3 ms·
You're spot-on with the weakness. The specific reason it is mentioned is because their recommendation is that the encryption key should be derived from both th
by asherkin 11y ago
You're spot-on with the weakness.
The specific reason it is mentioned is because their recommendation is that the encryption key should be derived from both the input numbers and a secret baked into the hardware - which would then require brute-forcing the entire key rather than just the input numbers if the attacker only had the data on the drive.
With properly assembled hardware (yay, epoxy) protecting the crypto chip, extracting that key could be made very difficult, protecting against the attacker having the enclosure as well (the secure chip would need to enforce the rate limit itself).