How to securely recycle or dispose of your SSD
backblaze.com
backblaze.com
I don't see a need in 99% of cases, when there are perfectly good ways to permanently delete the data and make it unrecoverable, albeit taking a longer time. No doubt I'll get shot to bits for this with various edge cases where it's important that the data is not recoverable, but the environmental cost of people destroying perfectly good drives because they want to upgrade and think that drilling or thermite is the way forward needs to be taken into account. Yes, it's quick to do the drilling, but is it really necessary when a free piece of software will render the same drive usable but without any real chance of access to the data that's on there?
We live in an increasingly throwaway society, but I'm certain that we will be viewed with true disgust by future generations when they see how knowingly profligate we have been with the resources we had access to.
Unless you're dealing with top-secret material, losing the encryption key is the best way
Or just dd around 5x - 50x (or more if you're paranoid) its size to the disk - if you want to further reuse it. No, you won't have a meaningful amount of data remaining on the disk and extracting it requires special software/hardware. Unless you're dealing with data that makes the disk price irrelevant, you can follow this procedure.
But if you're in the mood for vulgar displays of power, microwave the board or use a Tesla coil
The prize wasn't large, but the challenge got pretty good coverage on tech news sites, so it would have been good PR for any data recovery company.
Nobody accepted the challenge. I think recovering such data is impossible, and I'd be fascinated to be proven wrong - if you know anyone who could do so?
https://www.youtube.com/watch?v=-bpX8YvNg6Y&feature=youtu.be
We shouldn't be encouraging people to use them for as long as possible, we should be encouraging better recycling.
I agree about other electronics though - the constant upgrade cycle is very damaging to the environment.
First: 1) use encryption from day one. As long as you can be assured the encryption never failed (somehow repartitioning and writing bare data to the drive), it is a viable option to treat the drive as non-sensitive, depending on what it was used for.
Then: 2) use ATA secure erase to wipe it. This command, if you believe it was implemented correctly, should wipe the entire drive, including reserved space.
Then: 3a) re-use or re-sell the drives, if you're in a moderate security environment and all of the above have executed correctly. (or send back to a manufacturer if failed in moderate ways which still allow ata secure erase to execute...or if you really trust the disk encryption and it wasn't used for anything sensitive)
or
3b) If the security steps above have failed, or if you've screwed up somehow, or if the drive was used in a policy environment which requires or, or if it was used for the most sensitive of data and you need to convince outsiders of security, or if there's any chance the host the drive was attached to was hacked while in operation (in which case the drive security may have been defeated with new formatting or new firmware), physically destroy the drives in rotary disintegrator. You want to do the above even if you plan to shred them because it reduces security risks and requirements while in transit.
Let's say I have a 100Gb SSD disc and it contains 25Gb of files. If I read in my unencrypted files, encrypt them and write them back to the SSD, they won't necessarily end up in the same physical place as the unencrypted files. Won't the unencrypted files still be there, in unreferenced sectors (do SSD's have sectors?).
I would imagine that writing all zeroes at a low level would do a better job of removing data that is already there.
Only a very advanced attacker is likley to be able to read those reserved sectors and be able to reconstruct data from them.
I'd say you are safe from everyone except the drive manufacturer, state actors, and people with more than $50k to gain from extracting info.
Zeroing out is not entirely secure because at the hardware level a newly zeroed bit might be distinguishable from a bit that was already zero.
Most SSDs with built in encryption don't directly encrypt the data with your password - they encrypt the data with a random password, then encrypt that random password with your password. They do this so you can change your password without having to re-encrypt all the data on the disk (which would be slow, and could cause data loss if there was a failure during the re-encrypt process).
Even when you haven't set a password set on your drive, most SSDs encrypt all the data on the actual flash chips (including reserved space, unused space and spare/reallocated sectors) and just store the random password is unencrypted on the same drive. By activating the on-drive encryption, the random password gets encrypted - making your data unrecoverable.
Of course, on-drive SSD encryption is all unauditable closed source stuff. And the cops have complained much more about iPhone encryption than SSD encryption. Make of that what you will.
Depending on the drive, this is pretty easy. TCG OPAL drives are required to write encrypted data to the media 100% of the time. Seems that you can rekey the drive easily:
https://github.com/Drive-Trust-Alliance/sedutil/wiki/PSID-Re...
It is impossible to reason about the way the storage actually works because it is completely invisible.
If you write a large amount of zeroes, the disk may well only write one sector of zeroes and use some index to show it all over the disk. You'll never know.
If there is a bug in the firmware or someone uploads a different firmware to the controller, it might be possible to retrieve the data you thought was overwritten.
The only way to be sure that the data cannot be retrieved is by encrypting it with a key that is stored in a place where it can be removed.
