Copy of letter sent to Sandforce. Feel free to comment.
Hello,
I'm interested in the cryptographic features of your SF-1200 and SF-1500 SSD controllers. I have been unable to find any review which discusses these features in detail, and your website barely mentions the features.
Could you explain in detail, or link to a detailed explanation, of your AES implementation? Specifically,
As it stands, none of your competitors have cryptographically secure SSD controllers. Show that you've done it right, and make a profit.
Hello,
I'm interested in the cryptographic features of your SF-1200 and SF-1500 SSD controllers. I have been unable to find any review which discusses these features in detail, and your website barely mentions the features.
Could you explain in detail, or link to a detailed explanation, of your AES implementation? Specifically,
- Which AES mode are you using?
- Which algorithm do you use to create a key from the user supplied password?
- What constants, if any, do you use with these algorithms?
- Is there a way to disable cryptography on the drive, such that a reviewer could view the encrypted data directly in order to verify your encryption implementation? Do you have a software implementation of your cryptography features?
- Are internal data structures such as the free block list encrypted?
- Have any qualified cryptographers reviewed your implementation?
As it stands, none of your competitors have cryptographically secure SSD controllers. Show that you've done it right, and make a profit.
