A US company has come up with an original take on ultra-secure portable storage, fitting a full PIN entry keypad to a USB stick. A US company has come up with an original take on ultra-secure portable storage, fitting a full PIN entry keypad to a USB stick.The LOK-IT Secure Flash Drive from Systematic Development Group comes in two versions, the simpler of which allows five-key PINs to be entered to gain access, with a more sophisticated version featuring 10 keys.Apart from both using 256-bit AES encryption to secure data, both drives remain encrypted until the correct PIN code is entered at the point it is inserted into the PC, which can be Windows, Mac or Linux. Each drive supports two keys, one for the user and one for an admin.The drive design resists physical attacks by surrounding the chip on which the encryption PIN is held in an epoxy resin that breaks the chip if tampered with. Brute force PIN hacking is blocked by a maximum of ten logins attempts after which the drive has to be reformatted. In other respects, apart from its aluminium case and dust and water resistance, the drive is identical to any other USB stick, coming in 2GB, 4GB, 8GB and 16GB capacities.According to Systematic Development’s John Tate, most customers are plumping for the most secure, 10-digit model, attracted by the design’s different take on USB stick security. The majority of the company’s rivals used a design that involved authenticating a user’s login using a driver layer on the PC, something that was vulnerable to keyloggers, he said. The LOK-IT’s design advantage over conventional encrypted USB keys is hard to argue with – the key remains inside the drive and is never transferred to the PC, which would be a theoretical moment of vulnerability.Tate’s characterisation of rival designs as insecure is not entirely without supporting evidence. In January, three vendors of supposedly secure USB sticks admitted that the encryption on their drives was vulnerable to a theoretical attack that could render data insecure. Not all the products mentioned were current but the warning over design assumptions was clear.A second bonus is the LOK-IT’s OS-independent design, which means it can be plugged into any computer that supports USB storage. That also rules out the need for additional software.At first sight, a slight disadvantage appears to be awkwardness of plugging a PIN into a drive while it is docked with a PC, but Tate confirmed that the code can be entered in advance of mounting the drive. Interestingly, expense doesn’t seem to be a major issue – the 4GB drive costs $62 (approx £40), in line with other corporate-level encrypted USB sticks.LOK-IT’s makers have posted a video on YouTube explaining the design and doing the dirty on some of its rivals. Related content news analysis Attackers breach US government agencies through ColdFusion flaw Both incidents targeted outdated and unpatched ColdFusion servers and exploited a known vulnerability. By Lucian Constantin Dec 06, 2023 5 mins Advanced Persistent Threats Advanced Persistent Threats Advanced Persistent Threats news BSIMM 14 finds rapid growth in automated security technology Embrace of a "shift everywhere" philosophy is driving a demand for automated, event-driven software security testing. By John P. Mello Jr. Dec 06, 2023 4 mins Application Security Network Security news Almost 50% of organizations plan to reduce cybersecurity headcounts: Survey While organizations are realizing the need for knowledgeable teams to address unknown threats, they are also looking to reduce their security headcount and infrastructure spending. By Gagandeep Kaur Dec 06, 2023 4 mins IT Jobs Security Practices feature 20 years of Patch Tuesday: it’s time to look outside the Windows when fixing vulnerabilities After two decades of regular and indispensable updates, it’s clear that security teams need take a more holistic approach to applying fixes far beyond the Microsoft ecosystem. By Susan Bradley Dec 06, 2023 6 mins Patch Management Software Threat and Vulnerability Management Windows Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe