IIRC thought the whole reason for this was because the Hardware-based encryption turned out to be so terrible on just about every drive that Microsoft just decided to not even bother using it.
IIRC thought the whole reason for this was because the Hardware-based encryption turned out to be so terrible on just about every drive that Microsoft just decided to not even bother using it.
From 2018:
> The two [researchers] say that the SEDs they've analyzed, allowed users to set a password that decrypted their data, but also came with support for a so-called "master password" that was set by the SED vendor.
> Any attacker who read an SED's manual can use this master password to gain access to the user's encrypted password, effectively bypassing the user's custom password.
> The only way users would be safe was if they either changed the master password or if they 'd configure the SED's Master Password Capability setting to "Maximum," which effectively disables it.
* https://www.zdnet.com/article/flaws-in-self-encrypting-ssds-...
Apparently several vendors were using fixed encryption keys and at least one vendor was using all zeros as the AES key!
This notion that your encryption- any encryption- is going to stop a state-funded actor from getting past to your data is just as ridiculous IMO as the people who stockpile AR-15's and cosplay soldiers on the weekends think they're a realistic threat to the same military that has predator drones.
If the government wants your data, they probably already have it, just like if they wanted you dead, you'd already be in the ground. Assuming there's enough left of you to bury anyway.
Reasonable people can admit that they can't do much about case 2, while still believing that applying countermeasures against 1 can be effective. Also note there is more than one government in the world that may intend to exploit your lack of privacy...
Just because you're given up on privacy and sovereignty doesn't mean you should go around infecting others with the same contagion.
Well, there's certainly a chance. Firmware is reverse-engineered all the time.
The NSA has loaded their firmware after the fact without the drives' OEMs cooperation:
* https://www.cbc.ca/news/science/nsa-hid-spying-software-in-h...
Even if you have the type of resources that a big tech corporation like Google has, sooner or later the NSA will get a copy of your data.
It is not intended for providing privacy or security.
My point was that Kenny's claim is that on-drive encryption allows for easier "erasure", presumably by deleting the keys needed to decrypt the data and leaving the drive in the same state.
If that process is good enough to ensure proper "erasure" of the data (effectively complete prevention of data access), then how is it not equally secure as an encryption schema?