Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

On a clear disk you can seek forever.


computers / alt.os.linux.mageia / Re: Hdparm issue with Samsung EVO 870 drive

SubjectAuthor
* Hdparm issue with Samsung EVO 870 driveMarkus Robert Kessler
+* Re: Hdparm issue with Samsung EVO 870 driveMarco Moock
|`- Re: Hdparm issue with Samsung EVO 870 driveMarkus Robert Kessler
+* Re: Hdparm issue with Samsung EVO 870 driveDavid W. Hodgins
|`* Re: Hdparm issue with Samsung EVO 870 driveMarkus Robert Kessler
| +* Re: Hdparm issue with Samsung EVO 870 driveSjouke Burry
| |`* Re: Hdparm issue with Samsung EVO 870 driveMarkus Robert Kessler
| | `* Re: Hdparm issue with Samsung EVO 870 driveWilliam Unruh
| |  `- Re: Hdparm issue with Samsung EVO 870 driveDaniel65
| `- Re: Hdparm issue with Samsung EVO 870 drivePaul
`* Solved: Hdparm issue with Samsung EVO 870 driveMarkus Robert Kessler
 `- Re: Solved: Hdparm issue with Samsung EVO 870 driveDavid W. Hodgins

1
Hdparm issue with Samsung EVO 870 drive

<tf07c0$2uvps$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5107&group=alt.os.linux.mageia#5107

  copy link   Newsgroups: alt.os.linux.ubuntu alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: no_re...@dipl-ing-kessler.de (Markus Robert Kessler)
Newsgroups: alt.os.linux.ubuntu,alt.os.linux.mageia
Subject: Hdparm issue with Samsung EVO 870 drive
Date: Sat, 3 Sep 2022 18:45:20 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 36
Message-ID: <tf07c0$2uvps$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Sat, 3 Sep 2022 18:45:20 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="3b0a1832a8b8d609f0fa12f646828c3a";
logging-data="3112764"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX182/uEPdEHE2oOQNbyOGd1V"
User-Agent: Pan/0.145 (Duplicitous mercenary valetism; d7e168a
git.gnome.org/pan2)
Cancel-Lock: sha1:7NwNeIH1muOTA8gPzndyGGqw7/Y=
 by: Markus Robert Kessle - Sat, 3 Sep 2022 18:45 UTC

Hi all,

I just tried to prepare an external harddisk by setting a password to
make it safe for travelling.

All other harddisks like (older) Samsung, Western Digital, Hitachi etc.
accept locking / unlocking via password through hdparm commands via USB
(kernel 5.10.46 / x64), but Samsung EVO 870 refuses to do so:

$ hdparm --user-master u --security-set-pass 'newpass' /dev/sdb
security_password: "newpass"

/dev/sdb:
Issuing SECURITY_SET_PASS command, password="newpass", user=user,
mode=high
The running kernel lacks CONFIG_IDE_TASK_IOCTL support for this device.
SECURITY_SET_PASS: Invalid argument

B.t.w., I cannot even remove or overwrite the manufacturer's secret
master password. So, this is a severe security risk since someone could
know it and unlock those drives.

Has anyone already managed to lock / unlock such a drive?

Any idea how to proceed?

Thanks a lot!

Best regards,

Markus

--
Please reply to group only.
For private email please use http://www.dipl-ing-kessler.de/email.htm

Re: Hdparm issue with Samsung EVO 870 drive

<tf08gd$2uv4j$2@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5108&group=alt.os.linux.mageia#5108

  copy link   Newsgroups: alt.os.linux.ubuntu alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: mo0...@posteo.de (Marco Moock)
Newsgroups: alt.os.linux.ubuntu,alt.os.linux.mageia
Subject: Re: Hdparm issue with Samsung EVO 870 drive
Date: Sat, 3 Sep 2022 21:04:45 +0200
Organization: A noiseless patient Spider
Lines: 11
Message-ID: <tf08gd$2uv4j$2@dont-email.me>
References: <tf07c0$2uvps$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Injection-Date: Sat, 3 Sep 2022 19:04:46 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="2b4b82699e6c186dd089cdbe8a25a426";
logging-data="3112083"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18a2IBamO6BMwTxAEtRShbv"
Cancel-Lock: sha1:R7N4m2YmoW9k2mVkMog939VJ5PE=
 by: Marco Moock - Sat, 3 Sep 2022 19:04 UTC

Am Samstag, 03. September 2022, um 18:45:20 Uhr schrieb Markus Robert
Kessler:

> I just tried to prepare an external harddisk by setting a password to
> make it safe for travelling.

