USB drive recommandation

Any disk drive using whatever storage technology must be viewed with suspicion in respect of the robustness of the encryption that it performs - because there is no way to audit whether it is actually secure.

There is no way to audit whether

  • its key generation is sufficiently random
  • its encryption algorithm is what it claims
  • it has a back door for the encryption key
  • it has a timing attack against the encryption key
  • it has any other unspecified bugs or back doors
  • etc.

It may also be difficult or impossible to update the drive’s firmware if any firmware defect does come to light - or simply because the encryption algorithm ceases to be adequate e.g. firmware update program only available in closed source and only for Microsoft Windows, or firmware update not available at all (drive is end-of-life for support).

As such, I believe that, in general, open source advocates would prefer to have encryption in the operating system software, where it can be audited and fixed, even if that leads to lower throughput.

Of course I don’t speak for all open source advocates. Just one of them. :slight_smile:

2 Likes