<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BlockMaster&#187; security announcement</title>
	<atom:link href="http://www.blockmastersecurity.com/tag/security-announcement/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blockmastersecurity.com</link>
	<description>Protect you portable data with SafeStick the encrypted USB flash stick. Protects stored information automatically with hardware encryption and mandatory policy password. Managed in a enterprise setting with SafeConsole.</description>
	<lastBuildDate>Wed, 25 Aug 2010 12:38:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Competing Products Contain Serious Flaw &#8211; SafeStick Not Affected</title>
		<link>http://www.blockmastersecurity.com/security/competing-products-contain-serious-flaw-safestick-not-affected/</link>
		<comments>http://www.blockmastersecurity.com/security/competing-products-contain-serious-flaw-safestick-not-affected/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 15:55:53 +0000</pubDate>
		<dc:creator>Anders Pettersson</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[security announcement]]></category>

		<guid isPermaLink="false">http://www.blockmastersecurity.com/?p=1117</guid>
		<description><![CDATA[SECURITY ANNOUNCEMENT &#8211; SAFESTICK NOT AFFECTED
A flaw has been found in competing products to SafeStick. SafeStick does not contain this flaw.
The flaw exposed by the independent penetration testing firm SySS enables any user to access the unencrypted data quickly on all shipped drives from select competitors without the required password.
BlockMaster issues this statement to clearly [...]]]></description>
			<content:encoded><![CDATA[<h2>SECURITY ANNOUNCEMENT &#8211; SAFESTICK NOT AFFECTED</h2>
<p>A flaw has been found in competing products to <a href="../../product/secure-usb/" title='SafeStick the secure USB flash drive'>SafeStick</a>.<strong> SafeStick does not contain this flaw.</strong><br />
The flaw exposed by the independent penetration testing firm SySS enables any user to access the unencrypted data quickly on all shipped drives from select competitors without the required password.</p>
<p>BlockMaster issues this statement to clearly inform customers and partners that this is<strong> not a flaw found in any version of SafeStick. </strong><strong><br />
</strong></p>
<h3><strong> This is in short how SafeStick works in this aspect (in contrary to the flawed drives) </strong></h3>
<ul>
<li>The user password is verified within the <a href="../../product/secure-usb/" title='SafeStick the secure USB flash drive'>SafeStick</a> hardware device.</li>
<li>The password set by the user is what gives access to information stored on <a href="../../product/secure-usb/" title='SafeStick the secure USB flash drive'>SafeStick</a>.</li>
</ul>
<h3><strong style="color: #777777;">SafeStick password and key procedure in more detail</strong></h3>
<ul style="color: #777777;">
<li>Password verification is performed onboard the <a href="../../product/secure-usb/" title='SafeStick the secure USB flash drive'>SafeStick</a> device.</li>
<li>The <a href="../../product/secure-usb/" title='SafeStick the secure USB flash drive'>SafeStick</a> brute-force protection is also operated within the hardware controller.</li>
<li>The password entered by the user is hashed in the <a href="../../product/secure-usb/" title='SafeStick the secure USB flash drive'>SafeStick</a> computer host software using MD5.</li>
<li>The unique password string enters the <a href="../../product/secure-usb/" title='SafeStick the secure USB flash drive'>SafeStick</a> BM9930 hardware controller through a private channel over USB.</li>
<li>The hashed password string is hashed ones more (SHA256) in firmware onboard the <a href="../../product/secure-usb/" title='SafeStick the secure USB flash drive'>SafeStick</a> device.</li>
<li>The dually hashed password is used to access the hardware encrypted cryptographic keys created with the random number generator (ANSI X9.31 RNG) onboard <a href="../../product/secure-usb/" title='SafeStick the secure USB flash drive'>SafeStick</a>.</li>
<li>The unique cryptographic keys are used to encrypt all user stored information with AES256-CBC.</li>
<li>The <a href="../../product/secure-usb/" title='SafeStick the secure USB flash drive'>SafeStick</a> hardware is fully epoxy encapsulated.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.blockmastersecurity.com/security/competing-products-contain-serious-flaw-safestick-not-affected/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
