• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.
  • The forums have been upgraded with support for dark mode. By default it will follow the setting on your system/browser. You may override it by scrolling to the end of the page and clicking the gears icon.

SandForce 256-bit AES Encryption Limited to 128-bit, Fix En Route

btarunr

Editor & Senior Moderator
Staff member
Joined
Oct 9, 2007
Messages
47,695 (7.42/day)
Location
Dublin, Ireland
System Name RBMK-1000
Processor AMD Ryzen 7 5700G
Motherboard Gigabyte B550 AORUS Elite V2
Cooling DeepCool Gammax L240 V2
Memory 2x 16GB DDR4-3200
Video Card(s) Galax RTX 4070 Ti EX
Storage Samsung 990 1TB
Display(s) BenQ 1440p 60 Hz 27-inch
Case Corsair Carbide 100R
Audio Device(s) ASUS SupremeFX S1220A
Power Supply Cooler Master MWE Gold 650W
Mouse ASUS ROG Strix Impact
Keyboard Gamdias Hermes E2
Software Windows 11 Pro
Post acquisition, an audit by LSI reportedly discovered that the 256-bit AES native data encryption by SandForce SSD processors never was, and that the feature really just encrypted data with 128-bit AES. The problem has been resolved and a fix is in the works. LSI will share the fix with all SSD manufacturers with SandForce-based products, who could then release firmware updates to end-users.



View at TechPowerUp Main Site
 
does this open them up to lawsuits?
 
smells like a destructive firmware update will be coming down the pipe for whoever wants this feature, i don't see how they can change the cypher length without maintaining the data...
 
AES-256 as an encryption standard is broken. It's actually slightly less secure than AES-128 (though still secure enough that it's basically impossible to brute force). The fact that it took nearly two years for anyone to realize that this feature has never worked is a testament to how irrelevant it is.
 
Who cares except if you are using the security. So that means that 99% of users don't need it.

With that being said, watch out, here come the lawsuits from idiots who don't even know the difference.
 
does this open them up to lawsuits?
Yes, but they're being proactive about fixing it and, unless there's some documents out there that SandForce knew about it and didn't do anything, the case would be weak against them.


smells like a destructive firmware update will be coming down the pipe for whoever wants this feature, i don't see how they can change the cypher length without maintaining the data...
Flag the drive as 128-bit encrypted and require format to change to 256-bit encrypted.
 
Flag the drive as 128-bit encrypted and require format to change to 256-bit encrypted.

They really don't even need to do that. They could just release a utility that decrypts the data and re-encrypts it with a 256 bit cypher and writes it back to the drive.
 
They really don't even need to do that. They could just release a utility that decrypts the data and re-encrypts it with a 256 bit cypher and writes it back to the drive.

that would waste a ton of erase cycles on your flash, there's no chance in hell.

it will be a flash upgrade->secure erase firmware, but as some of you said, completely irrelevant
 
Back
Top