LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-23-2017, 12:00 PM   #1
linustalman
LQ Guru
 
Registered: Mar 2010
Location: Ireland
Distribution: Debian 12 Bookworm
Posts: 5,717

Rep: Reputation: 479Reputation: 479Reputation: 479Reputation: 479Reputation: 479
Is LUKS far more secure on a HDD than on a SSD with Trim?


Hi.

Is LUKS far more secure on a HDD than on a SSD with trim? How big is the security hit if any?

Thanks.
 
Old 06-23-2017, 12:58 PM   #2
rknichols
Senior Member
 
Registered: Aug 2009
Distribution: Rocky Linux
Posts: 4,779

Rep: Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212Reputation: 2212
It's slightly more secure on the HDD. When you trim the SSD, you reveal what blocks on the drive are not in use. It's a fairly coarse granularity, since those are the "erase blocks" (perhaps 256KB or larger) and not the 4KB filesystem blocks, but if you erased, for example, 200GB of illegal movie downloads, it would be apparent that ~200GB of space had become free. For those so concerned, there is also the issue of the unencrypted low-bandwidth side channel provided by manipulating the amount of free space.
 
Old 06-23-2017, 08:12 PM   #3
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,982

Rep: Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626
I'd think either way would take some time to break into with less than professional industrial or government support. It is possible that one could access the actual chips on a ssd and gather more information that may be there. The average Joe won't get past either easily.

You'd have to suspect that many of the top 500 supercomputers have some workload devoted to ......

Last edited by jefro; 06-23-2017 at 08:14 PM.
 
Old 06-24-2017, 02:55 PM   #4
linustalman
LQ Guru
 
Registered: Mar 2010
Location: Ireland
Distribution: Debian 12 Bookworm
Posts: 5,717

Original Poster
Rep: Reputation: 479Reputation: 479Reputation: 479Reputation: 479Reputation: 479
Question

On a scale of 1 to 10 (10 being unbreakable), how would 'LUKS on SSD + trim' compare in rating to 'Luks on HDD'? A rough estimate?
 
  


Reply

Tags
encryption, luks, ssd, trim



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
TRIM on SSD questions? puppyVT Arch 2 08-13-2016 04:02 PM
How can I use trim with luks+lvm on ssd? pengStudent Slackware 5 05-16-2013 11:15 AM
[SOLVED] Enabling TRIM on ssd jas0n Debian 6 09-08-2012 02:18 PM
ntfs-3g SSD TRIM? qrange Linux - Software 4 07-05-2012 10:00 PM
[SOLVED] TRIM on SSD mira.mikes Linux - Kernel 8 01-08-2011 06:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:35 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration