Take a look at our
ThinkPads.com HOME PAGE
For those who might want to contribute to the blog, start here: Editors Alley Topic
Then contact Bill with a Private Message

Disk drive encrytion - bad idea?

General Questions, Rumors, Real news & More
Post Reply
Message
Author
mikemex
Senior Member
Senior Member
Posts: 618
Joined: Mon Oct 04, 2010 8:54 pm
Location: Coyoacan, Mexico

Disk drive encrytion - bad idea?

#1 Post by mikemex » Tue Jun 21, 2022 6:58 am

Hi,

I fail to see what full disk encryption brings to the table, having the option to simply put an ATA password on the drive. It seems to me that such technologies make it even easier for hackers to use ransomware against you. Or make your data more prone to catastrophic loss / corruption if your system begins to fail / has a bug.

All in all, the most likely negative scenario is that you do something wrong yourself and you're locked out of your own data. Besides, I think the chances of finding someone capable of circumventng disk encryption are far higher than of finding someone capable of breaking into an ATA password protected drive. If for anything, because the former can be done remotely, and the second only physically.

Or am I missing something?
X301: SU9600 | 8GB | 1TB | WXGA+
X1C5: 7600U | 16GB | 1TB | FHD
X1C9: 1145G7 | 16GB | 1TB | WUXGA | WWAN
X1Y8: 1365U | 32GB | 1TB | WUXGA
P14s G1 AMD: 4750U | 32GB | 1TB | PG FHD Touch
T14 G2: 1145G7 | 32GB | 1TB | FHD

unix_joe
Junior Member
Junior Member
Posts: 353
Joined: Mon Jan 03, 2011 9:08 pm
Location: Pinehurst, NC
Contact:

Re: Disk drive encrytion - bad idea?

#2 Post by unix_joe » Thu Jul 07, 2022 6:36 am

In practice, on modern SSD's, they are the exact same thing.

You have to trust the hardware on some level, which has proven to be problematic. Hence the rise of secondary authentication measures like TPM, which distributes trust among components made by different manufacturers.

The attack vector comes in when you add remote management. McAfee, Symantec, and Bitlocker allow this.

But for that kind of infrastructure, you are talking a large corporation willing to pay for such services, and they assume the risk not in terms of data, but in terms of the insurance payout from the vendor when the data is lost.

For a personal user, normal FDE given by the OS is sufficient enough. The benefit of not using the ATA encryption is that, one can remove the drive, use dd or one of the pretty front ends (Clonezilla, etc) to mirror the drive to another one sector by sector and it the other drive will work with the same password. A nice out of band backup system.
unix_joe
Me: ThinkPad Z13 - Debian Stable KDE
Wife: ThinkPad Z16 - Pop!_OS
Kids: ThinkPad X280 - Debian Stable Gnome
TV: ThinkPad P14s - Debian Stable

elka.
Posts: 8
Joined: Fri Feb 03, 2023 12:12 pm
Location: Orlando FL

Re: Disk drive encrytion - bad idea?

#3 Post by elka. » Fri Feb 03, 2023 12:23 pm

> I fail to see what full disk encryption brings to the table, having the option to simply put an ATA password on the drive.

Not all computers have a way of entering ATA password. If your computer quits working you may be unable to read the drive in another computer.

Full disk encryption that is done in software doesn't have this issue.

FDE does not protect you from malware or ransomware. for this you need backups.

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “GENERAL ThinkPad News/Comments & Questions”

Who is online

Users browsing this forum: No registered users and 7 guests