threefoldtech / zos

Autonomous operating system
https://threefold.io/host/
Apache License 2.0
82 stars 13 forks source link

SSD capacity spoofing #1721

Open Nelson361 opened 2 years ago

Nelson361 commented 2 years ago

I bought a clearly fake1tb SSD just to see how easy it was to fake capacity. Testing shows it was much smaller than 1tb but the explorer reports it as 1tb. This is done through a fraudulent firmware installed on the SSD. It may be possible to detect the relatively few models of this out there and blacklist them in lieu of an actual utility to measure capacity in the short term. I have disconnected the node right after getting it only to not "steal" any TFT but I can reboot if you want to take a look at it. fake Capture .

muhamadazmy commented 2 years ago

There is currently a "work in progress" procedure to verify reported capacity. once fully implemented, this won't be possible anymore

@maxux