And it is also entirely useless for good amount of data volume-wise on machine.
I never need video game files to be encrypted for example. It's entirely waste of power and CPU time to do it.
And it is also entirely useless for good amount of data volume-wise on machine.
I never need video game files to be encrypted for example. It's entirely waste of power and CPU time to do it.
It’s a political problem not a technical one.
Modern CPUs can do AES faster than your SSD, sometimes faster than an NVME can read/write
To say anything interesting about performance on these modern machines, you would have to benchmark some real workload.
https://calomel.org/aesni_ssl_performance.html
First gen Ryzen (similar age) does 8.2GB/s, which is faster than PCIe 4 NVMe drives.
https://www.vortez.net/articles_pages/amd_ryzen_7_1800x_revi...
Somewhat recent intel i7-12700H does 14.8GB/s, which is about the limit of PCIe 5 NVMe drives.
https://www.notebookcheck.net/Intel-Core-i7-12700H-Processor...
Edit: here's a list of AES speeds via truecrypt. top of the charts is the Ryzen 9 7950X at 32GB/s.
https://www.notebookcheck.net/Benchmarks-and-Test-Results.14...
In the era of mechanical drives and 2 Mbps “broadband” nobody would notice. Now with SSDs and gigabit home internet, people do notice but vendors are still pretending they can just ignore the need to offload encryption.
VPN products and IPsec especially is almost always a disaster in my experience.
When evaluating any kind of network security product like a virtual WAN appliance, tunnel, or whatever, check the throughput. If it can get tens of gigabits for a single stream then it is using some sort of offload. If it seems to hit the wall at around 1.5 Gbps per core, do not buy.
Doing 2.6GB/s in single thread means you have one core less to use...
The penalty is not huge especially compared to fully software implementations but it's not zero. And it takes memory bandwidth too.
I don't use FDE on my gaming system for this reason. It's a big heavy PC that never leaves my house with not really any personal data anyway.
I'm an advocate for FDE across the board (literally all of my devices are on Windows 11 Pro, primarily so I at least have access to Bitlocker across the board), but it's disingenuous to claim that the only alternative to FDE when a device is taken would be to initiate a sector-by-sector wipe. He was responding to ilyt's comment about how only certain data is worth encrypting on pretty much every personal device (and we are talking about Win 11 Pro, not Enterprise).
Why pay cops if I’m not being murdered or robbed?
Why keep nukes behind launch codes, nobody’s trying to launch them?
Why eat every day, I don’t start to die until like 3 days in…
Why pay cops, they're already being bribed by criminals (batman, punisher, etc cops anyway :D )
> Why keep nukes behind launch codes, nobody’s trying to launch them?
Because if you get rid of launch codes you'll decimate the Hollywood Political Thriller movie industry
> Why eat every day, I don’t start to die until like 3 days in…
Why do you hate farmers?
:D