haaarrrryyyyy - you should be all over this one - or are you freaking out wondering how you are going to roll out full disk encryption by tomorrow
https://www.theregister.co.uk/2018/1...sd_encryption/
SSDs from crucial and samsung have been only using the Disk Encryption Key on the hardware to encrypt drives and this can be manipulated via the debugging ports and firmware
worse still bitlocker assumes everything is good and the DEK is derived from the user password
whoops