Questions tagged [tcg-opal]

A class of Security Subsystem in TCG Storage Architecture. Defined by Trusted Computing Group (TCG).

Opal Security Subsystem Class (Opal SSC) is a particular class of Security Subsystem for data storage devices. It is one of the classes in Storage Architecture defined by Trusted Computing Group.

16 questions
11
votes
5 answers

How to enable hardware based encryption on Samsung 850 Pro

I have a new Samsung 850 pro which touts hardware-based encryption. According to that page I should just go in my bios and set a hard-drive password (no problem right). The only relevant thread I found on the issue also says something along those…
ErlVolton
  • 328
8
votes
2 answers

Samsung SSD: Hardware encryption and speed

I'm concerned about speed changes of the Samsung MZ-M5E1T0BW 850-EVO when hardware encryption/decryption is enabled. I can't find any information in the data sheets. Do you guys know if there is a (significant) loss of read/write speed when the…
C.M.
  • 191
5
votes
1 answer

How to enable SSD encryption?

I just bought a Samsung EVO 840, which supports AES-256 encryption. Reading the very little documentation that I could find about SSD encryption, I found that I have to enter my BIOS, go to the security tab, select HDD encryption, and set a…
Nathan
4
votes
1 answer

Full disk encryption on Samsung 850 Pro, no UEFI

I've recently upgraded (clean install) to Windows 10 Enterprise. I installed an 850 Pro SSD at the same time. Knowing that this drive could support hardware encryption for Bitlocker, I naively assumed this would just work. I've since realised to my…
user1751825
  • 1,736
3
votes
1 answer

SSD hardware encryption TCG/OPAL - desktop motherboard in 2024

I have Samsung 980 PRO SSD which is advertised to support full drive encryption options like: AES 256-bit Encryption (Class 0), TCG/Opal,IEEE1667 (Encrypted drive) It's not a single case, this days a lot of SSD manufacturers are advertising similar…
2
votes
1 answer

Is it possible to bypass ATA password?

I am using TrueCrypt but I want to buy SSD with SED, it's Samsung 840 Evo. After firmware upgrade it "supports advanced data security features(TCG/Opal and IEEE 1667)". If I set ATA password, would it make my SSD secure enough? I am not talking…
Quak
  • 121
2
votes
2 answers

How to enable Hardware Encryption on Crucial MX500 SSD?

I have bought a 2 TB crucial MX500 SSD drive, and just installed it on a Windows 7 x64 machine, motherboard Gigabyte EP45-DS5 as a data drive. Using the crucial Storage Executive software, I can see on the PSID Revert menu that the PSID revert…
Oliver
  • 285
  • 1
  • 6
  • 14
2
votes
0 answers

SED FDE Samsung 840, 850 EVO in Windows 7 Pro x64. Options to Bitlocker

The goal: In a home computer, to ensure that in the event of theft of drives with or without the computer, that the drives are unreadable. Am wanting to protect financial and personal information. Secondary goal: To have that encryption be hardware…
1
vote
2 answers

How does Windows manage authentication keys for Opal drives?

I want to use a FIPS certified Opal drive on Windows to implement a system with at least one restricted encrypted partition. I want to use the band authentication feature of Opal to restrict access to a particular partition to a single service…
hkc
  • 47
1
vote
0 answers

Is hardware encryption portable to a new machine

I used hardware encryption on my Samsung EVO 850 on a laptop that recently died. The laptop used to ask for a password from the UEFI, before I was able to boot. I still have the password in a password safe, but not the encryption key. I would expect…
Herbert
  • 131
  • 4
1
vote
1 answer

Do the sedutil-cli revert commands also reset the given SID?

In sedutil-cli a sedutil-cli --PSIDrevert "Reset the device to it’s factory defaults using the SID password. If the locking SP is active this command ERASES ALL DATA, requires the SID password" By which I assume it returns all…
0
votes
1 answer

Is it possible to configure bootable NVMe disk as read-only using Opal 2.0 spec?

According to docs, one can set locking range to ro (see setLockingRange <0-15> ). That said, not sure what setLockingRange actually does and wasn’t able to find good documentation. $ sedutil-cli --setLockingRange 0 RO…
sunknudsen
  • 1,060
0
votes
1 answer

Samsung 980 Pro M.2 - Can't enable encrypted drive

I've just installed a new 980 Pro M.2 SSD in my Dell Inspiron 15 7000 Gaming. After re-installing windows 10, I installed Samsung Magician in order to enable Encrypted Drive. In Samsung Magician it tells me there's a compatibility issue with my…
0
votes
1 answer

How should I upgrade an OS on an OPAL encrypted drive?

I'm currently running Kubuntu 17.04 installed on a Samsung NVMe EVO 960 SSD drive. I managed to install it with OPAL encryption enabled by using sedutil, but it took me about 2 days to make it work (I had to compile the image by hand, since the…
0
votes
2 answers

Hardware Encryption and Ubuntu

I am an Ubuntu user and want my SSD (Samsung EVO 850) to be fully encrypted. The problem is that my BIOS does not support the ATA password for some reason. I do not want to lose performance using software-based encryption. Do I have any alternatives…
Max
  • 1
1
2