I can't help you with your problem, but setting this password won't
protect people from accessing it if they know how to remove it. The
data is still unencrypted. I recommend setting up LUKS to encrypt the
data, so you don't need to care about such a password anymore.

Re: Hdparm issue with Samsung EVO 870 drive

<op.1rxonpbya3w0dxdave@hodgins.homeip.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5109&group=alt.os.linux.mageia#5109

  copy link   Newsgroups: alt.os.linux.ubuntu alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: dwhodg...@nomail.afraid.org (David W. Hodgins)
Newsgroups: alt.os.linux.ubuntu,alt.os.linux.mageia
Subject: Re: Hdparm issue with Samsung EVO 870 drive
Date: Sat, 03 Sep 2022 15:05:39 -0400
Organization: A noiseless patient Spider
Lines: 32
Message-ID: <op.1rxonpbya3w0dxdave@hodgins.homeip.net>
References: <tf07c0$2uvps$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed; delsp=yes
Content-Transfer-Encoding: 8bit
Injection-Info: reader01.eternal-september.org; posting-host="fb51a4996d3c6f889c28ebfc89381370";
logging-data="3126679"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+uF69wYtkLM9fK1oU/mVwvMTiez14ZLmo="
User-Agent: Opera Mail/12.16 (Linux)
Cancel-Lock: sha1:Vm/GcZeeWbUo4tRbTCoIi4B4axE=
 by: David W. Hodgins - Sat, 3 Sep 2022 19:05 UTC

On Sat, 03 Sep 2022 14:45:20 -0400, Markus Robert Kessler <no_reply@dipl-ing-kessler.de> wrote:

> Hi all,
>
> I just tried to prepare an external harddisk by setting a password to
> make it safe for travelling.
>
> All other harddisks like (older) Samsung, Western Digital, Hitachi etc.
> accept locking / unlocking via password through hdparm commands via USB
> (kernel 5.10.46 / x64), but Samsung EVO 870 refuses to do so:
>
> $ hdparm --user-master u --security-set-pass 'newpass' /dev/sdb
> security_password: "newpass"
>
> /dev/sdb:
> Issuing SECURITY_SET_PASS command, password="newpass", user=user,
> mode=high
> The running kernel lacks CONFIG_IDE_TASK_IOCTL support for this device.
> SECURITY_SET_PASS: Invalid argument
>
> B.t.w., I cannot even remove or overwrite the manufacturer's secret
> master password. So, this is a severe security risk since someone could
> know it and unlock those drives.
>
> Has anyone already managed to lock / unlock such a drive?
>
> Any idea how to proceed?

Are you using a usb connection?
https://sourceforge.net/p/hdparm/support-requests/7/

Regards, Dave Hodgins

Re: Hdparm issue with Samsung EVO 870 drive

<tf0juo$303dn$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5110&group=alt.os.linux.mageia#5110

  copy link   Newsgroups: alt.os.linux.ubuntu alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: no_re...@dipl-ing-kessler.de (Markus Robert Kessler)
Newsgroups: alt.os.linux.ubuntu,alt.os.linux.mageia
Subject: Re: Hdparm issue with Samsung EVO 870 drive
Date: Sat, 3 Sep 2022 22:20:08 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 61
Message-ID: <tf0juo$303dn$1@dont-email.me>
References: <tf07c0$2uvps$1@dont-email.me>
<op.1rxonpbya3w0dxdave@hodgins.homeip.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Sat, 3 Sep 2022 22:20:08 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="6e63021beabc16a45427f83d48367a60";
logging-data="3149239"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18pu2cDnL1vrXl7TbW2r66g"
User-Agent: Pan/0.145 (Duplicitous mercenary valetism; d7e168a
git.gnome.org/pan2)
Cancel-Lock: sha1:+80pbawaX48x/jQnZ0NvwIbyT50=
 by: Markus Robert Kessle - Sat, 3 Sep 2022 22:20 UTC

On Sat, 03 Sep 2022 15:05:39 -0400 David W. Hodgins wrote:

