Gentoo Archives: gentoo-user

From: Michael <confabulate@××××××××.com>
To: Gentoo <gentoo-user@l.g.o>
Subject: Re: [gentoo-user] new hd: Security / hdparm / differences
Date: Wed, 22 Apr 2020 17:16:48
Message-Id: 2481551.BddDVKsqQX@lenovo.localdomain
In Reply to: [gentoo-user] new hd: Security / hdparm / differences by tuxic@posteo.de
1 On Wednesday, 22 April 2020 13:34:10 BST tuxic@××××××.de wrote:
2 > Hi,
3 >
4 > In my system there is a 3T Winchester digital blue
5 >
6 > Model Number: WDC WD30EZRZ-00GXCB0
7 > Firmware Revision: 80.00A80
8 >
9 >
10 > I bougth a second one for backyp purposes
11 >
12 > Model Number: WDC WD30EZRZ-00Z5HB0
13 > Firmware Revision: 80.00A80
14 >
15 > Looks pretty simiiar to me...
16 >
17 > The first one is in use for a month or so, I received
18 > the second one just two hours ago.
19 >
20 > I want to disable the security feature and the spindown-if-idle
21 > feature of the second drive as I did with the first.
22 >
23 > First step was to compare the output of 'hdparm -I <drive>' of the
24 > first with that of the second one.
25 >
26 > Differences ( I will skip identical parts ):
27 >
28 > First:
29 > Standards:
30 > Used: unknown (minor revision code 0x006d)
31 > Supported: 10 9 8 7 6 5
32 > Likely used: 10
33 >
34 > Second:
35 > Standards:
36 > Supported: 9 8 7 6 5
37 > Likely used: 9
38 >
39 >
40 >
41 > First:
42 > Formfactor 3.5inch
43 >
44 > Second:
45 > Not mentioned
46 >
47 > First
48 > Commands/features:
49 > Enabled Supported:
50 > * DMA Setup Auto-Activate optimization
51 > Device-initiated interface power management
52 > * Software settings preservation
53 > unknown 206[12] (vendor specific)
54 > unknown 206[13] (vendor specific)
55 > * DOWNLOAD MICROCODE DMA command
56 > * WRITE BUFFER DMA command
57 > * READ BUFFER DMA command
58 >
59 > Second:
60 > Commands/features:
61 > Enabled Supported:
62 > DMA Setup Auto-Activate optimization
63 > * SCT Write Same (AC2)
64 > * SCT Features Control (AC4)
65 > * SCT Data Tables (AC5)
66 > unknown 206[12] (vendor specific)
67 > unknown 206[13] (vendor specific)
68 > unknown 206[14] (vendor specific)
69 >
70 >
71 >
72 > "DMA Setup Ayto-Activate optimization" is enable for the first drive,
73 > for second one it is not. The section about this feature in the
74 > manpage says "use with extreme caytion" and I cannot decide, whether
75 > that what is written there is still valid or some sort of cry
76 > from the past.
77 >
78 > I am unsure about to think about these differences...?
79 >
80 > The second thing are the security settings. I want drives with no
81 > security settings and no way to manipulate them without user
82 > interaction. I want these settings stored in the drive instead
83 > of setting them at each boot since the second drive will be
84 > temporarily used in a docking station "past boot".
85 >
86 > The current security settings for both drives are:
87 > not enabled
88 > not locked
89 > frozen
90 > not expired: security count
91 > supported: enhanced erase
92 >
93 > (I have frozen the settings for the second drive just a minute ago and
94 > it will forget the settings (going "not frozen" then) as soon I switch
95 > the docking station off and on again.)
96 >
97 > If I remember correctly I did this for the frsit drive with:
98 > freeze security setting
99 > lock security settings
100 >
101 > and I did this without using any password.
102 >
103 > On the second drive "freeze" works as exspected, but "lock"
104 > wants a password.
105 >
106 > After startpageing for a while I found a site with "Master passwords
107 > for some drives"...and I am unsure of what I have found there
108 > (reliability-wise ... it was not via the TOR network, though... ;)
109 >
110 > Currently there are no data on the second drive. So accidentally
111 > wiping it off doesn't matter as long the drive remains intact.
112 >
113 > I would prefer to have both drives in the same state.
114 > I didn't changed any DMA-related settings for the first drive by the
115 > way.
116 >
117 > How should I handle the DMA differences between the frist and the
118 > second drive?
119 >
120 > How can I handle the security issue with the second drive?
121 >
122 > Cheers!
123 > Meino
124
125 Is the second drive connected to the same bus controller? If on a USB docking
126 station hdparm may or may not be able to do what you want - have a look here:
127
128 https://ata.wiki.kernel.org/index.php/ATA_Secure_Erase

Attachments

File name MIME type
signature.asc application/pgp-signature