News:

Buffalo provides Data Recovery services. Read about it here.

Main Menu

How does the full drive encryption work?

Started by wowpow, March 26, 2010, 11:15:49 PM

Previous topic - Next topic

wowpow

   

I'm a bit confused. My Ministation Metro comes comes with "hardware full disk encryption". I noticed that I can set and release the encryption mode at will. This operation is completed very quickly, suggesting that the data on the drive does not actually get encrypted or decrypted when I change the encryption mode.  So, how is the data stored on the media then? If I write to the drive in the Unencryped mode and then set it to Encrypted, would it be possible for someone to recover the data from the drive by removing the drive from the enclosure and analyzing its contents? Conversely, if I write to the drive in the Encrypred mode and then set it to Unencrypted, how is it still possible for the device to read the data from the media without my password?


PCPiranha

It uses 256 AES encryption and it encrypts the drive itself.  In theroy I guess an expert could analyze the files by disassembling the enclosure but it would be incredibly difficult.  From what I am told by fellow co workers it is so difficult to decrypt that even drive savers won't try to decrypt it as it would take so many man hours.


tmorant

#2
Interestingly, I recently had a  MiniStation Extreme USB Portable HDD fail and I sent it to a data recovery company.   They said the drive is not encrypted at all - they can see the data, but the filesystem has been locked using a utility they see on one of the sectors called password.exe.

This would explain how fast the ""encryption"" occurs - its not actually encrypting at all but rather locking the filesystem.   Encryption might still be used though -  but perhaps all that is done is that there's a hash of the password contained on the drive somewhere and password.exe hashes the password the user enters, the two are then compared which unlocks the filesystem.

Tony

breannewiske

Data recovery offline service - it is very expensive.
You can use freeware to do it by yourself.
http://formatdriverecovery.com/

Browser ID: smf (is_webkit)
Templates: 4: index (default), Display (default), GenericControls (default), GenericControls (default).
Sub templates: 6: init, html_above, body_above, main, body_below, html_below.
Language files: 5: index+Modifications.english (default), Post.english (default), Editor.english (default), Drafts.english (default), StopForumSpam.english (default).
Style sheets: 4: index.css, attachments.css, jquery.sceditor.css, responsive.css.
Hooks called: 172 (show)
Files included: 35 - 1354KB. (show)
Memory used: 1046KB.
Tokens: post-login.
Queries used: 16.

[Show Queries]