Comments on: Intel’s and Sandforce’s AES-128 encryption is useful, but not for what you think https://dfarq.homeip.net/intels-and-sandforces-aes-128-encryption-is-useful-but-not-for-what-you-think/?utm_source=rss&utm_medium=rss&utm_campaign=intels-and-sandforces-aes-128-encryption-is-useful-but-not-for-what-you-think David L. Farquhar on technology old and new, computer security, and more Thu, 03 Apr 2025 12:31:07 +0000 hourly 1 By: Pit https://dfarq.homeip.net/intels-and-sandforces-aes-128-encryption-is-useful-but-not-for-what-you-think/#comment-6725 Mon, 04 Apr 2011 17:13:41 +0000 https://dfarq.homeip.net/?p=3260#comment-6725 The thing is: the way to deliver password to the drive through ATA pass is not wrong per se. But the implementation on todays hardware is fundamentally skewed. Look at so called: Vendor Specific ATA Commands. There are special sets of commands (outside ATA spec or undocumented modified versions of offcial ATA set) unique to each manufacturer for low level diagnostics and maintenance which are successfully reverse engineered (using dedicated terminals) and used by hackers to get ata passwords (Master and User) or even dumping sector by sector from ATA security locked device. And the manufacturers put them on their hardware. They are responsible for making ATA password system full of holes. Maybe by their ignorance, maybe on purpose. It doesn’t matter. The fact is that these holes are by design and this shady business is being run for years (generations of devices) and without any reactions from critics. But this system could be done right. And not even with much higher price! Now it is a complete disaster security wise. As you stated: nobody cares about it anymore.
Intel is not responding to the requests for clarifications concerning his implementation. The official documents are mostly marketing BS. I wonder if they manage to get any security certification(s). Do not trust their implementation until that happen.

]]>