numbers and flawed PSID reset tokens. • Many vulnerabilities remain unpatched, affecting millions of devices.