
I'm not sure about the other vendors, but for HDS data at rest encryption
and secure erase have not been available for 15 years as you say. They have
been available for half a decade and two product generations.

I think all the vendors are supporting full AES 256 encryption. I'm not a
cypher expert but a bit of interesting reading on wiki suggest that brute
force is not going to make the cut in cracking this, and other techniques
require leaks or incomplete implementation of AES 256. The following gave me
a surprise as to the scale of computing and time required for a brute force

        " AES permits the use of 256-bit keys. Breaking a symmetric 256-bit
key by brute force requires 2128 times more computational power than a
128-bit key. A device that could check a billion billion (1E18) AES keys per
second (if such a device could ever be made - as of 2012, supercomputers
have computing capacities of 20 Peta-FLOPS, see Titan. So 50 supercomputers
would be required to process (1E18) operations per second) would in theory
require about 3E51 years to exhaust the 256-bit key space. " from

On average brute force will probably hit pay dirt with half the
permutations, but even if it gets lucky with a hit at just 0.001% of the
keys, that’s still looks like a lot of zeroes and a lot of centuries to me,
even if replacing the supercomputers with cloud, grid or a truckload of
graphics cards doubled the operations per second.

I think there are two things that have changed from 15 years ago. As you
reference, one is that secure erasure became vogue due to the urban myth
that the contents of a disk drive could be completely reconstructed by
reading the bits on a track that were randomly laid down outside the mode
write path of a head. Vendors had to respond to this so that customers
weren't keeping all their disk drives when they sold or traded in a
controller. Sounder heads have prevailed and this idea is being filed away
with some of Ian Fleming's best books, but having a process to erase the
contents of a disk drive with one pass (or more) without a host attached
remains a good idea. Most recently reviewed security standards only require
a single write pass for the track to be considered securely erased.

The second thing that has changed is that encryption has superseded secure
erasure as an acceptable method to secure data on a HDD or SSD once the
drive leaves the data center. There has been some change in physics, such
that relatively cheap ASICs can be installed in the disk array back ends to
process the AES256 cipher without any impact to performance, and I'd suggest
that this followed adoption AES256 relatively quickly. Using encryption from
initial install prevents clear text from being left in remapped sectors and

I guess the moot point is whether you accept that brute force cracking of
AES256 is typically measured in thousands of aeons, and must start with the
resources and planning to run for that time if they don't get lucky in the
first five minutes. 


