In the end, it’s encrypted, compressed, decrypted, and decompressed multiple times on the way from the platter (or flash) to the tape recording head. It feels kind of dumb, really, but I’ll agree that if the computer doesn’t have the private key of the drive, stealing the data on tape will be a lot harder.
Even things like Windows Bitlocker and LUKS/dmcrypt on Linux totally ignore the drives ability to do any encryption, and do all encryption using the CPU before the drive sees the data.
Bitlocker/LUKS could easily just calculate the encryption keys and send them to the drive and trust it to encrypt/decrypt data for them... but they don't.
Source? Last I heard many companies rely on the encryption supplied by tape drive systems.
The reason is that all encryption is based on the separation of place between the encrypted data and the encryption key. Whoever can access the encrypted data must not have any way to access the encryption key.
Whenever you give your encryption key to a hardware device, or worse, when the hardware device also generates itself the encryption key, it becomes impossible to ensure that the attacker will not be able to access the encryption key.
It is impossible to know how the encryption keys are stored inside a hardware device and how and when they are erased and how easy or how difficult it will be in the future for an attacker to retrieve them.
It is impossible to believe any marketing claim of the vendor of a hardware encryption device about how tamper-resistant the device is, because such claims have very frequently been proven to be lies (even when the claims come from the largest companies, e.g. Microsoft and many others like it) and it is too difficult to distinguish truth from lies in such cases.
The only reliable means of encryption are in software, under complete end user control (or equivalently, in a custom FPGA).
That's probably one of the items on the list of reasons there are so few vendors in the space, LTO drives are essentially fungible and don't do anything interesting across vendors.
If they didn't, they'd be vulnerable: https://en.wikipedia.org/wiki/Distinguishing_attack
However, something close to your point is true. If they compress the data and then encrypt, the ciphertext will indeed be smaller than the original data.
If you compress the symmetrically encrypted data, you will indeed gain some capacity. Not as much as you would compressing the raw data, but a visible amount, because the symmetric algorithm doesn't have the property of indistinguishability.
That property is not needed for tape storage because anyone who has the tape can safely assume it contains a ciphertext. The tape has header information saying whether it's encrypted or not.
If you read the links you posted, you will find out that it's not "most" cryptosystems, it's some. Some applications just don't need indistinguishability and LTO Tapes are one of them.
All that said, IBM does compress first then encrypt to make the most of the data compression, but the resulting ciphertext isn't completely random.
You can't really say indistinguishability makes one cryptosystem better than another because it prevents distinguishing attacks because for some applications it's both not needed and computationally expensive.
For a laptop SSD, all of these matter. You can't do much compression because compression consumes a lot of power and latency upon access, some compression schemes make random access harder (i.e. compression schemes without an index where you have to scan through intermediate checkpoints or, in the worst case, sequentially through the entire media), and it may lead to write amplification as well if you need to add a piece of data in the middle of a file (basically the issue with shingle HDDs). As a result, no compression possible, and so SSDs are advertised with the raw capacity (or, in fact, they are underadvertised because SSDs need spare block capacity to account for wear).
There's no such thing as a standard distribution of compressible data. Customer data varies wildly.