• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

SSD with encryption

MarshMellow

Weaksauce
Joined
Oct 8, 2009
Messages
81
Has anyone here used a SSD with a software based full disk encryption? I mean the type that works from boot, so the whole operating system is encrypted and you need to enter password at boot (does this software still exist?). What are the speeds like?
 
I've not heard of one, but many motherboards will let you set an option in the BIOS where you have to enter a password to boot to a particular drive. But if the drive is removed and placed in another system, it would boot AFAIK...
 
I've not heard of one, but many motherboards will let you set an option in the BIOS where you have to enter a password to boot to a particular drive. But if the drive is removed and placed in another system, it would boot AFAIK...

He means like TrueCrypt or Safeboot.

I have a 64gb Samsung SSD in my work laptop with Safeboot full disk encryption.
I cannot run a bench tool cause i dont have Admin rights to this machine, but i can say that it is much much better than what i had before.
 
He means like TrueCrypt or Safeboot.

I have a 64gb Samsung SSD in my work laptop with Safeboot full disk encryption.
I cannot run a bench tool cause i dont have Admin rights to this machine, but i can say that it is much much better than what i had before.


How does an encrypted SSD compare to a non encrypted traditional hard drive?
 
the SSD is still Way better.
I have a mediocre SSD thats encrypted and its a better OS drive than my WD 640 Black is.
 
there are also raid cards that do encrytion for entire arrays...for instance the 9260DEpops to mind
 
I think with the way society is heading having a completely encrypted hard drive is the only safe way to be. God knows what will be labeled illegal tomorrow so it is important to me. I would never consider encrypting a normal hard drive because they are slow enough as it is but a SSD opens up doing this.

Are there any issues with data loss? I know due to how encryption works you are prone to MORE data loss if you lose a single byte compared to a non encrypted byte.
 
there are also raid cards that do encrytion for entire arrays...for instance the 9260DEpops to mind
You're supposed to pair it with drives that supports self-encryption. The majority of drives do not support this. You would know if you were buying one that did.
 
I would never consider encrypting a normal hard drive because they are slow enough as it is but a SSD opens up doing this.

So long as your using a decent enough processor (virtually any modern CPU aside from an Intel Atom) then performance degradation from using TrueCrypt on a hard drive is minimal and practically unnoticeable. That's probably true for other full-disk encryption software as well.

I'm not sure about an SSD though; if you have a blazing fast one then it might tax the CPU enough to limit performance. Depending on your setup though it could mean the difference between 200 and 250MB/sec sequential access - which probably won't be noticeable.

Note that full-disk encryption writes to the entire drive when you set it up (at least TrueCrypt does anyway); you'll want to avoid SSDs that degrade significantly in performance when they get filled up.
 
Samsung offers SSDs with Hardware-based Full Disk Encryption (FDE), you can buy them as an option on Dell Latitude notebooks. I have some Seagate FDE.2 notebook drives that I'm experimenting with. Regardless of what some claim, machines with software encryption do take a noticeable performance hit. I'd recommend a self encrypting drive that uses the Trusted Computing Group (TCG)'s Opal standard.

There are a lot of articles out there on it. You can manage them in an enterprise with 3rd party software, or they can be used for personal use in machines that support them (usually enterprise laptops or other types of enterprise machines). Here is a sample link from April 09: http://www.engadget.com/2009/04/16/samsung-comes-clean-with-self-encrypting-ssds/
 
Samsung offers SSDs with Hardware-based Full Disk Encryption (FDE), you can buy them as an option on Dell Latitude notebooks. I have some Seagate FDE.2 notebook drives that I'm experimenting with. Regardless of what some claim, machines with software encryption do take a noticeable performance hit. I'd recommend a self encrypting drive that uses the Trusted Computing Group (TCG)'s Opal standard.

There are a lot of articles out there on it. You can manage them in an enterprise with 3rd party software, or they can be used for personal use in machines that support them (usually enterprise laptops or other types of enterprise machines). Here is a sample link from April 09: http://www.engadget.com/2009/04/16/samsung-comes-clean-with-self-encrypting-ssds/

Actually if it's in hardware I wouldn't trust it at all. At least with something like TrueCrypt you can compile and see the source yourself, notwithstanding that the algorithms themselves may already have been backdoored by their creators.

Maybe I'm jaded but hardware encryption in the past has been incredibly weak and I just don't trust that it is happening like it should be.

If you have a fast enough CPU then you won't really hit any performance limits when it comes to encrypting things as symmetrical encryption is rather quick.
 
So long as your using a decent enough processor (virtually any modern CPU aside from an Intel Atom) then performance degradation from using TrueCrypt on a hard drive is minimal and practically unnoticeable. That's probably true for other full-disk encryption software as well.

Well it will be slower there is no doubting it, and when HDs are already slow then every bit matters.

I'm not sure about an SSD though; if you have a blazing fast one then it might tax the CPU enough to limit performance. Depending on your setup though it could mean the difference between 200 and 250MB/sec sequential access - which probably won't be noticeable.

Well that's the thing, even if you don't get 250 and "only get 200" with a SSD it's still a massive improvement. This is why SSDs are opening this up to me.

Note that full-disk encryption writes to the entire drive when you set it up (at least TrueCrypt does anyway); you'll want to avoid SSDs that degrade significantly in performance when they get filled up.

Good point, I think a recent one about to be released by OCZ is fine even with a full disk. So maybe in a few months this will be viable.
 
Where I work our laptops are required to be encrypted with Check Point Pointsec full disk encryption (not to mention tons of other security bloatware). The performance impact is pretty bad, especially boot times. It used to take me 10 minutes to get a usable desktop with the original HDD the laptop came with. I eventually got this down to around 5 minutes by upgrading to faster drives, including a Seagate Momentus 7200.4, which is just about the fastest laptop drive around at the moment (until it fails anyway). Then, after my second Seagate starting making funny noises and seemed like it was about to die yet again, I dumped it and managed to acquire an Intel X25-M G1.

My old Dell D820 now feels like a new computer. It boots in about a minute and desktop operations are noticeably snappier. Crystal Disk benches are still pretty dismal (40mb/s for large xfers) but for some reason the machine feels much more responsive than the numbers would suggest.

What I don't know is how well the SSD will deal with the disk encryption over time. The Intel SSDs (even the ones without TRIM) are supposed to be the best around for managing drive fragmentation. But, from what I've read, full disk encryption creates access patterns are somewhat different than a normal drive, so it's possible it might confuse Intel's garbage collection algorithms. Everything seems fine so far but it's only been about a month.
 
Where I work our laptops are required to be encrypted with Check Point Pointsec full disk encryption (not to mention tons of other security bloatware). The performance impact is pretty bad, especially boot times. It used to take me 10 minutes to get a usable desktop with the original HDD the laptop came with. I eventually got this down to around 5 minutes by upgrading to faster drives, including a Seagate Momentus 7200.4, which is just about the fastest laptop drive around at the moment (until it fails anyway). Then, after my second Seagate starting making funny noises and seemed like it was about to die yet again, I dumped it and managed to acquire an Intel X25-M G1.

My old Dell D820 now feels like a new computer. It boots in about a minute and desktop operations are noticeably snappier. Crystal Disk benches are still pretty dismal (40mb/s for large xfers) but for some reason the machine feels much more responsive than the numbers would suggest.

What I don't know is how well the SSD will deal with the disk encryption over time. The Intel SSDs (even the ones without TRIM) are supposed to be the best around for managing drive fragmentation. But, from what I've read, full disk encryption creates access patterns are somewhat different than a normal drive, so it's possible it might confuse Intel's garbage collection algorithms. Everything seems fine so far but it's only been about a month.

Thanks for posting your experiences. I think only the newer SSD drives perform well when they are fully loaded so it might be something that improves drastically with the next generation of SSD.
 
Back
Top