Windows 11 Pro's On-by-Default Encryption Slows SSDs Up to 45%
tomshardware.com
tomshardware.com
IIRC thought the whole reason for this was because the Hardware-based encryption turned out to be so terrible on just about every drive that Microsoft just decided to not even bother using it.
From 2018:
> The two [researchers] say that the SEDs they've analyzed, allowed users to set a password that decrypted their data, but also came with support for a so-called "master password" that was set by the SED vendor.
> Any attacker who read an SED's manual can use this master password to gain access to the user's encrypted password, effectively bypassing the user's custom password.
> The only way users would be safe was if they either changed the master password or if they 'd configure the SED's Master Password Capability setting to "Maximum," which effectively disables it.
* https://www.zdnet.com/article/flaws-in-self-encrypting-ssds-...
Apparently several vendors were using fixed encryption keys and at least one vendor was using all zeros as the AES key!
The NSA has loaded their firmware after the fact without the drives' OEMs cooperation:
* https://www.cbc.ca/news/science/nsa-hid-spying-software-in-h...
Well, there's certainly a chance. Firmware is reverse-engineered all the time.
This notion that your encryption- any encryption- is going to stop a state-funded actor from getting past to your data is just as ridiculous IMO as the people who stockpile AR-15's and cosplay soldiers on the weekends think they're a realistic threat to the same military that has predator drones.
If the government wants your data, they probably already have it, just like if they wanted you dead, you'd already be in the ground. Assuming there's enough left of you to bury anyway.
Reasonable people can admit that they can't do much about case 2, while still believing that applying countermeasures against 1 can be effective. Also note there is more than one government in the world that may intend to exploit your lack of privacy...
Just because you're given up on privacy and sovereignty doesn't mean you should go around infecting others with the same contagion.
Even if you have the type of resources that a big tech corporation like Google has, sooner or later the NSA will get a copy of your data.
It is not intended for providing privacy or security.
My point was that Kenny's claim is that on-drive encryption allows for easier "erasure", presumably by deleting the keys needed to decrypt the data and leaving the drive in the same state.
If that process is good enough to ensure proper "erasure" of the data (effectively complete prevention of data access), then how is it not equally secure as an encryption schema?
Don't know about enterprise IT software - haven't worked in/with big companies lately.
2. The whole point of the comment was enterprise IT software, and I can confirm it severely impacts the performance of high-spec computers with stuff like 32GB mem and NVMe SSDs.
Sure it streams videos and so on (so cpu performance is OK), but basic stuff like "opening a word doc" or "launching Explorer" takes 10s of seconds.
I'm back to waking up my pc and going to get a coffee for 15 minutes so it might be ready to use when I return.
Not disk encryption, but my personal nightmare happened a decade ago, when MIS found out I had a data background, and they needed someone to resolve network latency issues, they told me 37k on what was supposedly gigabit ethernet. They pointed me at their security doohickey, the DMS, and a giant pile of pcap files. I had zero idea what I was doing, but I came back with 80% +++ infosec garbage, like, everywhere, even the packets on the factory floor and other dumb metal. I must have checked and rechecked a bazillion times - as mentioned, I really didn't know what any of this stuff was, and relied on text mining and Wikidata. After ganking the entire DMS into my magic widgets, found that there were seventeen network packet analyzer / security products all spooging into the network, all - if I can trust my gensim skills - reporting on each other, because ALL of them were implemented completely separately. Each one was some idiot program manager parroting instructions - forcing network changes - from the customer based on who knows how many deadend procurement officers. And judging from the contract documents, the sniffers were the tip of the iceberg: it was across the board for AV, encryption, email settings, you name it - you probably need to review all of that.
It was a mess, but the guy who brought me in - damn, he was a really nice guy, realized that I was a pay grade above janitor at the time, tried to make my life decent - that guy . . he looked actually sick, like, "I-need-a-toilet-right-now" sick. Above him, no one wanted to tell the level above, so we kept getting kicked upstairs until we ended up at E-level and they're calling the Overlords in the corporate office. In the end, nobody wanted to rock the boat, for fear of running afoul of some random procurement officer or other (who could of course become VPs any second, or any quarter they needed a quick sale). And so it remained. As far as I know, their security setup remains unchanged to this day.
Ah, that wasn't even the worst of that kind of thing to happen, but that's another story, in an area where I was actually semi-qualified . .
I may see multiple AV/EDR systems more than I see a system with just one, running.
I managed macs for years and it was not fun. And I had no choice because all this software was mandated by the security team.