> On Sat, 03 Sep 2022 14:45:20 -0400, Markus Robert Kessler
> <no_reply@dipl-ing-kessler.de> wrote:
>
>> Hi all,
>>
>> I just tried to prepare an external harddisk by setting a password to
>> make it safe for travelling.
>>
>> All other harddisks like (older) Samsung, Western Digital, Hitachi etc.
>> accept locking / unlocking via password through hdparm commands via USB
>> (kernel 5.10.46 / x64), but Samsung EVO 870 refuses to do so:
>>
>> $ hdparm --user-master u --security-set-pass 'newpass' /dev/sdb
>> security_password: "newpass"
>>
>> /dev/sdb:
>> Issuing SECURITY_SET_PASS command, password="newpass", user=user,
>> mode=high The running kernel lacks CONFIG_IDE_TASK_IOCTL support for
>> this device.
>> SECURITY_SET_PASS: Invalid argument
>>
>> B.t.w., I cannot even remove or overwrite the manufacturer's secret
>> master password. So, this is a severe security risk since someone could
>> know it and unlock those drives.
>>
>> Has anyone already managed to lock / unlock such a drive?
>>
>> Any idea how to proceed?
>
> Are you using a usb connection?
> https://sourceforge.net/p/hdparm/support-requests/7/

Yes and no. First, I tried to connect via USB, since this worked for
every other disk I have, but accessing EVO 870 failed.

In the BIOS I could set the user password, but not the factory-set master-
password. So, everyone knowing the master-pw can gain access to the data.
This is inacceptable.

So, I then put it into one of my notebooks and booted from a live dvd
(Mageia 8 / x64).

I could see the drive, but, unfortunately, when the live-dvd is up, there
is no way to set/unset user/master password with hdparm, since prior to
booting, the BIOS has "frozen" the settings of the disk.
There is no "do not freeze the disk" checkbox in my BIOS.

So, currently, I am stuck here. But, anyway, Samsung did not integrate
such an evil backdoor in the former models like EVO 840..860.
Just now, into EVO 870. -- Anyone can tell me why?

Best regards,

Markus

--
Please reply to group only.
For private email please use http://www.dipl-ing-kessler.de/email.htm

Re: Hdparm issue with Samsung EVO 870 drive

<nnd$5e196d0d$49410af8@99268c51e91d016f>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5111&group=alt.os.linux.mageia#5111

  copy link   Newsgroups: alt.os.linux.ubuntu alt.os.linux.mageia
Date: Sun, 04 Sep 2022 00:34:52 +0200
From: burrynul...@ppllaanneett.nnll (Sjouke Burry)
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:17.0) Gecko/20131118 Thunderbird/17.0.11
MIME-Version: 1.0
Newsgroups: alt.os.linux.ubuntu,alt.os.linux.mageia
Subject: Re: Hdparm issue with Samsung EVO 870 drive
References: <tf07c0$2uvps$1@dont-email.me> <op.1rxonpbya3w0dxdave@hodgins.homeip.net> <tf0juo$303dn$1@dont-email.me>
In-Reply-To: <tf0juo$303dn$1@dont-email.me>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Message-ID: <nnd$5e196d0d$49410af8@99268c51e91d016f>
Organization: KPN B.V.
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!feeder.usenetexpress.com!tr2.eu1.usenetexpress.com!94.232.112.245.MISMATCH!feed.abavia.com!abe005.abavia.com!abp001.abavia.com!news.kpn.nl!not-for-mail
Lines: 63
Injection-Date: Sun, 04 Sep 2022 00:34:51 +0200
Injection-Info: news.kpn.nl; mail-complaints-to="abuse@kpn.com"
 by: Sjouke Burry - Sat, 3 Sep 2022 22:34 UTC

