All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic  [ 45 posts ]  Go to page Previous  1, 2, 3
Author Message
 Post subject: Re: Security theater (backdoor ATA Master Password)
PostPosted: June 4th, 2010, 9:09 
Offline

Joined: August 20th, 2009, 18:16
Posts: 19
Location: Illinois, USA
guru wrote:
AFAIK

The ATA Master and User password are kept in a seperate negative LBA/Cylinder area on the drive (So usual lab attack methods to get at this is possible)


Do you base this on prior experience with non-FDE drives? Or have you read a source that asserts this for Seagate's FDE drives?

Even if Seagate stores the ATA passwords on-disk, since all data on the disk always AES-128 encrypted, do you think that Seagate would store any password on disk in an unencrypted state? If it's AES-128 encrypted, do you think it would still be possible to get at the password?

Quote:
="guru"]
One worrying thing about warranty returns that I did find from the manual :-

"Important: When returning a drive for warranty support, if possible, you should provide the valid ATA Master password, or return the drive in the Security Erased state with the User Data Area accessible"

If not they cannot process your warranty claim. I wonder how many people will provide their passwords ?


Is this text available online? What is the actual text that says they won't process your warranty claim unless those conditions are met?

Thanks,
tinkerdude


Top
 Profile  
 
 Post subject: Re: Security theater (backdoor ATA Master Password)
PostPosted: June 5th, 2010, 2:45 
Offline
User avatar

Joined: May 5th, 2004, 20:06
Posts: 2782
Location: England
Ref to warranty http://www.seagate.com/staticfiles/supp ... 71983b.pdf

Page 15 :-

Important: When returning a drive for warranty support, if possible, you should provide the valid ATA Master password, or return the drive in the Security Erased state with the User Data Area accessible.
If these recommendations are not followed, Seagate cannot access the drive to perform failure analysis to verify your warranty claim.
To determine the warranty for a specific drive, use a web browser to access the
following web page: support.seagate.com/customer/warranty_validation.jsp
You will be asked to provide the drive serial number, model number (or part number) and country of purchase. After submitting this information, the system will display the warranty information for your drive..

---------------------------------------------------------------------------------------------------------------

_________________
All went well until I plugged the drive in.


Top
 Profile  
 
 Post subject: Re: Security theater (backdoor ATA Master Password)
PostPosted: June 5th, 2010, 9:50 
Offline

Joined: August 20th, 2009, 18:16
Posts: 19
Location: Illinois, USA
guru wrote:
Ref to warranty http://www.seagate.com/staticfiles/supp ... 71983b.pdf

Page 15 :-

Important: When returning a drive for warranty support, if possible, you should provide the valid ATA Master password, or return the drive in the Security Erased state with the User Data Area accessible.
If these recommendations are not followed, Seagate cannot access the drive to perform failure analysis to verify your warranty claim.
To determine the warranty for a specific drive, use a web browser to access the
following web page: support.seagate.com/customer/warranty_validation.jsp
You will be asked to provide the drive serial number, model number (or part number) and country of purchase. After submitting this information, the system will display the warranty information for your drive..

---------------------------------------------------------------------------------------------------------------


That does seem over the top to me, or worded badly or both. In fact, the statement:

"If these recommendations are not followed, Seagate cannot access the drive..."

is technically just flat out false if taken literally (if the drive is not locked in the first place, there shouldn't be an issue).

Besides, almost all the time, consumers will have absolutely no idea what an ATA Master Password or what Security Erase is.

Seems like a screwup to me. the Momentus 5400 FDE.4 manual abandons that clause, though it's present in all prior 5400 manuals - FDE.3, FDE.2 and FDE. So it seems somebody finally realized it was ridiculous and snipped it (though the 7200 FDE.2 manual you cite above was apparently published *after* the 5400 FDE.4 manual - Sep 2009 vs July 2009).

It's tough to imagine them sticking literally to this clause, but I don't have much to go on.

For reference, Momentus manuals are at:
http://www.seagate.com/ww/v/index.jsp?l ... 48090aRCRD


Top
 Profile  
 
 Post subject: Re: Security theater (backdoor ATA Master Password)
PostPosted: July 5th, 2010, 11:44 
Offline

Joined: July 5th, 2010, 11:32
Posts: 1
Location: Hong Kong
I came across this thread while researching how FDE works on my new Dell Latitude E6510. I am not an HDD Guru (but I am generally tech-savvy) but I am having some trouble distinguishing between ATA Passwords and Trusted Drives. I mean, I know that they are not the same, but don't really understand how.

My Dell came with the Seagate ST9250414ASG drive and the Wave Embassy Security Center for Dell. I have not enabled any ATA passwords, but I have initialised the "Trusted Drive" feature from the Embassy Security Center and now when I boot I get a prompt from the Wave Pre-Boot screen asking for the username and password I set up. My main concern is losing my laptop, and I want to know:

1) Without any ATA user password set (and I suppose the default ATA master password set), but with the Trusted Drive feature enabled and with the Wave Pre-Boot prompt showing, can anyone with physical access to my laptop (in power off state) get any data off my drive using the ATA master password?

2) Can someone explain more clearly, are the Trusted Drive feature and ATA passwords linked in any way or are they completely independent?

3) The Seagate docs seem to suggest that the Trusted Drive feature and ATA passwords are mutually exclusive. However, the Dell BIOS allows me to set an ATA password, though I have not tried to do so. What's up with this?

4) Rhetorical question: WHY would Seagate print the master password on the drive label? :? :? :?

Thanks in advance for your help and any information you can provide. This whole thing is hugely confusing with neither Dell, nor Seagate, nor Wave really providing any clear answers.


Top
 Profile  
 
 Post subject: Re: Security theater (backdoor ATA Master Password)
PostPosted: July 5th, 2010, 14:39 
Offline
User avatar

Joined: September 29th, 2005, 12:02
Posts: 3564
Location: Chicago
aebrahim wrote:
1) Without any ATA user password set (and I suppose the default ATA master password set), but with the Trusted Drive feature enabled and with the Wave Pre-Boot prompt showing, can anyone with physical access to my laptop (in power off state) get any data off my drive using the ATA master password?

no

aebrahim wrote:
2) Can someone explain more clearly, are the Trusted Drive feature and ATA passwords linked in any way or are they completely independent?

They are independent

aebrahim wrote:
3) The Seagate docs seem to suggest that the Trusted Drive feature and ATA passwords are mutually exclusive. However, the Dell BIOS allows me to set an ATA password, though I have not tried to do so. What's up with this?

Well, there is only one truth
Some people tended to believe manuals, some more believe ones' own eyes. It is up to you

aebrahim wrote:
4) Rhetorical question: WHY would Seagate print the master password on the drive label? :? :? :?

Because FDE drives are always encrypted the encryption Master key supposed to be stored in hashed/encrypted way even before end user get such a drive, so when end user wants to install Trusted feature password the Master Key supposed to be decrypted first from the area where it's stored, default decryption password is the printed "Master password" on a drive's label. Once Trusted feature user password is installed printed password has no value anylonger (for Trusted feature).

_________________
SAN, NAS, RAID, Server, and HDD Data Recovery.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 45 posts ]  Go to page Previous  1, 2, 3

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 41 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group