5 ms·
I use the standard hardware encryption of my SSD (a Samsung 830 in my 2012-era Dell XPS 13), which requires I enter the passphrase when I turn my machine on. A
by de_dave 10y ago
I use the standard hardware encryption of my SSD (a Samsung 830 in my 2012-era Dell XPS 13), which requires I enter the passphrase when I turn my machine on.
Advantages:
- OS neutral
- Seemingly as fast as running 'unencrypted'
(I assume performance is identical, the only
difference being the passphrase is stored in
my head rather than the BIOS)
Disadvantages:
- Limited to an 8-char (!) ASCII passphrase
- I've no idea how secure it really is
- Can't audit the algorithm (not that I have
the technical ability to)
- d33 10y agoThat sounds like an annoyance, not encryption to me.
- popey456963 10y agoGenerally as you increase security you will lose usability and vice versa. It's about weighing the advantages against the disadvantages.
- centizen 10y agoIt's the 8-char password that I find absurd - that would take about 2 hours to brute force max.
- jkot 10y agoI think hdd will wipe itself after N incorrect attempts.
- dmd 10y agoSo you copy the drive first.
- jcrawfordor 10y agoEncryption is done in drive hardware, so copying the drive is possible via hardware attacks but would be a pretty involved lab operation. Would definitely take longer and require more sophistication than many in-practice crypto exploits.
- de_dave 10y agoAllegedly it's 256-bit AES and would take thousands of years to brute force. (Allegedly, because of course there's no way for me to easily verify!)
- wepple 10y agoa 256-bit AES key might take eternity, but if it's derived directly from 8-char ASCII the search space is tiny. Somewhat does depend on how it's actually implemented in hardware, however.
- bb88 10y agoOr even better, the key is determined randomly, and the 8 char password decrypts the key.
- JaRail 10y agoThe 8 char password does not decrypt the key; it unlocks/retrieves it. The drive will only allow a fixed number of attempts. Once past the 10 or whatever allowed attempts, an attacker needs to brute force the full encryption key. It should be a very similar scheme to what you get with a modern smartphone, such as a new iPhone. (Not one of the older iphones the FBI cracked recently, a new one with a Secure Enclave.)
- na85 10y agoWhat stops the attacker from just imaging the drive in its encrypted state and continuing to run attacks on the 8 char password well in excess of 10 attempts?
- jcrawfordor 10y agoThe drive controller does not allow you to read the encrypted form of the data out. This kind of drive-encryption is the same as the common ATA lock command (implemented in your BIOS and the drive controller), but the drive controller actually encrypts the data as well as just refusing to work without being unlocked first.
- eeZi 10y agoOn Thinkpads at least it can be much longer.
- _RPM 10y agoIt reminds me of how I set a boot password in the BIOS on my HP laptop. I now have forgot the admin password in order to remove that "feature". I have no idea how I can fix it. The laptop is bricked. I can't install Linux on it because it is set not to boot from USB or CD/ROM
- witty_username 10y ago> I have no idea how I can fix it. Just disconnect the CMOS batteries; you can find tutorials online. Or you can take it to a computer shop, it should be a simple fix.
- _RPM 10y agoWhere are those located?
- witty_username 10y agoThe grey coin-sized CMOS battery is alongside the motherboard. I suggest you look at the many guides and videos, just search "removing BIOS password".
- _RPM 10y agoThat will work for sure? I'd have to really start taking things apart.
- whamlastxmas 10y agoAlmost certainly yes. I have taken apart many laptops, it's usually not more than 5 minutes reading a guide/video and another 5-10 minutes of work.
- jerf 10y agoCheck HP for the service manual for your laptop. This is generally a standard goal the manual will give steps for. Usually all you need is a screwdriver of the right size and a bit of guts to pull apart bits of plastic, though I find my confidence that I'm not destroying anything is greatly enhanced when I'm following the manual and have reasonable confidence all the screws are out properly.
- de_dave 10y agoYou're correct, it's not going to stop someone who knows exactly what they're doing and has the time/patience/tools to brute force. But it is enough to stop casual thieves from stealing more than just hardware, which is (fortunately) my main concern.
- eeZi 10y agoIt does actually encrypt your data, and if it's correctly implemented, it's fine. Those drives sell for a few years now and not a single exploit is known. For most people this is more than enough.