From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.saout.de ([127.0.0.1]) by localhost (mail.saout.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bTDvVdr3UaLV for ; Fri, 24 Aug 2012 17:54:06 +0200 (CEST) Received: from v4.tansi.org (ns.km33513-03.keymachine.de [87.118.94.3]) by mail.saout.de (Postfix) with ESMTP for ; Fri, 24 Aug 2012 17:54:06 +0200 (CEST) Received: from gatewagner.dyndns.org (84-72-142-78.dclient.hispeed.ch [84.72.142.78]) by v4.tansi.org (Postfix) with ESMTPA id 4E93B206697 for ; Fri, 24 Aug 2012 17:54:06 +0200 (CEST) Date: Fri, 24 Aug 2012 17:54:05 +0200 From: Arno Wagner Message-ID: <20120824155405.GC30694@tansi.org> References: <50379888.7060202@redhat.com> <50379C59.5020908@archlinux.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable In-Reply-To: <50379C59.5020908@archlinux.org> Subject: Re: [dm-crypt] SSDs & flash... and secure keyslot erase List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: dm-crypt@saout.de On Fri, Aug 24, 2012 at 05:23:05PM +0200, Thomas B?chler wrote: > Am 24.08.2012 17:06, schrieb Milan Broz: [...] > > But there is no perfect solution. >=20 > Interesting write-up. If you are really paranoid, it seems you must back > up all data, perform ATA security erase and put the data back on the > disk (and then perform ATA security erase on the backup). That may not be enough, see Section 3.2 of=20 http://cseweb.ucsd.edu/users/swanson/papers/Fast2011SecErase.pdf Unfortunately, no manufacturer names given. My current take is that the only reliable thing is to have LUKS key-slots individually larger than the spare area and then overwrite all free space with random data after a key-slot change. That way the SSD would be unable to hold an old key-slot. For a 240G SSD that may mean key-slots > 16GB each. Also, you cannot be sure how much Flash capacity an SSD actually has without=20 opening it.=20 Arno --=20 Arno Wagner, Dr. sc. techn., Dipl. Inform., Email: arno@wagner.name=20 GnuPG: ID: 1E25338F FP: 0C30 5782 9D93 F785 E79C 0296 797F 6B50 1E25 338F ---- One of the painful things about our time is that those who feel certainty= =20 are stupid, and those with any imagination and understanding are filled=20 with doubt and indecision. -- Bertrand Russell=20