5 ms·
If you use a mode like CTR you just flip the corresponding ciphertext bit. As for CBC there are padding-oracle attacks.
by snakeanus 9y ago
If you use a mode like CTR you just flip the corresponding ciphertext bit. As for CBC there are padding-oracle attacks.
- tedunangst 9y agoDo SSDs use CTR mode? How does one perform a padding oracle against an SSD? I feel like we're pretty far away from the relevant context, which is users corrupting data on an SSD.
- heheocoenev 9y agoXTS mode for block storage. Can't be CBC or CTR, where would you Store the IV or counter/nonce?
- Scaevolus 9y agoYou could store it in the block metadata, which SSD flash translation layers already use for wear-leveling purposes.
- tedunangst 9y agoThis sounds more like random speculation than informed commentary.
- rlanday 9y agoDoes the SSD let you read the raw ciphertext to perform that attack? Or does it only expose the decrypted data?
- dmitrygr 9y agoThere is no documented way to read cyphertext. I am SURE some manufacturer specific commands exist. But they will likely be undocumented, model-specific, and may be locked away behind a manufacturer key