Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For SSDs that doesn’t actually guarantee deletion - there could still be some over-provisioned erase blocks that have the old data due to wear leveling.


Apple's SSDs are all encrypted at the controller nowadays. No need to rewrite, just reformat and it cycles the key, leaving any recoverable data irrevocably encrypted (until we break modern encryption).


I thought all SSDs did that for wear-leveling purposes.


They do, but consumer ones usually don't implement the additional API (TCG Opal) that lets you lock/unlock the hardware encryption key. Without that capability you can't use it to implement full-disk encryption. They do usually implement the NVMe secure erase feature though, which will rotate it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: