Intel or any other safe drive encrypting in Lenovo t410 ssdd

T400/410/420 and T500/510/520 series specific matters only
Post Reply
Message
Author
rychuu
Sophomore Member
Posts: 155
Joined: Sun Sep 11, 2011 7:41 am
Location: Warsaw, Poland

Intel or any other safe drive encrypting in Lenovo t410 ssdd

#1 Post by rychuu » Thu Jul 12, 2012 10:14 am

Hello,

I have bought an SSD OCZ agility 3 hdd and one Intel SSd else.

I would like to make my computer now as safe as possible now, so i would like to ask you for two things:

durability and performance of encrypted SSD

How to encrypt - from which should I start. I need stability and performance but the most important for me is confidence - to make disks unreadable for other persons.

I have any Intel AT tehnologies in my Lenovo.

Only last question - what is the idea of the drive encrypting ? Disk pulled from the computer is blocked? What in the original compuetr? Without plugging it and when we broke OS We will have access to files?


thank for helping
I am using Lenovo t410 2518-4ju.

best regards

EOMtp
ThinkPadder
ThinkPadder
Posts: 1583
Joined: Fri May 19, 2006 12:51 pm

Re: Intel or any other safe drive encrypting in Lenovo t410 ssdd

#2 Post by EOMtp » Thu Jul 12, 2012 5:33 pm

Two types of drive encryption:
1) Software encryption, like TrueCrypt, and
2) "Always-on" hardware encryption, performed automatically and transparently by the drive's electronics whenever data is written to the drive.

It is best to use a drive with built-in always-on hardware encryption. The data written to such a drive is always automatically encrypted, and also automatically decrypted upon read, by the drive's electronics ... HOWEVER, if the user sets a hard drive password on the drive (via the BIOS), then the drive will NOT automatically decrypt the data if that password is not provided by the user when the drive is powered up.

Note that the hard drive password, if set by the user, will be stored in the drive's electronics, not in the BIOS, so the drive will operate in any machine which is able to pass on to it the password the user provides at power up. In other words, you can remove the encrypted drive from one machine, place the drive in a different machine, provide the password, and the drive will decrypt the data.

[It does not matter for this discussion, but also note that the key used to encrypt the data on the drive is different from the password the user sets. Changing the encryption key (not the drive's password) will have the same effect as instantly erasing everything on the drive.]

Your Intel SSD drive may have built-in hardware full drive encryption, depending on which model/version you have.

All software-based encryption schemes are inferior, in one or more ways, to hardware full drive encryption.

ThinkRob
Senior ThinkPadder
Senior ThinkPadder
Posts: 2364
Joined: Wed May 20, 2009 9:54 am
Location: near RTP, NC

Re: Intel or any other safe drive encrypting in Lenovo t410 ssdd

#3 Post by ThinkRob » Thu Jul 19, 2012 6:41 pm

EOMtp wrote: All software-based encryption schemes are inferior, in one or more ways, to hardware full drive encryption.
I strongly disagree with that statement. Whether hardware or software encryption is better depends on entirely your needs.

Do you, for example, need to use multiple encrypted containers or assign multiple different passwords to an encrypted drive? Then hardware solutions are inferior for that, since none of the ones on the market support that.

Do you want to pick your own encryption/authentication algorithms? Good luck finding a hardware solution that allows as much choice as Truecrypt or LUKS.

How about backing up the encryption keys? Some hardware solutions support it, some don't.

And cloning the drive without decrypting it first? If you use a hardware solution, forget it.

So no, hardware solutions are not always superior and are for some uses quite inferior.

Personally I'd recommend a software approach, as you retain the flexibility of choosing whatever drive you'd like, and being able to better manage your keys and encryption configuration -- plus, with modern CPUs the performance penalty is so small as to be imperceptible for typical desktop tasks.
Need help with Linux or FreeBSD? Catch me on IRC: I'm ThinkRob on FreeNode and EFnet.

Code: Select all

Current laptop: X1 Carbon 3
Current workstation: none

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “ThinkPad T400/410/420 and T500/510/520 Series”

Who is online

Users browsing this forum: No registered users and 6 guests