3 ms·
Some of Seagate's drives require signed firmware. http://www.seagate.com/www-content/product-content/savvio-fam/savvio-10k/savvio-10k-6/en-us/docs/100699181c.p
by deadfece 12y ago
Some of Seagate's drives require signed firmware.
http://www.seagate.com/www-content/product-content/savvio-fam/savvio-10k/savvio-10k-6/en-us/docs/100699181c.pdf http://www.seagate.com/www-content/product-content/savvio-fa...
8.7 AUTHENTICATED FIRMWARE DOWNLOAD
In addition to providing a locking mechanism to prevent unwanted firmware download attempts, the drive also only accepts
download files which have been cryptographically signed by the appropriate Seagate Design Center.
Three conditions must be met before the drive will allow the download operation:
1. The download must be an SED file. A standard (base) drive (non-SED) file will be rejected.
2. The download file must be signed and authenticated.
3. As with a non-SED drive, the download file must pass the acceptance criteria for the drive. For example it must be applicable
to the correct drive model, and have compatible revision and customer status.
- elchief 12y agoNext week on Der Spiegel: NSA stole drive manufacturers' private keys.
- pstrateman 12y ago"stole"
- cdr 12y agoYes, stole. As repeatedly evidenced - most recently with the Gemalto documents - the NSA far prefers to obtain keys surreptitiously than to go through the trouble of legally compelling corporations to provide them.
- Guvante 12y agoNo corporation would continue to use a private key they divulged to outside sources, there is no reason to other than a minor syncing headache.
- cnvogel 12y agoLooking at the "Lavabit" incident, there's obviously some legal framework that allows a government entity in the USA to force a company to surrender a copy of the private key used for email encryption. If said company would change the private key, obviously the same legal framework can be used to get this new key, in turn. So it's fruitless. Of course, if it's an "inofficial" leak, a revocation and renewal of keys makes sense.
- chinathrow 12y agoIssuing an NSL is not really "trouble" for them. As we have seen now countless of times...
- qb45 12y agoThe fact that you have seen it is the trouble.
- jacquesm 12y agoNote the 'N'stands for 'National' and Gemalto is not American.
- chinathrow 12y agoSo? Listed company, locations in TX. http://www.gemalto.com/companyinfo/offices-locator http://www.gemalto.com/companyinfo/offices-locator
- magila 12y agoSigned firmware is generally only featured on SAS drives. I image the NSA is much more interested in infecting the more common SATA drives which have no such protection.
- DrStalker 12y agoI imagine they also have the capability to sign firmware if they need to.