crwdns2933423:0crwdne2933423:0
crwdns2918538:0crwdne2918538:0

crwdns2934241:0crwdne2934241:0 Tom Chai

crwdns2934249:0crwdne2934249:0:

1: “First, I’ve read online that once data is marked as unused by the SSD controller, it is no longer encrypted.  “

read online where? it’s nonsense.

2: Trim marks blocks no longer used by the file system ready for recycling, it doesn’t care about what data is in them and made no changes.

3: If all data is encrypted, recovery software is useless unless the software can recover encryption keys, which contradicts the “is encrypted” part, thus logically nonsense.

4: Data recovery software only  works at file system level, it analyzes all blocks addressable and readable, to figure out previous data marked out by the file system. It doesn’t care about anything lower level. Even if the data blocks are still there, the metadata containing the keys are removed, therefore recovery is difficult and if the master key is securely removed, data recovery is impossible.

What CAN be undone by Trim is the deletion of certain master keys if the deletion was not properly handled at physical level. Apple made this kind of mistake back in iPhone 3Gs era, now there is reason to believe that they handle volume or device keys securely and make sure the keys are stored on non-mappable areas or deletion actually goes to the physical blocks instead of being wear-leveling out.

5: Please use carriage return, don’t type all your questions in one  block of mess.

crwdns2915684:0crwdne2915684:0:

open