Why Would an SSD Internally Encrypt Data Without a Password?

why-would-an-ssd-internally-encrypt-data-without-a-password photo 1

While many people actively choose to encrypt their data, others may be surprised to find out that their current drive is doing so automatically without input from them. Why is that? Today’s SuperUser Q&A post has the answers to a curious reader’s question.

Today’s Question & Answer session comes to us courtesy of SuperUser—a subdivision of Stack Exchange, a community-driven grouping of Q&A web sites.

Photo courtesy of Roo Reynolds (Flickr).

The Question

SuperUser reader Tyler Durden wants to know why his SSD internally encrypted data without a password:

I recently had an SSD fail and I am attempting to recover the data. The data recovery company has told me that it is complicated because the built-in drive controller uses encryption. I assume this means that when it writes data to the memory chips, it stores it in an encrypted format on the chips. If this is true, why would an SSD do that?

Why would an SSD internally encrypt data without a password?

The Answer

SuperUser contributor DragonLord has the answer for us:

Always-on encryption allows you to secure your data by setting a password without having to wipe or separately encrypt the data. It also makes it fast and easy to “erase” the entire drive.

  • The SSD does this by storing the encryption key in plain text. When you set an ATA disk password (Samsung calls this Class 0 security), the SSD uses it to encrypt the key itself, so you will need to enter the password to unlock the drive. This secures the data on the drive without having to erase the entire contents of the drive or overwrite all data on the drive with an encrypted version.
  • Having all the data encrypted on the drive also brings another perk: the ability to effectively erase it instantly. By simply changing or deleting the encryption key, all data on the drive will be rendered unreadable without having to overwrite the entire drive. Some newer Seagate hard-drives (including several newer consumer drives) implement this feature as Instant Secure Erase(1).
  • Because modern hardware encryption engines are so fast and efficient, there is no real performance advantage to disabling it. As such, many newer SSDs (and some hard-drives) have always-on encryption. In fact, most newer WD external hard-drives have always-on hardware encryption.

(1) In response to some of the other comments: This may not be entirely secure considering that governments may be able to decrypt AES within the near future. It is, however, generally sufficient for most consumers and for businesses who are trying to reuse old drives.


Have something to add to the explanation? Sound off in the comments. Want to read more answers from other tech-savvy Stack Exchange users? Check out the full discussion thread here.

More stories

How to Quickly Move or Copy Content in Word Using F2

Instead of using the cut and copy commands, “Ctrl + X” and “Ctrl + V”, to move content, you can more quickly move text using fewer keystrokes. Any content, including text, graphics, and tables, can be moved using the “F2” key and the “Enter” key.

What Data Does Android Back Up Automatically?

Much of the data on your Android phone or tablet is backed up by Google (or the individual apps you use) automatically. Your photos can also be backed up automatically, but aren’t by default. However, some data is never backed up automatically.

How to Save Your Smartphone From the Brink of Watery Death

It’s happened again. You were trying to answer a call while washing dishes, and your phone takes a dive straight into the sink. Getting water inside your phone is one of the most devastating ways to watch your mobile device bite the dust, but fear not, all is not lost just yet.

How to Deposit Checks to Your Bank Account Using Your Phone

Much ado has been made in recent years about being able to deposit checks to your bank accounts using your phone’s camera. It works well and is super convenient, so if your bank’s app offers this feature you may want to try it out.

How to Mount ISOs and Other Disc Images on Windows, Mac, and Linux

Disc images have become more useful than ever on modern PCs that often lack CD and DVD drives. Create ISO files and other types of disc images and you can “mount” them, accessing the virtual discs as if they were physical discs inserted into your computer.

Why are PDF Files Generated by Microsoft Word so Large?

When your documents are mainly text only in nature, then it would seem like the file sizes for .docx and .pdf versions should be fairly similar when saved, but that is not always the case. Today’s SuperUser Q&A post has the answer to a curious reader’s questions about the large difference in file