SandForce SF-2000 Controllers Limited to 128-Bit Encryption

Latest Videos FromTom's Hardware
  • sixdegree
    It's always good to see companies address their costumers' dissatisfaction with such great care. I hope more vendors follow Intel and Kingston step.
    Reply
  • A Bad Day
    Well, at least they're admitting the problem and offering services. I'd wish more companies would follow Intel's and Kingston's step.
    Reply
  • josejones
    Is this an issue with Mushkin SSD's too?
    Reply
  • This is not an issue at all. You shouldn't be using AES-256 anyway (http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf and http://www.schneier.com/blog/archives/2009/07/another_new_aes.html). This is now 3 years old.
    The problem lies with the key scheduling algorithm, which affects AES-256, but not AES-128.
    It's simply badly designed. It looked OK at first, but it's 3 years past it's sell-by date.
    As a result of the design error, AES-128 has a best-known attack complexity of 2^128, but AES-256 has an attack complexity of only 2^119.
    Both are safe from known brute-forcing today, but AES-256 has a *smaller* margin of safety than AES-128.
    Reply
  • jdamon113
    Boring
    Reply
  • rantoc
    A Bad DayWell, at least they're admitting the problem and offering services. I'd wish more companies would follow Intel's and Kingston's step.
    Agreed, at least they don't try to sweep the problem under the rug and provide a comedian solution for the issues once the truth got out. Intel handle hardware issues nicely, this and early SB were both handled nicely and show that they care about their customers... unlike some other company's, no need to mention them. Some shady company's get caught over and over while gambling with quality and worst of all is how their fanboy(esses) remain loyal to the company that pisses on them is well beyond me.
    Reply
  • applegetsmelaid
    Only 128-bit encryption? Now I feel like a sucker.
    Reply
  • eddieroolz
    Let the firmware updates flow in!
    Reply
  • freggo
    Nice for them to address the issue and not trying to sweep it under the rog. But I think it is fair to say that for most of us it does not matter. Not exactly Bond style secrets on our drives; unless you include the various future 'Bond Girls' of course :-)

    Reply
  • dragonsqrrl
    CryptoGeekThis is not an issue at all. You shouldn't be using AES-256 anyway (http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf and http://www.schneier.com/blog/archi aes.html). This is now 3 years old.The problem lies with the key scheduling algorithm, which affects AES-256, but not AES-128.It's simply badly designed. It looked OK at first, but it's 3 years past it's sell-by date.As a result of the design error, AES-128 has a best-known attack complexity of 2^128, but AES-256 has an attack complexity of only 2^119.Both are safe from known brute-forcing today, but AES-256 has a *smaller* margin of safety than AES-128....bad link dude.
    Reply