On 04.09.22 0:20, Markus Robert Kessler wrote:
> On Sat, 03 Sep 2022 15:05:39 -0400 David W. Hodgins wrote:
>
>> On Sat, 03 Sep 2022 14:45:20 -0400, Markus Robert Kessler
>> <no_reply@dipl-ing-kessler.de> wrote:
>>
>>> Hi all,
>>>
>>> I just tried to prepare an external harddisk by setting a password to
>>> make it safe for travelling.
>>>
>>> All other harddisks like (older) Samsung, Western Digital, Hitachi etc.
>>> accept locking / unlocking via password through hdparm commands via USB
>>> (kernel 5.10.46 / x64), but Samsung EVO 870 refuses to do so:
>>>
>>> $ hdparm --user-master u --security-set-pass 'newpass' /dev/sdb
>>> security_password: "newpass"
>>>
>>> /dev/sdb:
>>> Issuing SECURITY_SET_PASS command, password="newpass", user=user,
>>> mode=high The running kernel lacks CONFIG_IDE_TASK_IOCTL support for
>>> this device.
>>> SECURITY_SET_PASS: Invalid argument
>>>
>>> B.t.w., I cannot even remove or overwrite the manufacturer's secret
>>> master password. So, this is a severe security risk since someone could
>>> know it and unlock those drives.
>>>
>>> Has anyone already managed to lock / unlock such a drive?
>>>
>>> Any idea how to proceed?
>>
>> Are you using a usb connection?
>> https://sourceforge.net/p/hdparm/support-requests/7/
>
> Yes and no. First, I tried to connect via USB, since this worked for
> every other disk I have, but accessing EVO 870 failed.
>
> In the BIOS I could set the user password, but not the factory-set master-
> password. So, everyone knowing the master-pw can gain access to the data.
> This is inacceptable.
>
> So, I then put it into one of my notebooks and booted from a live dvd
> (Mageia 8 / x64).
>
> I could see the drive, but, unfortunately, when the live-dvd is up, there
> is no way to set/unset user/master password with hdparm, since prior to
> booting, the BIOS has "frozen" the settings of the disk.
> There is no "do not freeze the disk" checkbox in my BIOS.
>
> So, currently, I am stuck here. But, anyway, Samsung did not integrate
> such an evil backdoor in the former models like EVO 840..860.
> Just now, into EVO 870. -- Anyone can tell me why?
>
> Best regards,
>
> Markus
>
>
Why not put your data in a password protected
zipfile on the HD?
That way you dont need to block the drive.

Re: Hdparm issue with Samsung EVO 870 drive

<tf0rd5$3134j$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5112&group=alt.os.linux.mageia#5112

  copy link   Newsgroups: alt.os.linux.ubuntu alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: nos...@needed.invalid (Paul)
Newsgroups: alt.os.linux.ubuntu,alt.os.linux.mageia
Subject: Re: Hdparm issue with Samsung EVO 870 drive
Date: Sat, 3 Sep 2022 20:27:16 -0400
Organization: A noiseless patient Spider
Lines: 91
Message-ID: <tf0rd5$3134j$1@dont-email.me>
References: <tf07c0$2uvps$1@dont-email.me>
<op.1rxonpbya3w0dxdave@hodgins.homeip.net> <tf0juo$303dn$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Sun, 4 Sep 2022 00:27:17 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="5f6b65462205c329343591944ef93762";
logging-data="3181715"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/3M//M7tNeSXcPh4D+wIkpumZ/MamDDxo="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:t+fUyh0eja9HsXww1afn3RufVyw=
Content-Language: en-US
In-Reply-To: <tf0juo$303dn$1@dont-email.me>
 by: Paul - Sun, 4 Sep 2022 00:27 UTC

On 9/3/2022 6:20 PM, Markus Robert Kessler wrote:
> On Sat, 03 Sep 2022 15:05:39 -0400 David W. Hodgins wrote:
>
>> On Sat, 03 Sep 2022 14:45:20 -0400, Markus Robert Kessler
>> <no_reply@dipl-ing-kessler.de> wrote:
>>
>>> Hi all,
>>>
>>> I just tried to prepare an external harddisk by setting a password to
>>> make it safe for travelling.
>>>
>>> All other harddisks like (older) Samsung, Western Digital, Hitachi etc.
>>> accept locking / unlocking via password through hdparm commands via USB
>>> (kernel 5.10.46 / x64), but Samsung EVO 870 refuses to do so:
>>>
>>> $ hdparm --user-master u --security-set-pass 'newpass' /dev/sdb
>>> security_password: "newpass"
>>>
>>> /dev/sdb:
>>> Issuing SECURITY_SET_PASS command, password="newpass", user=user,
>>> mode=high The running kernel lacks CONFIG_IDE_TASK_IOCTL support for
>>> this device.
>>> SECURITY_SET_PASS: Invalid argument
>>>
>>> B.t.w., I cannot even remove or overwrite the manufacturer's secret
>>> master password. So, this is a severe security risk since someone could
>>> know it and unlock those drives.
>>>
>>> Has anyone already managed to lock / unlock such a drive?
>>>
>>> Any idea how to proceed?
>>
>> Are you using a usb connection?
>> https://sourceforge.net/p/hdparm/support-requests/7/
>
> Yes and no. First, I tried to connect via USB, since this worked for
> every other disk I have, but accessing EVO 870 failed.
>
> In the BIOS I could set the user password, but not the factory-set master-
> password. So, everyone knowing the master-pw can gain access to the data.
> This is inacceptable.
>
> So, I then put it into one of my notebooks and booted from a live dvd
> (Mageia 8 / x64).
>
> I could see the drive, but, unfortunately, when the live-dvd is up, there
> is no way to set/unset user/master password with hdparm, since prior to
> booting, the BIOS has "frozen" the settings of the disk.
> There is no "do not freeze the disk" checkbox in my BIOS.

