4 ms·
They're fine for most use cases. Probably wouldn't trust windows or MacOS against state actors. Fedora defaults are adequate but depend on the strength of your
by onlypositive 3y ago
They're fine for most use cases. Probably wouldn't trust windows or MacOS against state actors.
Fedora defaults are adequate but depend on the strength of your password.
Simplest setup is actually to just enable SSD password in bios. All SSDs these days are encrypted by default - they just store the password in bios and don't tell you they're doing it. If you set a password there is zero perf overhead.
A basic linux setup is unencrypted boot and encrypted root partitions.
You can encrypt boot using a small grub partition to chain load boot/root but all it's preventing is someone swapping your kernel/bootloader configs out without your knowledge. If that's not a concern you can skip it.
While using bios level encryption is simple it limits my options as far as controlling decryption with keyfiles on USB or yubikey which I like in some situations.
The bigger problem I have with encryption these days is ensuring my automated backups are encrypted despite being always on.
- sampa 3y agoSSD password in BIOS is mostly a snake oil. Nobody verifies that the encryption scheme is sound. PS And when somebody takes a look at it, most of the time it is broken. Google the research.
- dathinab 3y agoThey are not sanke oil but "compliance tricks" ;=) Basically: - full disk encryption is required for whatever reason - BIOS SSD passwords fulfill that requirement and it is good enough to prevent accidentally leaking data when losing the laptop and it goes in the hand of someone slightly technical versatile but not a specialist/hacker nor a targeted attack interested in handing the laptop to a specialist. Hence why compliance rules in cases involving actual sensitive data often require full disk encryption using more strict requirements not fulfilled with BIOS encryption. > Nobody verifies that the encryption scheme is sound. for some Latop brands/variants you most likely have a sound encryption schema, but there is still the problem that it's unlocked by the TPM and the en-/de-cryption is likely run on the CPU or similar instead of an specialized IO description chip tightly coupled with the TPM (modern Apple devices, at least phones, are a notable exception here AFIK). So even if the encryption schema is sound it's normally not too hard to extract the key in one of many ways for a specialist. And even if that doesn't work there is still the attack to inject your OS which then sees the unencrypted SSD... so normally not secure.
- petepete 3y agoIf anyone is looking into self encrypting drives, the main specification is called Opal. https://en.wikipedia.org/wiki/Opal_Storage_Specification https://en.wikipedia.org/wiki/Opal_Storage_Specification
- veeti 3y agoI will never trust the FDE implementation shipped on an SSD. [1] https://www.tomshardware.com/news/crucial-samsung-ssd-encryption-bypassed,38025.html https://www.tomshardware.com/news/crucial-samsung-ssd-encryp...