Gentoo Archives: gentoo-user

From: tuxic@××××××.de
To: Gentoo <gentoo-user@l.g.o>
Subject: [gentoo-user] new hd: Security / hdparm / differences
Date: Wed, 22 Apr 2020 12:34:20
Message-Id: 20200422123410.czduusdx27bt6mf3@solfire
1 Hi,
2
3 In my system there is a 3T Winchester digital blue
4
5 Model Number: WDC WD30EZRZ-00GXCB0
6 Firmware Revision: 80.00A80
7
8
9 I bougth a second one for backyp purposes
10
11 Model Number: WDC WD30EZRZ-00Z5HB0
12 Firmware Revision: 80.00A80
13
14 Looks pretty simiiar to me...
15
16 The first one is in use for a month or so, I received
17 the second one just two hours ago.
18
19 I want to disable the security feature and the spindown-if-idle
20 feature of the second drive as I did with the first.
21
22 First step was to compare the output of 'hdparm -I <drive>' of the
23 first with that of the second one.
24
25 Differences ( I will skip identical parts ):
26
27 First:
28 Standards:
29 Used: unknown (minor revision code 0x006d)
30 Supported: 10 9 8 7 6 5
31 Likely used: 10
32
33 Second:
34 Standards:
35 Supported: 9 8 7 6 5
36 Likely used: 9
37
38
39
40 First:
41 Formfactor 3.5inch
42
43 Second:
44 Not mentioned
45
46 First
47 Commands/features:
48 Enabled Supported:
49 * DMA Setup Auto-Activate optimization
50 Device-initiated interface power management
51 * Software settings preservation
52 unknown 206[12] (vendor specific)
53 unknown 206[13] (vendor specific)
54 * DOWNLOAD MICROCODE DMA command
55 * WRITE BUFFER DMA command
56 * READ BUFFER DMA command
57
58 Second:
59 Commands/features:
60 Enabled Supported:
61 DMA Setup Auto-Activate optimization
62 * SCT Write Same (AC2)
63 * SCT Features Control (AC4)
64 * SCT Data Tables (AC5)
65 unknown 206[12] (vendor specific)
66 unknown 206[13] (vendor specific)
67 unknown 206[14] (vendor specific)
68
69
70
71 "DMA Setup Ayto-Activate optimization" is enable for the first drive,
72 for second one it is not. The section about this feature in the
73 manpage says "use with extreme caytion" and I cannot decide, whether
74 that what is written there is still valid or some sort of cry
75 from the past.
76
77 I am unsure about to think about these differences...?
78
79 The second thing are the security settings. I want drives with no
80 security settings and no way to manipulate them without user
81 interaction. I want these settings stored in the drive instead
82 of setting them at each boot since the second drive will be
83 temporarily used in a docking station "past boot".
84
85 The current security settings for both drives are:
86 not enabled
87 not locked
88 frozen
89 not expired: security count
90 supported: enhanced erase
91
92 (I have frozen the settings for the second drive just a minute ago and
93 it will forget the settings (going "not frozen" then) as soon I switch
94 the docking station off and on again.)
95
96 If I remember correctly I did this for the frsit drive with:
97 freeze security setting
98 lock security settings
99
100 and I did this without using any password.
101
102 On the second drive "freeze" works as exspected, but "lock"
103 wants a password.
104
105 After startpageing for a while I found a site with "Master passwords
106 for some drives"...and I am unsure of what I have found there
107 (reliability-wise ... it was not via the TOR network, though... ;)
108
109 Currently there are no data on the second drive. So accidentally
110 wiping it off doesn't matter as long the drive remains intact.
111
112 I would prefer to have both drives in the same state.
113 I didn't changed any DMA-related settings for the first drive by the
114 way.
115
116 How should I handle the DMA differences between the frist and the
117 second drive?
118
119 How can I handle the security issue with the second drive?
120
121 Cheers!
122 Meino

Replies

Subject Author
Re: [gentoo-user] new hd: Security / hdparm / differences Michael <confabulate@××××××××.com>