Sometimes an add-on card is "unfrozen".

https://commons.wikimedia.org/wiki/File:Noname_JMB363-based_P-_%26_SATA_controller_card.png

I could set an HPA (Host Protected Area) using the
JMB363 on my previous motherboard, whereas
the motherboard BIOS module for the ICH10
SATA ports was "frozen". I've never tried
any password procedures, so cannot even tell
you whether setting a password makes sense.

The Flash memory on that card can be re-flashed.
It can be flashed with RAID or non-RAID code.

What happens when UEFI boots up, is unknown.

The various manufacturers, have either good or bad
BIOS module designers. Perhaps JMicron or ITE might
make unfrozen stuff. I don't know what VIA products
are like (you'd want an 8237-S for it to work anyway).
Asmedia is probably frozen (they tend to be technically
proficient so BIOS code won't leave with holes in it).
Intel is definitely frozen. No reason for AMD
to be any different.

The ability to set an HPA or use one of those
passwords, will not appear in any product documentation.
Intel will not tell you that their SATA ports
are frozen. You have to test it yourself to find out.
On my motherboard (the motherboard that is dead now),
the ICH10 was frozen and useless, whereas the JMB363 allowed
some experiments.

It is a murky topic, poorly documented, and for
people with lots of time and money (for controller cards)
to waste.

The manual page for HDParm, in many cases, is the only
educational material :-)

Paul

Re: Hdparm issue with Samsung EVO 870 drive

<tf1tm3$36k0j$2@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5116&group=alt.os.linux.mageia#5116

  copy link   Newsgroups: alt.os.linux.ubuntu alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: no_re...@dipl-ing-kessler.de (Markus Robert Kessler)
Newsgroups: alt.os.linux.ubuntu,alt.os.linux.mageia
Subject: Re: Hdparm issue with Samsung EVO 870 drive
Date: Sun, 4 Sep 2022 10:12:19 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 83
Message-ID: <tf1tm3$36k0j$2@dont-email.me>
References: <tf07c0$2uvps$1@dont-email.me>
<op.1rxonpbya3w0dxdave@hodgins.homeip.net> <tf0juo$303dn$1@dont-email.me>
<nnd$5e196d0d$49410af8@99268c51e91d016f>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Sun, 4 Sep 2022 10:12:19 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="6e63021beabc16a45427f83d48367a60";
logging-data="3362835"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/arUdNwKCeTRwj6PhFMbat"
User-Agent: Pan/0.145 (Duplicitous mercenary valetism; d7e168a
git.gnome.org/pan2)
Cancel-Lock: sha1:XD3taz7pjvELKUyDoUVtD2sciPE=
 by: Markus Robert Kessle - Sun, 4 Sep 2022 10:12 UTC

On Sun, 04 Sep 2022 00:34:52 +0200 Sjouke Burry wrote:

> On 04.09.22 0:20, Markus Robert Kessler wrote:
>> On Sat, 03 Sep 2022 15:05:39 -0400 David W. Hodgins wrote:
>>
>>> On Sat, 03 Sep 2022 14:45:20 -0400, Markus Robert Kessler
>>> <no_reply@dipl-ing-kessler.de> wrote:
>>>
>>>> Hi all,
>>>>
>>>> I just tried to prepare an external harddisk by setting a password to
>>>> make it safe for travelling.
>>>>
>>>> All other harddisks like (older) Samsung, Western Digital, Hitachi
>>>> etc.
>>>> accept locking / unlocking via password through hdparm commands via
>>>> USB (kernel 5.10.46 / x64), but Samsung EVO 870 refuses to do so:
>>>>
>>>> $ hdparm --user-master u --security-set-pass 'newpass' /dev/sdb
>>>> security_password: "newpass"
>>>>
>>>> /dev/sdb:
>>>> Issuing SECURITY_SET_PASS command, password="newpass", user=user,
>>>> mode=high The running kernel lacks CONFIG_IDE_TASK_IOCTL support for
>>>> this device.
>>>> SECURITY_SET_PASS: Invalid argument
>>>>
>>>> B.t.w., I cannot even remove or overwrite the manufacturer's secret
>>>> master password. So, this is a severe security risk since someone
>>>> could know it and unlock those drives.
>>>>
>>>> Has anyone already managed to lock / unlock such a drive?
>>>>
>>>> Any idea how to proceed?
>>>
>>> Are you using a usb connection?
>>> https://sourceforge.net/p/hdparm/support-requests/7/
>>
>> Yes and no. First, I tried to connect via USB, since this worked for
>> every other disk I have, but accessing EVO 870 failed.
>>
>> In the BIOS I could set the user password, but not the factory-set
>> master-
>> password. So, everyone knowing the master-pw can gain access to the
>> data. This is inacceptable.
>>
>> So, I then put it into one of my notebooks and booted from a live dvd
>> (Mageia 8 / x64).
>>
>> I could see the drive, but, unfortunately, when the live-dvd is up,
>> there is no way to set/unset user/master password with hdparm, since
>> prior to booting, the BIOS has "frozen" the settings of the disk.
>> There is no "do not freeze the disk" checkbox in my BIOS.
>>
>> So, currently, I am stuck here. But, anyway, Samsung did not integrate
>> such an evil backdoor in the former models like EVO 840..860.
>> Just now, into EVO 870. -- Anyone can tell me why?
>>
>> Best regards,
>>
>> Markus
>>
>>
> Why not put your data in a password protected zipfile on the HD?
> That way you dont need to block the drive.

