3 ms·
I have a question about this. I don't use unencrypted storage and RPis have no hardware accelerated extensions. But modern SSDs do, and IMO it is good enough f
by ulzeraj 5y ago
I have a question about this. I don't use unencrypted storage and RPis have no hardware accelerated extensions.
But modern SSDs do, and IMO it is good enough for some stuff even considering the issues. They call it Self Encrypted Disks but I don't know if this feature requires some BIOS specific instructions or special devices like TMPs or if there are special parameters one could pass to GEOM or LUKS to use those encryption capabilities.
Anyone could give me a brief explanation on SED and if they could be used on RPi?
- deleted 5y ago[deleted]
- tw04 5y agoSED requires a key server to function or a utility to manually enter a password. sedutil appears to be the go-to on linux assuming it's not your boot drive: https://wiki.archlinux.org/title/Self-encrypting_drives#Encrypting_a_non-root_drive https://wiki.archlinux.org/title/Self-encrypting_drives#Encr... In the enterprise we use external keyservers like the ones Thales sells.
- ZiiS 5y agoThe common standard for SED is TCG OPAL. This has a pre-boot image allowing you to enter your password. Once the drive is decrypted it is completly transparent with your unmodified bootloader and kernel loaded with normal commands. I don't think the RasPi can trigger this unlocking nor could be modified to.
- ZiiS 5y ago* on boot. You can trigger the decryption of additional drives after boot.
- theandrewbailey 5y agoI noticed that OPAL features are becoming less used in encryption software, because the keys to some drives can be dumped through their JTAG ports.