Samsung 850 Evo Hardware Encryption & Data Migration/Clone

tacomaguy20

Distinguished
May 2, 2009
41
0
18,530
I have recently upgraded my Samsung 850 Evo Drive to windows 10. This SSD drive comes with hardware encryption but I never encrypted the drive when I first installed it. At that time I just cloned my old hard drive to it. Now I'm thinking I need to encrypt the drive and its suggested to use bitlocker. I have a lot of information/settings on this drive that I don't want to lose but bitlocker says I need to erase and fresh install Windows in order to get bitlocker to work. I do back up system image regularly through Macrium reflect. My question is that if I erase the drive, install a fresh copy of windows, and encrypt with bitlocker, can I use my backup image to clone the drive back and keep the encryption? Essentially I want to encrypt my existing drive/data but it sounds like I may need to go about it in a tough way.

Additionally, I understand that I can do encryption with other software such as Veracrypt. I use that encryption on my SATA drives but I tried it on this drive and it slowed down my SSD drive to a crawl. This Samsung drive also has an TCG Opal encryption option which can be used but I don't know if that is a better option. It seems that I would need special software to run it? Any help or suggestions would be helpful. Thanks
 

USAFRet

Titan
Moderator


BitLocker comes with some versions of Windows, not all of them.
Generally, Pro and above.
 

tacomaguy20

Distinguished
May 2, 2009
41
0
18,530
Yes, I have pro. Any input on my original question? Can I migrate back my data to a Samsung Edrive using bitlocker or are you familiar with the TCG opal software I can use instead? Or can you suggest something other than veracrypt that won't slow down my SSD drive too much that is compatible with windows 10?
 

Palorim12

Distinguished


TCG/OPAL can only really be used by businesses, as the software needed to enable it is only available to businesses.

I've only ever seen in instructions for the E-drive with doing a secure erase and then fresh installing a GPT UEFI installation of Windows. Have you tried the encryption option that's available by enabling an ATA or HDD password on the drive in the BIOS?
 

tacomaguy20

Distinguished
May 2, 2009
41
0
18,530
Yeah I was reading that bios password option is fairly easy to bypass. I understand that Edrive needs a secure erase and a fresh install but what about after that? Can a drive be cloned back to it. Like copying information to it once its encrypted and accessed?
 

Palorim12

Distinguished



There's a big difference between a "BIOS Password" and enabling the AES encryption by setting an "ATA Password" on the BIOS.

Basically, how Samsung has described their process to me:

"You set the ATA password. Your password gets sent to the FW of the drive, which encrypts the password. It then stores it in the NAND, which is seperately encrypted. When you type in a password to unlock the drive, the FW check it against the stored password in the NAND, and if its a match, it unlocks the drive."

And from what I've read, only one guy was able to crack it. He forgot what exactly his password was and it was only because he made a contraption that he set up macros for that would try various combinations of passwords of what he thought might be the correct password. After, i think it was a few days, it finally unlocked because it used the correct password.

Unfortunately the blog where he wrote everything that happened no longer exists...though i managed to find it one time using wayback Machine...

*edit*
Some internetting and i found it! Though the pictures don't load unfortunately: https://web.archive.org/web/20140831005751/http://martynas.bagdonas.net/?p=5