Hi,

this was one my favorite options in the beginning, yes.
But in this case, someone can install trojans, keyloggers etc. to, sooner
or later, get access.

Besides this, the archive can be stolen and be decrypted via cloud
services, no matter, how long it takes. He will get access.

Best regards,

Markus

--
Please reply to group only.
For private email please use http://www.dipl-ing-kessler.de/email.htm

Re: Hdparm issue with Samsung EVO 870 drive

<tf1u5n$36k0j$3@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5117&group=alt.os.linux.mageia#5117

  copy link   Newsgroups: alt.os.linux.ubuntu alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: no_re...@dipl-ing-kessler.de (Markus Robert Kessler)
Newsgroups: alt.os.linux.ubuntu,alt.os.linux.mageia
Subject: Re: Hdparm issue with Samsung EVO 870 drive
Date: Sun, 4 Sep 2022 10:20:39 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 31
Message-ID: <tf1u5n$36k0j$3@dont-email.me>
References: <tf07c0$2uvps$1@dont-email.me> <tf08gd$2uv4j$2@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Sun, 4 Sep 2022 10:20:39 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="6e63021beabc16a45427f83d48367a60";
logging-data="3362835"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+vKY00fPORL4yCR9s4ZZ1I"
User-Agent: Pan/0.145 (Duplicitous mercenary valetism; d7e168a
git.gnome.org/pan2)
Cancel-Lock: sha1:KFEMC4YFwQMq6ggppgszeVEsRu0=
 by: Markus Robert Kessle - Sun, 4 Sep 2022 10:20 UTC

On Sat, 03 Sep 2022 21:04:45 +0200 Marco Moock wrote:

> Am Samstag, 03. September 2022, um 18:45:20 Uhr schrieb Markus Robert
> Kessler:
>
>> I just tried to prepare an external harddisk by setting a password to
>> make it safe for travelling.
>
> I can't help you with your problem, but setting this password won't
> protect people from accessing it if they know how to remove it. The data
> is still unencrypted. I recommend setting up LUKS to encrypt the data,
> so you don't need to care about such a password anymore.

Some years ago, I had to prepare for a business trip and therefore I
tried to do a harddisk encryption.

Well, yes, this did work. But, whenever something went wrong and I had to
simply switch the notebook off, instead of shutting down, the whole thing
crashed and I had to reinstall all.

This happened 2 or 3 times and finally I gave up. I switched to SATA
password and everything was fine :-)

Best regards,

Markus

--
Please reply to group only.
For private email please use http://www.dipl-ing-kessler.de/email.htm

Solved: Hdparm issue with Samsung EVO 870 drive

<tf206m$36k0j$5@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5119&group=alt.os.linux.mageia#5119

  copy link   Newsgroups: alt.os.linux.ubuntu alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: no_re...@dipl-ing-kessler.de (Markus Robert Kessler)
Newsgroups: alt.os.linux.ubuntu,alt.os.linux.mageia
Subject: Solved: Hdparm issue with Samsung EVO 870 drive
Date: Sun, 4 Sep 2022 10:55:18 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 66
Message-ID: <tf206m$36k0j$5@dont-email.me>
References: <tf07c0$2uvps$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Sun, 4 Sep 2022 10:55:18 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="6e63021beabc16a45427f83d48367a60";
logging-data="3362835"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19HNyYAO5jtLVNzodkSCkr1"
User-Agent: Pan/0.145 (Duplicitous mercenary valetism; d7e168a
git.gnome.org/pan2)
Cancel-Lock: sha1:TTHBri6QtTaqc56srXkyAzmsmQw=
 by: Markus Robert Kessle - Sun, 4 Sep 2022 10:55 UTC

