Paranoia and deletion: the wipe man page
boingboing.net
boingboing.net
Secondly, new drives reserve a percentage of the room (invisible to the user), in case some of the sectors go bad the controller will re-map them transparently to new sectors. This might leave old data in the old sectors, where you can't normally see it but an investigator armed with the proper ATA commands can. (This isn't a conspiracy of the government and drive manufacturers, it's all there in the ATA spec.) The correct way to securely erase a drive is to send the drive the SECURITY-ERASE command. The drive controller will securely erase every part of the drive. https://ata.wiki.kernel.org/index.php/ATA_Secure_Erase The NSA actually recommends this to other government agencies, so it's probably OK.
This is really the approach that most conspiracy theories take. The fact that we don't know something to be true (but it's very likely to be) is used as an implication that it's probably false.
I'm generally satisfied with df if=/dev/zero of=/dev/sda because I'm not actually dealing with anything that sensitive, but if you are, just take appropriate steps. Defense in depth.
On a related note, I also have zero trust in manufacturer-supplied encryption that sits in the drives. There is no way for me to verify whether it actually does anything.
Warning: I don't know if the fumes are toxic.
If it's schoolwork or unimportant business data, a format is good enough. If we're talking CC and SSN numbers, the ATA command with writing 0's is good. If it's sensitive, a sledgehammer and an anvil is suitable.
I inherited a junk 1G hard drive, and just 'filed it away' in my junk drawer. After years, I actually checked the contents. Lo and behold: a flat database full of medical data, including SSN's and other revealing data. It was only 1G so it got the sledge (I use a small section of railroad tie instead of a blacksmiths anvil).
1) The scope is too large. Too many engineers at hard drive manufacturing companies would have to know about it.
2) Too America-centric. Engineers in foreign countries, that actually build most of the stuff, would know about it. It would be an enormous security gap that they could use as well.
The sad thing is that such paranoid fantasies, that are easy to debunk, blind you to the actual conspiracies, that are less comprehensive, more subtle and therefore much more threatening. I bet the TLA government agencies love these stories.
I am not sure how they broke that disc into so many pieces though, in my experience they are incredibly strong and rigid.
The discs make great wind chimes too.
Harbor Freight has a $3 security bit set if you have drives with special screws.
Not to say spelling corrections are never useful, I think they often are, but I don't understand the mindset that upvotes them over comments that actually participate in the discussion.
- remove top plate of drive - a number of heavy blows with a Sledgehammer. - incineration.
This usually does the trick.
and from the caption it sounds like it actually did that to itself which seems impossible unless maybe the platter was made defectively in the first place ... ? (note it was an "old" 40gb drive - also looks like 2.5 inch)
The best way to sanitize a storage medium is to subject it to tempera-
tures exceeding 1500K. As a cheap alternative, you might use wipe at
your own risk. Be aware that it is very difficult to assess whether
running wipe on a given file will actually wipe it -- it depends on an
awful lot of factors, such as : the type of file system the file
resides on (in particular, whether the file system is a journaling one
or not), the type of storage medium used, and the least significant bit
of the phase of the moon.
But no matter what, wipe is a really great program. Of course this shifts the trust to the computing system,
the CPU, and so on. I guess there are also "traps" in the
CPU and, in fact, in every sufficiently advanced mass-
marketed chip. Wealthy nations can find those. Therefore
these are mainly used for criminal investigation and
"control of public dissent".
I'm unsure in which way a government agency could benefit from having backdoors in the CPU? Even if they did, and even if it could detect that some sort of encryption was going on, where would it store the interesting data?A lot of people are smart enough to format it quickly, but not everyone will let (or know to) a computer sit for dozens of hours so that things might be wiped more securely.
Granted, somehow visiting the craigslist site turns ordinary people into flakes, but the "wiped" statement correlates a bit too well with the vanishing interest.
dd if=/dev/zero of=/dev/hda bs=1M
Wonder if it is going to be slower than wipe.Overwriting it once prevents software reconstruction of the data, but magnetic analysis of the underlying disk itself can reveal (depending on the voltage returned by the resulting 0 or 1) whether the previous value was (within a degree of certainty) a 0 or 1.