They have to be rated to survive those temperatures for short periods of time during reflow soldering.
Apparently flash memory is rated to last a minimum of 10 hours baking at 125c, or 360 hours at 85c. The decay is exponential, so in theory 30-60min at 230c should do a lot more damage.
But I'm not sure you should rely on it, that 10 hours @ 125c number is for when the bit-errors exceed the capabilities of the ECC. The data will be partially recoverable for much longer. Or you might have some flash which does a lot better than the minimum spec.
https://www.eeweb.com/blog/eli_tiomkin/industrial-temperatur...
That might get you into a lot of legal problems, [1].
As a private person? I think not so much.
dd if=/dev/urandom of=secret_terror_plan.doc
In the UK that command could get you imprisoned indefinitely, especially if you're under suspicion for other reasons. C:\Windows> COPY README.TXT A:\VIRUS.EXE
(or something very similar), got me permanently kicked out of all computer classes in my high school so I can certainly believe that.Probably even more so in the U.S.
Here's one notable article from almost a year ago but last I checked he's still being held in contempt. https://www.techdirt.com/articles/20160428/07395434297/so-mu...
It's one thing to demand that someone turns over their password but currently AFAIK there's no rigorous proof that the data in question is even encrypted or that the defendant had decrypted it in the past beyond "it was on his computer".
WILL IT BLEND
:)
ps: I am not affiliated in anyway, I just enjoy watching the guy's videos!
Also, I find it disappointing that the GNU "shred" utility [2] apparently does not work as expected.
[1] http://www.noah.org/wiki/Dd_-_Destroyer_of_Disks#caveat_on_F...
[2] https://www.gnu.org/software/coreutils/manual/html_node/shre...
It goes against unix philosophy of a simple tool that only does what it is supposed to do, but some warning from shred that you are using it on FS on which it can't be trusted would be nice.
No.
> Shred It
> Physically destroying the SSD by shredding it into small particles is the absolutely safest, most foolproof method for safe and secure disposal.
A blender is just a homebrew variant, the important part is
> make sure the shred size is small enough to actually destroy the memory chips on your SSD, however. The shred width should be 1/2 inch or less if you want to make sure the chips get properly mashed up.
which a blender doesn't exactly guarantee so you can't use it for "mass" destruction as you'll have to inspect the results and possibly re-blend it until you've ensured sub-half-inch pieces.
It's also a solid excuse to buy a blendtec 800 with sound enclosure for the office -- way quieter than any shredder. And good for making drinks.
Didn't you recommend against drinking electronics dust right at the start of the comment?
- Are the AES keys unique per device?
- Any guarantee that the manufacturer is not keeping a record of serial numbers / AES keys going out the door? (Assuming sealed manufacturer packaging and trust in same when buying.)
- There are some instructions for resetting an AES key after installation. How do I reset an SSD's AES key before installation? Can and how do I use the manufacturer's utility or other means to do so when it is e.g. plugged into an extant system via USB?
- Exact descriptions of how the firmware interacts with BIOS (or UFI, I suppose).
At the moment, I'm trusting to whole-disk software encryption. Not that I have anything particularly concerning to hide (less than most, probably). I considered using the SSD firmware encryption, but I wore out on chasing down such details. Maybe things have improved in this regard, in the meantime, but a few years ago, I didn't manage to chase down clear descriptions and instructions for these things.
Here is a tool written for exactly that (although not intended for securely erasing a drive, it will have that effect too): https://github.com/rentzsch/stressdrive
Isn't it widely suspected the TLA's have backdoors to the encryption used SSD makers? eg depending on who you're wanting to keep things private from, using any built in SSD encryption might not be the right approach.
https://www.alanross.biz/equipment/32778
and
USB sticks the actual flash memory chips have input protection diodes and are quite physically small (limiting the voltage across them), so again I wouldn't be surprised if they survived.
i bet 20 rounds of 12 gauge for $15 would sufficiently pulverize it. Maybe this wasn't written by an american?
What about some kind of acid bath to liquefy the silicon?
Or even our old free plasma generator: bonfires?
I think there are fun/creative/cheap routes not explored in this article.
It says encrypting it and throwing the key away is going to make data unrecoverable.
While thats true for now, what happens when tech reaches the point that current encrypted items can be done within milliseconds?
So yes while encrypting it will make it so that the person that wants to extract information out of it can't do it with the current tech, but whenever a breakthrough on that field will happen then that person will be able to decrypt the SSD.
https://media.ccc.de/v/camp2015-6799-how_to_destroy_a_laptop...
I've watch the video at least 2 times it's great and interesting. :)
I cannot recommend all the CCC media highly enough. ;)