On Sat, 03 Sep 2022 18:45:20 +0000 Markus Robert Kessler wrote:

> Hi all,
>
> I just tried to prepare an external harddisk by setting a password to
> make it safe for travelling.
>
> All other harddisks like (older) Samsung, Western Digital, Hitachi etc.
> accept locking / unlocking via password through hdparm commands via USB
> (kernel 5.10.46 / x64), but Samsung EVO 870 refuses to do so:
>
> $ hdparm --user-master u --security-set-pass 'newpass' /dev/sdb
> security_password: "newpass"
>
> /dev/sdb:
> Issuing SECURITY_SET_PASS command, password="newpass", user=user,
> mode=high The running kernel lacks CONFIG_IDE_TASK_IOCTL support for
> this device.
> SECURITY_SET_PASS: Invalid argument
>
> B.t.w., I cannot even remove or overwrite the manufacturer's secret
> master password. So, this is a severe security risk since someone could
> know it and unlock those drives.
>
> Has anyone already managed to lock / unlock such a drive?
>
> Any idea how to proceed?
>
> Thanks a lot!
>
> Best regards,
>
> Markus

Hi all,
many thanks for all your hints!

In the meantime I found more adapters here and accomplished some more
tests.

Just to summarize -- I found the following:

- both, Samsung EVO 840 and 870 can be fully accessed by hdparm through
USB

- both, Samsung EVO 840 and 870 do have a built-in master password (which
should be overwritten prior to use)

- USB-to-SATA adapters from "Logilink" do or do not work. At least, this
one does not support HPA and other hdparm features: SN 39993001701

- Renkforce "SATA Docking Station Cloner" is fully supporting hdparm
command set. So, whenever a machine has to be equipped with a new SSD
that has a master password, and the machine does not allow to disable it
in the BIOS, the password can be set this way.

So, once again, thanks for all your ideas!

Best regards,

Markus

--
Please reply to group only.
For private email please use http://www.dipl-ing-kessler.de/email.htm

Re: Hdparm issue with Samsung EVO 870 drive

<tf2cmb$38e3k$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5121&group=alt.os.linux.mageia#5121

  copy link   Newsgroups: alt.os.linux.ubuntu alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: unr...@invalid.ca (William Unruh)
Newsgroups: alt.os.linux.ubuntu,alt.os.linux.mageia
Subject: Re: Hdparm issue with Samsung EVO 870 drive
Date: Sun, 4 Sep 2022 14:28:28 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 22
Message-ID: <tf2cmb$38e3k$1@dont-email.me>
References: <tf07c0$2uvps$1@dont-email.me>
<op.1rxonpbya3w0dxdave@hodgins.homeip.net> <tf0juo$303dn$1@dont-email.me>
<nnd$5e196d0d$49410af8@99268c51e91d016f> <tf1tm3$36k0j$2@dont-email.me>
Injection-Date: Sun, 4 Sep 2022 14:28:28 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="30da21ad7b61e2c4e3a91d09d61721ea";
logging-data="3422324"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+hy2AdEvooIBScRw+jM3Wl"
User-Agent: slrn/1.0.3 (Linux)
Cancel-Lock: sha1:p+1r/ylC8UNPXWuHUNh10xsxnSA=
 by: William Unruh - Sun, 4 Sep 2022 14:28 UTC

> Hi,
>
> this was one my favorite options in the beginning, yes.
> But in this case, someone can install trojans, keyloggers etc. to, sooner
> or later, get access.
>
> Besides this, the archive can be stolen and be decrypted via cloud
> services, no matter, how long it takes. He will get access.

Nuts. With modern encryption this is just wrong. He will not get access.
The earth will get fried in a supernova or red giant before it is
decrypted, assuming you do not use idiotically weak passwords.

And why would anyone spend that kind of time and effort and money on
your data?

