4 ms·
In these days, a lot of SSD makers have AES engine inside, it encrypts and decrypts on-the-fly. I don't understand the usage of AES in T2.
by codebook 8y ago
In these days, a lot of SSD makers have AES engine inside, it encrypts and decrypts on-the-fly. I don't understand the usage of AES in T2.
- foobarbazetc 8y agoYeah it’s a strange re-implementation of SEDs.
- Twisell 8y agoBecause this way you have to put your trust in only one company instead of all it’s suppliers? PS: And for the company one less dependency to manage?
- gumby 8y agoThe NVMe storage doesn't look like an SSD and doesn't have a traditional disk controller.
- deleted 8y ago[deleted]
- thisacctforreal 8y agoThe Secure Enclave in the T1 and all iPhones since the 5s has a unique key in the AES engine's silicon, that cannot be read even from the Secure Enclave's firmware. This key is "tangled" with user-supplied keys for per-device access to data. I assume the T2 offers this same feature. See UID in the glossary (page 80) or under Hardware security features (page 12) of the iOS 11 Security Guide https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf
- jwr 8y agoHow do you know it encrypts and decrypts on-the-fly? Is there a way to verify it? [and before someone says it, yes, in the iMac Pro you can read the data off the NVMe lanes to check if it indeed is encrypted]