this post was submitted on 22 Oct 2023
387 points (95.3% liked)

Technology

58137 readers
5011 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Tested: Windows 11 Pro's On-By-Default Encryption Slows SSDs Up to 45%::Windows 11 Pro defaults to BitLocker being turned on, using software encryption. We've tested the Samsung 990 Pro with hardware encryption to show how the various modes impact performance, and how muc

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 32 points 11 months ago (2 children)

Why is there zero need in desktops?

[–] [email protected] 19 points 11 months ago (3 children)

Presumably you're relying on the security of your home, and if that's broken you've got bigger things to worry about.

[–] [email protected] 34 points 11 months ago (1 children)

I don't buy this. If my home security is compromised I have big issues, but my data security is probably one of the biggest. If my desktop gets yoinked or HD plucked, the degree of identity theft that could be pulled off is simply massive. I can think of little better peace of mind than knowing my HD was well encrypted if my home was violated.

[–] [email protected] 1 points 11 months ago (1 children)

Yeah I do agree and myself run FDE as a defence in depth measure and as a protection against specific threats such as the one you mentioned. I think we agree on that completely.

In saying that, I would further add that it shouldn't be relied upon as the only defensive measure as once someone has gained physical access to the device it's not going to protect you against targeted attacks. If someone has access to your home they could install a camera aimed at the keyboard, or a hardware keylogger, or the good ol' $5 wrench attack.

[–] [email protected] 4 points 11 months ago (1 children)

I use FDE because my locks are easily pickable. I don’t trust the landlord’s son that lives in the unit above mine. Also the computer is near a big window. Property crime is a popular activity in the area, so the smash-and-grab is a plausible threat. Defence in depth, though, so I still lock the front and interior office doors.

[–] [email protected] 3 points 11 months ago

Good point. Smash & grabs are definitely a valid threat model that FDE can help mitigate the effects of. Can be more or less prevalent due to location and ease of access. Personally, I live in a high rise, access controlled apartment so the smash & grab is a non issue for me.

Another specific threat could be protection against government seizure.

[–] [email protected] 5 points 11 months ago (1 children)

Yeah, but normally FDE overhead is so low, you may as well encrypt.

[–] [email protected] 0 points 11 months ago (2 children)

That's one issue I had with this article. It doesn't do any actually tests to compare it to other OS implementations. How can we condemn Microsoft for 45% slower speeds (in a specific benchmark on specific hardware) when there's no context to compare it to? And this claim is specifically only for software encryption where hardware level encryption is not available. Is it Windows 11 that's specifically causing this, or is it a general problem?

[–] [email protected] 2 points 11 months ago (1 children)

Comparing to macOS is actually impossible because fde can’t be turned off on Macs at all. Macs (and iPhones etc.) handle encryption of internal storage transparently in hardware at pretty much no overhead and without the CPU even having access to the key. You can only choose whether a login is required for the Secure Enclave hardware to be able to access the key.

On other platforms it’s pretty much a hardware question too. PC vendors and hard disk vendors could do the same thing Apple is doing regardless of whether the OS is Windows or Linux or whatever. How fast the OS based encryption is only matters on hardware that doesn’t have this functionality.

[–] [email protected] 2 points 11 months ago (1 children)

Exactly right. To me it seems overly clicky baity to specifically condemn Windows 11 for the overhead of software based encryption because the hardware doesn't support it. The same problem exists across all platforms (hypothetically) if there is no hardware support.

It would have been another thing if they could show this problem was unique to Windows 11, or if they focused on the fact that it was difficult to disable. Instead they put so much effort into saying Windows 11 runs 45% slower due to Bitlocker.

[–] [email protected] 2 points 11 months ago

What was telling for me was the article from the same site from a few years ago about Microsoft disabling the use of hardware encryption by default because they couldn't trust the drive manufacturers to do it right.

Do they want things to be secure or fast?

[–] [email protected] -1 points 11 months ago (1 children)

Did you even read the article?

The configuration has a powerful cpu and fast ssd. There are multiple benchmark tools used, and 2 encryption methods, software and hardware.

[–] [email protected] 2 points 11 months ago

Yes I did and everything you pointed out does nothing to address my comment.

It doesn't do any actually tests to compare it to other OS implementations.

Is it Windows 11 that's specifically causing this, or is it a general problem?

How does pointing out that they did tests with different CPUs and SSDs, multiple benchmarking software, and different encryption methods do anything to address my complaint that they did not comment on whether this is a Windows 11 specific issue? Did you even ready comment?

[–] [email protected] 1 points 11 months ago (1 children)

It's largely useful on mobile devices because you can easily forget them somewhere and all a tech savvy person has to do to get the data is remove the HDD (if it's a laptop), or if it's integrated, reset the admin password with something like NT Offline Password Reset. Smartphones are another can of worms I won't get into, but I'm sure you understand.

With a desktop, it's highly unlikely you're carrying it around and will forget it some place. The only way someone can get the drive is to break into your residence and physically remove the drive, and as someone else said: if someone is breaking into your residence to get a HDD out of your PC, you have bigger problems.