4 ms·
Right. The thing is, when you wear out an SSD, you get these enormous (multiple seconds) pauses that, if you're doing anything I/O bound slow you down to a craw
by archivator 13y ago
Right. The thing is, when you wear out an SSD, you get these enormous (multiple seconds) pauses that, if you're doing anything I/O bound slow you down to a crawl. Even opening a heavy web page can trigger them. Buy a fast HDD if you want consistent long term behaviour with FDE.
The reason FDE breaks SSDs is that the implementation in LVM works at the block level. To send TRIM, the filesystem says "this block is empty, tell the controller" but depending on a thousand things, among which are cipher mode, cipher block size and other minutiae, LVM will invalidate the TRIM command. Without TRIM, SSDs deteriorate rather quickly.
Personally, I understand why FDE is needed but I'm of the opinion that selective encryption (with possible plausible deniability measures) is a much neater, if more difficult, approach.
- Spittie 13y agoYou should enable encryption at the controller level, many modern SSD support it and it shouldn't influence the performance.
- archivator 13y agoIndeed! Which is why I said "software full disk encryption" in my OP. :)