Posts

Showing posts with the label Encryption

Self-Encrypting Drives Explained: SED, OPAL and Crypto Erase

A self-encrypting drive performs encryption in hardware on the drive itself, using a controller built into the device. Every write is encrypted and every read decrypted, always, with no software involvement. How it works The drive holds a media encryption key generated on the device and never leaving it. All data on the platters or flash is encrypted with that key from the factory onwards — there is no "enable encryption" step that rewrites existing data. What changes when you enable security is that the media key is itself encrypted with an authentication key derived from a password or supplied by the platform. Without that, the drive will not release the media key and the stored data is unreadable. Two consequences follow, and both are exam points. Enabling encryption is instant. Nothing is re-encrypted; only the key wrapping changes. Compare this with software full-disk encryption, which must read and rewrite every block — hours on a large drive. There is no perfo...

Data in Use Explained: Protecting Data in Memory for Security+

Data exists in three states, and data in use is the one with no easy answer. At rest you encrypt the disk. In transit you encrypt the channel. In use the data is decrypted in memory because the processor has to work on it — and anything with sufficient privilege on that machine can read it. Why it is hard A CPU cannot add two encrypted numbers in the ordinary way. To process data, something must decrypt it, and at that moment plaintext exists in RAM, in CPU registers and caches, and potentially in swap files, crash dumps and hibernation files. That last group is the practical gap. Full disk encryption protects the drive, but a memory dump written after a crash can contain decrypted customer data, and a hibernation file is a copy of RAM written to disk. What attacks it Memory scraping. Malware reading another process's memory for plaintext. The classic case is point-of-sale malware harvesting card data in the moment between the card being read and the transaction being encrypt...