Audit Open Original ↗
Western Digital Sweet B
Type
Security review
Client
Western Digital
Date
2020-01
Domain
Systems
Effort
4 wks
Section
Western Digital
Trail of Bits's security review of Western Digital (Jan 2020) identified 6 issues: 1 medium, 3 low, and 2 informational.
Findings · 6
- 1 Assembly does not work in all build configurations Medium
- 2 Use of libc functions that may not be constant time Low
- 3 Enabling of SB_DEBUG_ASSERTS violates constant time behavior Low
- 4 HMAC_DRBG may lack backtracking resistance Low
- 5 Use of functions on the SDL List of Banned Functions Informational
- 6 API for ECDSA signatures does not enforce secure message digests Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related