Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

SSD Hardware and BitLocker Encryption

By Sean Lawless on November 19, 2018
Email this postTweet this postLike this postShare this post on LinkedIn

Security researchers at Radboud University in the Netherlands have discovered a flaw in several manufacturers’ solid state hard drive firmware that can be exploited to read data from self-encrypting drives (SED). The researchers published their findings in a paper on November 5th. The authors identified several methods they were able to use to bypass hardware based full disk encryption on drives from Crucial and Samsung. On November 6th, Microsoft issued a Security Advisory detailing a vulnerability as it relates to use of Microsoft’s BitLocker encryption scheme which is included with its Windows operating system.

When using Microsoft’s BitLocker encryption Windows will leverage the hard drive’s hardware-based encryption as opposed to its own software-based BitLocker Drive Encryption. This leaves the drive vulnerable to the exploit identified by the researchers at Radboud. Several articles have documented that BitLocker’s default behavior of relying on the SED only pertains to Windows 10, however, Microsoft’s Security Advisory specifies several versions of Windows are affected.

Microsoft recommends changing the encryption method from hardware-based encryption to software-based BitLocker Drive Encryption. To change encryption schemes the drive must be unencrypted and re-encrypted. Microsoft outlines the necessary steps using Group Policy in their Security Advisory. They also provide the syntax for a command that can be used to determine the type of encryption currently being used on the computer.

Photo of Sean Lawless Sean Lawless

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries…

Sean is Robinson+Cole’s Infrastructure & Security Manager, a member of the firm’s Data Privacy + Cybersecurity Team, and a non-attorney contributor to the Data Privacy + Cybersecurity Insider blog. He has spent more than a decade helping professional services organizations in various industries, develop and implement practical information security programs based on industry standard frameworks. Sean holds a Bachelor of Science degree from the University of Connecticut and is a member of several cybersecurity professional organizations.

Read more about Sean LawlessEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo