<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Breaking the IronKey (literally)</title>
	<atom:link href="http://www.rec-sec.com/2009/05/27/breaking-the-ironkey/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rec-sec.com/2009/05/27/breaking-the-ironkey/</link>
	<description>a non-profit information security web site authored by Moshe Ben Abu (Trancer), focusing on vulnerability research, exploit development (mainly for the Metasploit Framework), web application security, information security and hacking news from around the world.</description>
	<lastBuildDate>Wed, 21 Jul 2010 17:11:36 +0000</lastBuildDate>
	<generator>http://www.rec-sec.com</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<atom:link rel="hub" href="http://pubsubhubbub.appspot.com" />
	<atom:link rel="hub" href="http://superfeedr.com/hubbub" />
		<item>
		<title>By: Anhldbk</title>
		<link>http://www.rec-sec.com/2009/05/27/breaking-the-ironkey/comment-page-1/#comment-1044</link>
		<dc:creator>Anhldbk</dc:creator>
		<pubDate>Wed, 01 Jul 2009 06:40:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=575#comment-1044</guid>
		<description>You&#039;ve got a good sense of humor! :D</description>
		<content:encoded><![CDATA[<p>You&#8217;ve got a good sense of humor! :D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Trent</title>
		<link>http://www.rec-sec.com/2009/05/27/breaking-the-ironkey/comment-page-1/#comment-981</link>
		<dc:creator>Justin Trent</dc:creator>
		<pubDate>Thu, 28 May 2009 14:31:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=575#comment-981</guid>
		<description>Dave,

Glad to see a modified form of the case is coming. Currently, at least according to the device&#039;s official FIPS security policy registered at NIST, my users are supposed to use a hair dryer to open it up and check the epoxy themselves on a periodic basis.

I&#039;ve been very worried that someone would yank the devices off desks when they found out users weren&#039;t doing this (for obvious reasons). Hopefully this new design will improve things.</description>
		<content:encoded><![CDATA[<p>Dave,</p>
<p>Glad to see a modified form of the case is coming. Currently, at least according to the device&#8217;s official FIPS security policy registered at NIST, my users are supposed to use a hair dryer to open it up and check the epoxy themselves on a periodic basis.</p>
<p>I&#8217;ve been very worried that someone would yank the devices off desks when they found out users weren&#8217;t doing this (for obvious reasons). Hopefully this new design will improve things.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trancer</title>
		<link>http://www.rec-sec.com/2009/05/27/breaking-the-ironkey/comment-page-1/#comment-979</link>
		<dc:creator>Trancer</dc:creator>
		<pubDate>Thu, 28 May 2009 07:26:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=575#comment-979</guid>
		<description>Dave, I personally think the IronKey is a great product and I&#039;m glad to hear you&#039;ve got a newer design. This post is a joke (Categories: LOLz) don&#039;t take it too seriously :)</description>
		<content:encoded><![CDATA[<p>Dave, I personally think the IronKey is a great product and I&#8217;m glad to hear you&#8217;ve got a newer design. This post is a joke (Categories: LOLz) don&#8217;t take it too seriously :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave_IronKey</title>
		<link>http://www.rec-sec.com/2009/05/27/breaking-the-ironkey/comment-page-1/#comment-978</link>
		<dc:creator>Dave_IronKey</dc:creator>
		<pubDate>Thu, 28 May 2009 00:14:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=575#comment-978</guid>
		<description>Trancer,
You&#039;ve still got to get through the epoxy without damaging the chips, but even then, you&#039;ve got the crypto and key protection to deal with.

The case you show is an older IronKey design.  The current cases are a single extruded assembly and there is no label plate to get off.  There is a top plate on the current design, which goes around the USB connector, and it has teeth which engage into the case.  This whole thing is epoxied.  It&#039;s a highly robust design that has been submitted for FIPS 140-2 Level 3 validation, which tests the tamper resistance to a high level.

Dave @ IronKey</description>
		<content:encoded><![CDATA[<p>Trancer,<br />
You&#8217;ve still got to get through the epoxy without damaging the chips, but even then, you&#8217;ve got the crypto and key protection to deal with.</p>
<p>The case you show is an older IronKey design.  The current cases are a single extruded assembly and there is no label plate to get off.  There is a top plate on the current design, which goes around the USB connector, and it has teeth which engage into the case.  This whole thing is epoxied.  It&#8217;s a highly robust design that has been submitted for FIPS 140-2 Level 3 validation, which tests the tamper resistance to a high level.</p>
<p>Dave @ IronKey</p>
]]></content:encoded>
	</item>
</channel>
</rss>
