FIPS 140-2 Cerified Flash Drives Have Security Flaw

On the 18th of December, the German security firm SySS published a paper saying that it had found a way to "bypass the entire protection of the [FIPS 140-2 certified] USB sticks. Independent from the password in use, respective encrypted data can be reconstructed within seconds."

SySS then reported - and vendors SanDisk, Verbatim and Kingston Technology reluctantly confirmed early last week - that a number of their cryptographic standard FIPS 140-2 certified flash drives including SanDisk Cruzer Enterprise FIPS Editions CZ32 and CZ46 in 1G, 2G, 4G and 8G; the Verbatim Corporate Secure FIPS Edition in 1G, 2G, 4G and 8G; and Kingston Technology's DataTraveler Secure, DataTraveler Elite and DataTraveler Blackbox were open to this bypass technique.

Kingston said that a number of their other models (DataTraveler Locker DataTraveler Locker+, DataTraveler Vault, DataTraveler Vault, Privacy Edition, DataTraveler Elite and the DataTraveler Secure) were not affected, however.

According to this story yesterday in Government Computing News (GCN), the National Institute of Standards and Technology (NIST) is now looking into the issue, and has said in a press release that, "From our initial analysis, it appears that the software authorizing decryption, rather than the cryptographic module certified by NIST, is the source of this vulnerability. Nevertheless, we are actively investigating whether any changes in the NIST certification process should be made in light of this issue."

All three vendors have issued software updates to address the problem, GCN reports.

Advertisement

Risk Factor

IEEE Spectrum's risk analysis blog, featuring daily news, updates and analysis on computing and IT projects, software and systems failures, successes and innovations, security threats, and more.

Contributor
Willie D. Jones
 
Advertisement