Hacker News new | past | comments | ask | show | jobs | submit login

In case you're wondering if this affects you (I know I was wondering) the relevant command to run is (in an elevated command prompt)

`manage-bde -status <drive_letter>`

Then look at the output for "Encryption Method". If it says something like "XTS-AES 128" I think that means you're using software encryption. If it mentions hardware encryption, then it's using it :) (more info. https://helgeklein.com/blog/2015/01/how-to-enable-bitlocker-...)

FWIW on my Win 10 install with a Samsung PM871 it was set to software encryption.




I never used HW disk encryption (other than TPM) because I always seen it as unnecessary as in it doesn’t really improve on SW+TPM in terms of performance or compatibility and could only cause potential data recovery and security issues.

There is no performance benefit in fact with modern CPUs that have crypto extensions it’s often slower and I never trust commercial solutions ever since you could dump the key from the SanDisk/McAfee “secure” flash drives, and all previous HDD password protection schemes like the ATA passcode were so shit I didn’t even understood why people bothered with them in the first place.


The hw drives absolutely perform better if you have a raid.


Is there a source for that? XTS-AES was actually slower with some of the drives, block chaining for raid is done on the raid logical blocks I don’t see how HW would be faster, in fact until fairly recently HW encryption didn’t really work with raid setups at least those available to consumers.


That was my point. Software aes-Xts gets slow when you use it on a raid.

If you do use it on raid put it under the raid so make one decrypt device for each drive then raid those.


Does anyone have any info on whether this affects Macs as well? I recently bought an external Samsung T5 SSD. I'm using APFS with encryption. Does that mean it is using the broken hw encryption that Samsung provides or is OSX actually doing this properly?


If you are using FileVault you are not affected. The encryption is done in software.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: