Rootkit Labs has released the Phantomdrive, an open-source, inconspicuous USB device that uses AES-256 encryption and a hidden partition to protect sensitive data from unauthorized physical access.
Key Points
- The Phantomdrive utilizes a CH569 microcontroller and a user-provided microSD card to manage both a decoy 8GB partition and a hidden, encrypted storage area.
- Firmware intercepts specific text file commands to unlock the hidden partition, ensuring the password is never written to the physical storage cells.
- Security features include PBKDF2-HMAC-SHA-256 hashing with intentional delays to prevent brute-force attacks and hardware-bound encryption keys.
- Users can spoof vendor IDs to make the device appear as a standard, low-cost USB drive from brands like Kingston to avoid suspicion.
- The project is fully open-source, with schematics, PCB layouts, and firmware available on GitHub, or available for purchase from Rootkit Labs for $50.