>
> Best regards,
>
> Markus
>
>

Re: Solved: Hdparm issue with Samsung EVO 870 drive

<op.1rzh2tqma3w0dxdave@hodgins.homeip.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5123&group=alt.os.linux.mageia#5123

  copy link   Newsgroups: alt.os.linux.ubuntu alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: dwhodg...@nomail.afraid.org (David W. Hodgins)
Newsgroups: alt.os.linux.ubuntu,alt.os.linux.mageia
Subject: Re: Solved: Hdparm issue with Samsung EVO 870 drive
Date: Sun, 04 Sep 2022 14:38:43 -0400
Organization: A noiseless patient Spider
Lines: 21
Message-ID: <op.1rzh2tqma3w0dxdave@hodgins.homeip.net>
References: <tf07c0$2uvps$1@dont-email.me> <tf206m$36k0j$5@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed; delsp=yes
Content-Transfer-Encoding: 8bit
Injection-Info: reader01.eternal-september.org; posting-host="e84042fe62fc55e03ca058fd1f2f57ec";
logging-data="3470759"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+iRVa8GsWzUnOdJGEpdtZAIRdpuY9px40="
User-Agent: Opera Mail/12.16 (Linux)
Cancel-Lock: sha1:A+YIM6g3BoT/O6Lpsh7bB5OKRUA=
 by: David W. Hodgins - Sun, 4 Sep 2022 18:38 UTC

On Sun, 04 Sep 2022 06:55:18 -0400, Markus Robert Kessler <no_reply@dipl-ing-kessler.de> wrote:
> So, once again, thanks for all your ideas!

Glad you got it working. One thing I'd like to clarify. Using "hardware" based
encryption does not provide any extra security over using software based
encryption.

The "hardware" based encryption is just using software that is stored in the
firmware of the device, which you may or may not be able to update when
problems are found. The only benefit of using it is that an attacker has to
have a similar drive, and the tools/skill needed to switch parts from one
drive to another to access the encrypted data.

Once they have access to the encrypted data, the software used in the firmware
is more likely to have un-patched flaws that can be exploited, then up-to-date
file system encryption software such as luks.

A major drawback of hardware based encryption is that it can make it much more
difficult to move storage from one computer to new one if the old computer fails.

Regards, Dave Hodgins

Re: Hdparm issue with Samsung EVO 870 drive

<tf4kd4$3i8kv$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5125&group=alt.os.linux.mageia#5125

  copy link   Newsgroups: alt.os.linux.ubuntu alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: danie...@nomail.afraid.org (Daniel65)
Newsgroups: alt.os.linux.ubuntu,alt.os.linux.mageia
Subject: Re: Hdparm issue with Samsung EVO 870 drive
Date: Mon, 5 Sep 2022 20:52:20 +1000
Organization: A noiseless patient Spider
Lines: 30
Message-ID: <tf4kd4$3i8kv$1@dont-email.me>
References: <tf07c0$2uvps$1@dont-email.me>
<op.1rxonpbya3w0dxdave@hodgins.homeip.net> <tf0juo$303dn$1@dont-email.me>
<nnd$5e196d0d$49410af8@99268c51e91d016f> <tf1tm3$36k0j$2@dont-email.me>
<tf2cmb$38e3k$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 5 Sep 2022 10:52:20 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="f2f94fe8bbc2a0759ee2f969eb474eae";
logging-data="3744415"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+skkGBK+TgIYBrsFDnDQ7n0+OtGgwicKA="
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101
SeaMonkey/2.53.13
Cancel-Lock: sha1:Fk6qdN+BBH/KdmOT+CC50JJwrxs=
In-Reply-To: <tf2cmb$38e3k$1@dont-email.me>
 by: Daniel65 - Mon, 5 Sep 2022 10:52 UTC

William Unruh wrote on 5/9/22 12:28 am:
>> Hi,
>>
>> this was one my favorite options in the beginning, yes.
>> But in this case, someone can install trojans, keyloggers etc. to, sooner
>> or later, get access.
>>
>> Besides this, the archive can be stolen and be decrypted via cloud
>> services, no matter, how long it takes. He will get access.
>
> Nuts. With modern encryption this is just wrong. He will not get access.
> The earth will get fried in a supernova or red giant before it is
> decrypted, assuming you do not use idiotically weak passwords.
>
> And why would anyone spend that kind of time and effort and money on
> your data?

EXACTLY!! Back in the 80's/90's, I was in Australian Army, dealing with
Radio and Crypto equipment.

At one stage, I was told that the daily crypto-keys (64 or 128 bit, I
think) they were using then were rated as good for 25-28 hours because
it would take the bad guys that long to break the code!!

Sure, the code-breaker equipment has gotten better/faster, but so too
then has the Crypto-Equipment.

And all just to find out that someone was being posted somewhere else!! ;-P
--
Daniel

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor