You keep the drive encrypted while you are using it, and then when you want to wipe the data, you just wipe the part of the drive holding data related to computing the encryption key. You don’t touch the rest of the drive, but without the encryption key it’s effectively random noise.
It’s slower to encrypt and then delete the keys than it is to zero the drive, yes. But that’s not how it’s supposed to work.
You encrypt your data (based on the pre-generated key) piecemeal as you fill the drive over the course of years, then you delete the key when retiring the drive, so you can make a drive unreadable in seconds.
If the disk has built in encryption, so the storage controller on the disk handles the encrypt/decrypt cycle but presents as an unencrypted disk for all intents and purposes to the user. All thats needed to wipe the disk is to delete the encryption keys. Its a pretty common feature in enterprise disks and i quite like it. Saves a lot of time when decom time rolls arround
You don’t need to encrypt empty disk space. Formatting a disk only writes some data structures here and there, leaving vast majority of the disk unchanged.
I don’t know how you manage to keep being confused about this whole deal. When you buy a disk, you don’t care what’s in the empty space. You format it as an encrypted disk by writing a few sectors. When you want to throw it out, you delete the keys that decrypt what you wrote over the life of the disk, and perhaps wipe the sectors containing encryption metadata. What is unclear about this?
Besides, when the disk is configured as encrypted, the junk in the empty sectors can’t be read by decrypting it. Unless it’s software encryption and you bypass it by poking the disk directly, you can’t read anything from those sectors. Which, again, contain either noise, or what the possible previous owner has written there.
The key is in firmware which is setup before you write any data. So to “delete” any data you simply wipe the key.
Even if you use software to encrypt the drive luks would just mean any data written to the drive would be encrypted. Old data my zeroed out could technically be ready unless overwritten.
In either case your weirdly aggressive statement is wrong.
How computing a result from a ?4096?bits key for each byte goes faster than writing 0 for each byte?
You keep the drive encrypted while you are using it, and then when you want to wipe the data, you just wipe the part of the drive holding data related to computing the encryption key. You don’t touch the rest of the drive, but without the encryption key it’s effectively random noise.
It’s slower to encrypt and then delete the keys than it is to zero the drive, yes. But that’s not how it’s supposed to work.
You encrypt your data (based on the pre-generated key) piecemeal as you fill the drive over the course of years, then you delete the key when retiring the drive, so you can make a drive unreadable in seconds.
If the disk has built in encryption, so the storage controller on the disk handles the encrypt/decrypt cycle but presents as an unencrypted disk for all intents and purposes to the user. All thats needed to wipe the disk is to delete the encryption keys. Its a pretty common feature in enterprise disks and i quite like it. Saves a lot of time when decom time rolls arround
You are jumping to a point in time after what I am asking:
“all you need” is to delete a key -> No, you need to encrypt the disk before, which is the step prior, and without it, deleting a key change a thing…
So basically, the part “hardware” built-in could make sense, but the guy didn’t specify any if this…
In other words, zeroing the disk is going to be faster “in normal circumstances”.
You don’t need to encrypt empty disk space. Formatting a disk only writes some data structures here and there, leaving vast majority of the disk unchanged.
The whole problem and why people are zeroing is that “empty space” is not really empty.
I don’t know how you manage to keep being confused about this whole deal. When you buy a disk, you don’t care what’s in the empty space. You format it as an encrypted disk by writing a few sectors. When you want to throw it out, you delete the keys that decrypt what you wrote over the life of the disk, and perhaps wipe the sectors containing encryption metadata. What is unclear about this?
Besides, when the disk is configured as encrypted, the junk in the empty sectors can’t be read by decrypting it. Unless it’s software encryption and you bypass it by poking the disk directly, you can’t read anything from those sectors. Which, again, contain either noise, or what the possible previous owner has written there.
The key is in firmware which is setup before you write any data. So to “delete” any data you simply wipe the key.
Even if you use software to encrypt the drive luks would just mean any data written to the drive would be encrypted. Old data my zeroed out could technically be ready unless overwritten.
In either case your weirdly aggressive statement is wrong.