On the 18th of December, the German security firm SySS published a paper saying that it had found a way to "bypass the entire protection of the [FIPS 140-2 certified] USB sticks. Independent from the password in use, respective encrypted data can be reconstructed within seconds."
SySS then reported - and vendors SanDisk, Verbatim and Kingston Technology reluctantly confirmed early last week - that a number of their cryptographic standard FIPS 140-2 certified flash drives including SanDisk Cruzer Enterprise FIPS Editions CZ32 and CZ46 in 1G, 2G, 4G and 8G; the Verbatim Corporate Secure FIPS Edition in 1G, 2G, 4G and 8G; and Kingston Technology's DataTraveler Secure, DataTraveler Elite and DataTraveler Blackbox were open to this bypass technique.
Kingston said that a number of their other models (DataTraveler Locker DataTraveler Locker+, DataTraveler Vault, DataTraveler Vault, Privacy Edition, DataTraveler Elite and the DataTraveler Secure) were not affected, however.
According to this story yesterday in Government Computing News (GCN), the National Institute of Standards and Technology (NIST) is now looking into the issue, and has said in a press release that, "From our initial analysis, it appears that the software authorizing decryption, rather than the cryptographic module certified by NIST, is the source of this vulnerability. Nevertheless, we are actively investigating whether any changes in the NIST certification process should be made in light of this issue."
All three vendors have issued software updates to address the problem, GCN reports.
Robert N. Charette is a Contributing Editor to IEEE Spectrum and an acknowledged international authority on information technology and systems risk management. A self-described “risk ecologist,” he is interested in the intersections of business, political, technological, and societal risks. Charette is an award-winning author of multiple books and numerous articles on the subjects of risk management, project and program management, innovation, and entrepreneurship. A Life Senior Member of the IEEE, Charette was a recipient of the IEEE Computer Society’s Golden Core Award in 2008.