Earlier quoted context omitted.
The really clever way to encrypt your drives is to make the passphrase for the drive decrypt a very small (512-bit) header that contains the decryption key for the rest of the drive. Then wiping the drive consists of just erasing those critical bits quickly.
Except that erasure on modern drives rarely actually erases things...
Re: Uber Tries to Remotely Encrypt Corporate Data During Government Raid [ENGLISH]
#11Hence it is advisable to store the encryption key somewhere where erasure was properly accounted for during design, e.G. a TPM (trusted platform module).