{"id":3134,"date":"2011-09-23T08:22:40","date_gmt":"2011-09-23T05:22:40","guid":{"rendered":"http:\/\/mummila.net\/nuudelisoppa\/?p=3134#post-"},"modified":"2011-09-27T15:24:22","modified_gmt":"2011-09-27T12:24:22","slug":"encryption-and-ssds","status":"publish","type":"post","link":"https:\/\/mummila.net\/nuudelisoppa\/2011\/09\/23\/encryption-and-ssds\/","title":{"rendered":"Encryption and SSDs"},"content":{"rendered":"<p>I&#8217;ve been contemplating on getting a SSD for my desktop. At the same time, I&#8217;ve been meaning to once again get my entire system partition encrypted (for now, I&#8217;ve only encrypted a directory within my home directory). I used to run an entirely encrypted system from a traditional hard disk, but I know an SSD is a different beast.<\/p>\n<p>According to Wikipedia, <a href=\"https:\/\/secure.wikimedia.org\/wikipedia\/en\/w\/index.php?title=TRIM&amp;oldid=451309758#Shortcomings\" title=\"Wikipedia: TRIM. 3 Shortcomings (19. 9. 2011)\">when software-based disk encryption (such as dm-crypt) is used, using the TRIM command reveals information about which blocks are in use<\/a>. This means you either have to disable TRIM and risk performace degradation to gain security, or keep TRIM and risk exposing information about your data.<\/p>\n<p>And at least according to one user on StackExchange, even <a href=\"http:\/\/askubuntu.com\/questions\/59519\/do-you-recommend-luks-encryption-on-a-ssd-trim-support\/59816#59816\">enabling TRIM won&#8217;t help protect the drive&#8217;s performance due to how software encryption works<\/a>.<\/p>\n<p>So my best bet would be hardware-based encryption such as the one offered by the Kingston SSDNow V+ 100E Series. According to Kingston&#8217;s FAQ, <a href=\"http:\/\/www.kingston.com\/support\/ssdnow\/faq\/KSD-011411-ENC-01.asp\">the encryption on their disks utilizes the hard disk password feature of the BIOS<\/a>. From what I gather, that password is used as the encryption key, which means unauthorized access cannot be gained by simply bypassing the disk&#8217;s locking mechanism, unlike in drives with no built-in encryption. (It also means <a href=\"http:\/\/www.kingston.com\/support\/ssdnow\/faq\/KSD-011411-ENC-03.asp\">once you lose the password, there&#8217;s no way to recover your data<\/a>, as it should be in a truly secure system.)<\/p>\n<p><ins datetime=\"2011-09-24T07:29:32+00:00\">Edit<\/ins>: My ASUS M4A78-EM doesn&#8217;t seem to support setting a HD password, so it looks like I&#8217;m out of luck until I upgrade my motherboard. :(<\/p>\n<p><ins datetime=\"2011-09-27T12:22:38+00:00\">Edit<\/ins>: I flashed the mobo with <a href=\"http:\/\/www.fitzenreiter.de\/ata\/ata_eng.htm\">ATA Security eXtension -enabled BIOS<\/a> and now I can haz hdd passwords.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;ve been contemplating on getting a SSD for my desktop. At the same time, I&#8217;ve been meaning to once again get my entire system partition encrypted (for now, I&#8217;ve only encrypted a directory within my home directory). I used to run an entirely encrypted system from a traditional hard disk, but I know an SSD [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3134","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/mummila.net\/nuudelisoppa\/wp-json\/wp\/v2\/posts\/3134","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mummila.net\/nuudelisoppa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mummila.net\/nuudelisoppa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mummila.net\/nuudelisoppa\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/mummila.net\/nuudelisoppa\/wp-json\/wp\/v2\/comments?post=3134"}],"version-history":[{"count":7,"href":"https:\/\/mummila.net\/nuudelisoppa\/wp-json\/wp\/v2\/posts\/3134\/revisions"}],"predecessor-version":[{"id":3139,"href":"https:\/\/mummila.net\/nuudelisoppa\/wp-json\/wp\/v2\/posts\/3134\/revisions\/3139"}],"wp:attachment":[{"href":"https:\/\/mummila.net\/nuudelisoppa\/wp-json\/wp\/v2\/media?parent=3134"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mummila.net\/nuudelisoppa\/wp-json\/wp\/v2\/categories?post=3134"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mummila.net\/nuudelisoppa\/wp-json\/wp\/v2\/tags?post=3134"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}