Look at what our software actually does and the actual resources used in doing so. Compare that to the theoretical minimum required. That ratio has been growing steadily. In the 80s, when your systems were simple and things were Assembly or C, not much efficiency was lost. Nowadays, enormous efficiency is wasted on telemetry, security measures (AV, Spectre etc. mitigations), programming in the name of being cross platform (Electron, …), indirection (APIs calling APIS ad infinitum), …
Also there is no source for the 45% figure.
> But the critical aspect is that software BitLocker dropped random write performance by 45% compared to hardware BitLocker.
I don't think consumers are engaging in a lot of sustained random writes. On the other hand, it might be a reason to avoid software encryption on a database server with a lot of writes.
Let me introduce you to Windows update. It is both random and sustained permanently.
Though if those are (hopefully) applied overnight, speed doesn't really matter.
And it is also entirely useless for good amount of data volume-wise on machine.
I never need video game files to be encrypted for example. It's entirely waste of power and CPU time to do it.
It’s a political problem not a technical one.
Modern CPUs can do AES faster than your SSD, sometimes faster than an NVME can read/write
The penalty is not huge especially compared to fully software implementations but it's not zero. And it takes memory bandwidth too.
I don't use FDE on my gaming system for this reason. It's a big heavy PC that never leaves my house with not really any personal data anyway.
To say anything interesting about performance on these modern machines, you would have to benchmark some real workload.
https://calomel.org/aesni_ssl_performance.html
First gen Ryzen (similar age) does 8.2GB/s, which is faster than PCIe 4 NVMe drives.
https://www.vortez.net/articles_pages/amd_ryzen_7_1800x_revi...
Somewhat recent intel i7-12700H does 14.8GB/s, which is about the limit of PCIe 5 NVMe drives.
https://www.notebookcheck.net/Intel-Core-i7-12700H-Processor...
Edit: here's a list of AES speeds via truecrypt. top of the charts is the Ryzen 9 7950X at 32GB/s.
https://www.notebookcheck.net/Benchmarks-and-Test-Results.14...
In the era of mechanical drives and 2 Mbps “broadband” nobody would notice. Now with SSDs and gigabit home internet, people do notice but vendors are still pretending they can just ignore the need to offload encryption.
VPN products and IPsec especially is almost always a disaster in my experience.
When evaluating any kind of network security product like a virtual WAN appliance, tunnel, or whatever, check the throughput. If it can get tens of gigabits for a single stream then it is using some sort of offload. If it seems to hit the wall at around 1.5 Gbps per core, do not buy.
Doing 2.6GB/s in single thread means you have one core less to use...
I'm an advocate for FDE across the board (literally all of my devices are on Windows 11 Pro, primarily so I at least have access to Bitlocker across the board), but it's disingenuous to claim that the only alternative to FDE when a device is taken would be to initiate a sector-by-sector wipe. He was responding to ilyt's comment about how only certain data is worth encrypting on pretty much every personal device (and we are talking about Win 11 Pro, not Enterprise).
Why pay cops if I’m not being murdered or robbed?
Why keep nukes behind launch codes, nobody’s trying to launch them?
Why eat every day, I don’t start to die until like 3 days in…
Why pay cops, they're already being bribed by criminals (batman, punisher, etc cops anyway :D )
> Why keep nukes behind launch codes, nobody’s trying to launch them?
Because if you get rid of launch codes you'll decimate the Hollywood Political Thriller movie industry
> Why eat every day, I don’t start to die until like 3 days in…
Why do you hate farmers?
:D
I’ve said it before and I’ll say it again, it’s a matter of time before Windows runs on the Linux kernel. It’ll just be this big monoculture like Chromium with browsers. There really isn’t any reason to duplicate all this effort in maintaining an OS. Might as well have the whole world pitch in on one strong project.
Do you also feel confident nobody will pick your drive up at the landfill where it's going to end up?
Crackhead burgling my home is significantly higher risk than the NSA trying to grab my data. If the NSA wants it, my cute 32 character random password is probably insufficient to stop them.
There are precautions available to any user before they throw a drive away.
I do, because it's not going to end up there. I still have possession of literally every hard drive I've ever owned.
- Storage is always encrypted on Apple Silicon Macs.[1]
- You can enable FileVault, but all FileVault does on Apple Silicon is add the user's password as an additional key[2]. There is not an additional performance hit with FileVault.
1. https://support.apple.com/guide/security/data-protection-ove...
2. https://support.apple.com/guide/security/volume-encryption-w...
The only thing that is hard to find these days is SSDs with 4K AND OPAL. The WD 850X has 4K clusters, but not OPAL.
The Samsung 980 Pro has 515B clusters, and OPAL. Not sure about the Samsung 990 Pro.