Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
Several flash drive manufacturers recently issued warnings about a flaw which could allow an attacker to access encrypted data on a supposedly secure USB drive. Secure flash drives utilize 256-bit AES hardware-based encryption to protect sensitive information. The vulnerability, which affects certain secure Kingston, SanDisk and Verbatim flash drives, is present in the mechanism used to verify an individual's password.“A skilled person with the proper tools and physical access to the drives may be able to gain unauthorized access to data contained on [certain] Kingston Secure USB drives,” Kingston said in an advisory on its website. The flaw is not present in the hardware or firmware in affected devices but is part of the drive's application on a user's computer, according to SanDisk's alert, which includes an update to address the issue. Verbatim issued a similar advisory, which also directs users to a site where they can download an update. Individuals should contact Kingston technology support to receive an update, the company said.Affected devices include:
“Frankly, it's pretty shameful that these so-called secure drives should be vulnerable to this kind of attack,” Graham Cluley, senior technology consultant at security vendor Sophos, said in a blog post Tuesday. “Clearly, if someone inside your organization, or an attacker…was interested in reading confidential information held on an encrypted USB stick, then this would be a very attractive method of attack (if they could gain physical access to the device)."See original article on scmagazineuk.com
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.