Even more sophisticated: Seagate hard disks sold with manipulated FARM values

After manipulating the serial number comes the next trick: the fraudsters manipulate the FARM values. Initially, Exos drives with 20 TByte are affected.

listen Print view
Numerous hard disks on one shelf

(Image: c't / ll)

3 min. read

The scandal surrounding used Seagate hard disks sold as new continues; we are still receiving emails from fraudulent buyers. Now a new method has come into play that makes fraud detection even more difficult.

The crooks have apparently managed to change a value that was previously considered a clear indication of fraud: the number of operating hours in the FARM values. According to Seagate, the "FARM log is pulling data from several internal logs to provide an overview of the drive usage and health status. Depending on knowledge and capabilities, logs can be cleared and if one of the background data the FARM log pulls was cleared, it has an effect."

A simple comparison of the operating hours in the usual SMART values with the operating hours (Power On Hours, POH) in the FARM values is therefore no longer sufficient to identify a used drive. Only a look at the operating hours of, for example, the individual heads shows whether the drives are really new.

Update

Due to an error in the smartmontools, the operating time of the heads is displayed in seconds. You therefore have to convert this appropriately. The error will be fixed in version 7.5 of the tools.

This is particularly annoying for users of a Synology NAS who check their drives with the Docker image farm-check. The programmer of the tool sees no possibility to extend the tool to a check without the POH. published an update. The output is now similar to the following:

=== Checking device: /dev/sdc ===

Model Family: Seagate Exos X16

Device Model: ST16000NM001G-2KK103

Serial Number: ...

SMART: 2863

FARM: 2863

HEAD: PASS (Max: 19 hrs)

RESULT: PASS

Videos by heise

For most used drives, however, there is still the option of verifying the age via the production date. A hard disk should not take more than six months to reach the end customer – If the production date is significantly longer ago, a more detailed check is adviced.

A missing sticker on the front is also an indication of fraud. The serial number of the drive is printed directly on it, as is a barcode. If you can't read the serial number, simply use a barcode scanner on your smartphone to display the number.

From the QR code on the sticker directly to the warranty check: this does not work with a fake sticker.

A counterfeit sticker can also be easily identified with the help of a smartphone: Normally, the barcode on the sticker leads to the website with the warranty query, with the serial number already pre-populated. With counterfeit stickers, however, you have to type in the serial number yourself.

Empfohlener redaktioneller Inhalt

Mit Ihrer Zustimmung wird hier ein externer Preisvergleich (heise Preisvergleich) geladen.

Ich bin damit einverstanden, dass mir externe Inhalte angezeigt werden. Damit können personenbezogene Daten an Drittplattformen (heise Preisvergleich) übermittelt werden. Mehr dazu in unserer Datenschutzerklärung.

(ll)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.