It's a counter argument to the urban legend that says data should be wiped multiple times to be truly deleted.
It's worth noting that with today's disks' PRML channels, the signal is barely there already. It's merely "guessed" at (ML in PRML stands for maximum likelyhood). It's seems crazy that anyone could recover something after it's been overwritten. Maybe in the past, but not any more.
Consider though, the data is digital, and error corrected, but it is written onto a fundamentally analog medium. By reading the medium you can easily determine the last written data which then lets you determine to a rather high precision the signal that was used to write that data (because it's all digital). That then allows you to subtract that signal from your analysis without leaving a ton of residual noise. Now perhaps there isn't much left after that, but what is left will be designed to be read even in the midst of noise, because it employs error correction. Who knows what the theoretical limit of such detection is with state of the art technology.
The evidence does tend to argue against any similar techniques of data recovery being used in practice anywhere today. Does that mean you should feel safe?
Much of Feenberg's argument here rests on technology. STM, MFM scanning. Image storage and processing. Tens of terabytes of data would need to be captured and processed, etc. Technology is not static though. What is the likelihood that there will be significant advances in STM/MFM scanning in the near future? In image storage and processing? In storage capacities in the ten terabyte range? For all of these it's a near certainty that we will continue to see exponential advances for the foreseeable future.
So perhaps abandoning your hard-drive that has been "wiped" once to the vagaries of the world is a safe bet today. But what happens in 10, 20, 30 years when all of those technologies have advanced remarkably and it is not only possible but perhaps even trivial to recover data on such drives? That is the conundrum.
Generally speaking, if you think your drives have contained material which you do very much wish to remain confidential in perpetuity, it probably makes sense to destroy old hard-drives rather than re-sell them. Though the cost/benefit trade-off may be a bit different if you are a business with a lot of data.
Having said that, like many others in this discussion, I'm skeptical of how practical data recovery really is vs. a theoretical issue. I'm guessing that the value of the data has to be extremely high before it would be worth while going to the necessary lengths.
It is usually much easier to use a $5 wrench, ref: http://xkcd.com/538/.
He more or less said that recovering all the data from a hard drive that cannot be read with its read/write head (either the original or a spare) would not be feasible or economical for his company. He said it would take several years. (And that’s without even considering overwritten data.)
When asked what’s the best way to destroy data forever he said that overwriting the data once is sufficient in any case. I take from this that at least his company and presumably other data recovery companies cannot read data that was overwritten once, even in principle (i.e. it’s not just a question of throwing enough resources at it). I have my doubts that the government has capabilities beyond that.
[1] Link to mp4 (h.264): http://mirror.fem-net.de/CCC/27C3/mp4-h264-HQ/27c3-4231-en-d...; link to slides: http://events.ccc.de/congress/2010/Fahrplan/events/4231.en.h...
The companies that do it charge several thousand an hour, IIRC. (this was back in the 90s?)
Depending on the non-spinning disk type in question, it can be either more or less secure than the usual magnetic HDD. You've got "flash" but that's just a nice word for any number of highly-differing technologies such as MLC and SLC on the inside. And you have NAND vs NOR techs to consider as well.
Perhaps the security in non-magnetic-HDDs comes from the fact that they're so new to the table, not many specialize in restoring data from them.
/dev/urandom
will suffice. But its going to be slow.Overwriting does not completely destroy old data. You can think of it as repainting a wall with a single coat of paint. You can still vaguely see the old coat of paint under it. The magnetic domains can also migrate away from the read/write head either to the side of the track or deeper down into the magnetic material, where they can linger for a longer time. Overwritten data is typically not recoverable with the normal read/write head, but an attacker who takes apart a disk drive and uses specialized equipment might be able to retrieve some or all of the old data.
They also advocate multiple, random overwrites using fresh data as a best practice at this time.
Also, I am not sure that this is guaranteed to overwrite the last part of a disk whose size is not a multiple of 1M. I guess that will depend on how eagerly the device detects ENOSPC conditions.
The Secure Empty Trash function is a frontend for this IIRC.
"I strongly recommend to call wipe directly on the corresponding block device with the appropriate options. However THIS IS AN EXTREMELY DANGEROUS THING TO DO. Be sure to be sober."