11-05-2018 02:29 PM
11-05-2018 02:29 PM
A paper has been published that details how to bypass hardware encryption on Crucial MX100, MX200 and MX300 SSDs: https://www.ru.nl/publish/pages/909275/draft-paper_1.pdf
Can we expect a firmware fix for this?
11-05-2018 03:07 PM
11-05-2018 03:07 PM
The ZDNet article says the vulnerabilities were found in April, and "both SSD vendors whose products they've tested... have released firmware updates to address the reported flaws", but it would be good to get a clear answer from the horse's mouth.
I'd very much like to know if it affects the MX500 as well, since the researchers didn't look at current drives. I specifically bought a few MX500s due to the SED capability, so I'll be quite grumpy if I have to go back to software encryption and take the performance hit.
11-06-2018 01:36 AM - edited 11-06-2018 01:37 AM
11-06-2018 01:36 AM - edited 11-06-2018 01:37 AM
@hoodoo wrote:
I'd very much like to know if it affects the MX500 as well
Oh my... This news is not good at all.
I would like to know if it affects older models M500 and M550 as well. I use this feature on those drives and it is very likely they are affected too.
Firmware update notes say:
Firmware revisions MU05 for the MX200 (all form factors) and MU03 for the MX100 (all form factors)
Release Date: 5/25/2018 (both updates)
There is no such information for MX300!
11-06-2018
01:07 PM
- last edited on
11-12-2018
01:23 PM
by
Crucial_Guru
11-06-2018
01:07 PM
- last edited on
11-12-2018
01:23 PM
by
Crucial_Guru
Micron is aware of the Radboud University researchers’ report describing a potential security vulnerability in its Crucial MX100, MX200 and MX300 products. This vulnerability can only be exploited by an individual who is able to remove the drive from the system, has the relevant equipment, as well as knowledge of the drive’s electrical and firmware functionality.
Micron has developed firmware patches to address vulnerabilities in the MX100, MX200 and MX300 products. The MX100 and MX200 firmware updates are available today on crucial.com. The ETA for the MX300 firmware is planned for November 13, 2018.
Micron is committed to conducting business with integrity and accountability, which includes delivering best-in-class product quality, security, and customer support.
11-06-2018 03:26 PM
11-06-2018 03:26 PM
@Crucial_AgentC wrote:Micron has developed firmware patches to address vulnerabilities in the MX100, MX200 and MX300 products.
@Hi @Crucial_AgentC, thank you for your comment. These are serious vulnerabilities.
Please can you confirm which existing (or upcoming) firmware versions contain the relevant fixes for:
Can you please also confirm whether or not the MX500 is affected by any of the vulnerabilities highlighted in the Radboud research (as it was not included in their analysis), and if so, the relevant firmware version for that model as well?
Thank you.
11-06-2018 11:38 PM
11-06-2018 11:38 PM
@djcater wrote:
Can you please also confirm whether or not the MX500 is affected by any of the vulnerabilities highlighted in the Radboud research (as it was not included in their analysis), and if so, the relevant firmware version for that model as well?
The MX500 isn't affected.
11-07-2018 02:50 PM
11-07-2018 02:50 PM
@targetbsp wrote:The MX500 isn't affected.
@Thanks for your comment @targetbsp.
How do you know that the MX500 isn't affected please?
11-07-2018 03:44 PM
11-07-2018 03:44 PM
@djcater wrote:
@targetbsp wrote:
The MX500 isn't affected.
@Thanks for your comment @targetbsp.
How do you know that the MX500 isn't affected please?
Bogdan asked in the private forum for super users ( https://forums.crucial.com/t5/Forum-Rules-Guidelines/Crucial-Super-User-Program/td-p/180442 ) and they replied that it is unaffected. It uses an entirely different brand of drive controller to the previous MX drives so that may be why?
11-08-2018 05:29 AM
11-08-2018 05:29 AM
11-08-2018 05:35 AM
11-08-2018 05:35 AM
Here is the link - http://www.crucial.com/usa/en/support-ssd?cm_re=top-nav-_-flyout-support-_-us-support-product-suppor...
You can also update the firmware with Crucial Storage Executive - http://www.crucial.com/usa/en/support-storage-executive