Kanagawa government hard disks swiped, sold online
www3.nhk.or.jp
www3.nhk.or.jp
I looked-up the company's contact info and emailed them. They called the next day and asked for the server's serial number (which I gave them). A few days later one of the company's executives called back and asked me to confirm the serial number (which I did), he said he was holding a certificate of destruction for that server's hard drives and would be taking some action against the contractor that had been hired to destroy them. I had already wiped the data and installed OpenBSD (or was about to).
Anyway, I'm not surprised this type of thing still occurs. To be sure data is not exposed, companies ought to wipe drives themselves and encrypt them before handing them over to contractors. Once the gear is gone, no one knows where it will end up.
Truly ensuring their destruction is going to cost, including but not limited to security guards, people to watch those people, searching through or destroying the trash generated in the building, looking through "parts" to see if they're disassembled hard disks etc.
I can easily angle-grind a HDD in two in my garage, where if I fuck it up no-one would be liable. But it would be quite involved to do the same thing in work, where if I fuck up they'd be liable.
Unless of course your rule is "diligently follow all security policies, but ignore and bypass workplace safety policies" which I would say is a confusing message to give your employees.
Of course, there's no excuse not to dd zeros over the entire disk and, (if it's an SSD) trigger a security-erase with hdparm.
If you don't have a facilities department that is prepared - e.g. with protective gears and an angle grinder or similar power tools, odds are someone will decide it's easier to bypass that process you describe than to get the equipment and do the job properly. It takes firm management by someone who knows and understand the risks and cares about preventing them to ensure it's hard enough to bypass these processes, and hiring someone that takes this seriously just isn't high up on peoples list (e.g. I've never been asked about what approach I'd take to physical security of server infrastructure by anyone wanting to hire me to roles where I'd be responsible for server infrastructure).
At that point, when the platters have been exposed, you're basically done, feel free to scratch them up or smash them with a hammer.
Frankly, having read about this, a once-over pass with dd if=/dev/zero of=/dev/sdX is going to be enough to destroy all data anyway. There is no instance I know of that the theoretical data-recovery techniques proposed to recover after that have been successful in practice, they depended on electron microscopes and 90s platter densities.
Also with defective drives or S.M.A.R.T. failures it’s easier to meet the requirements by physically destroying the medium.
I've run drives with the platters exposed. I've push-started a drive (with a damaged motor) with my fingers and copied data out. You need to destroy the platters properly if you're going to prevent people from getting data out. Even partially damaging platters is insufficient.
> Frankly, having read about this, a once-over pass with dd if=/dev/zero of=/dev/sdX is going to be enough to destroy all data anyway
The problem with that is that you're trusting that people have actually done that, and that nothing went wrong and that the drive firmware was not compromised. If we could trust that people would properly delete the data, then this wouldn't a problem, but the whole point is that we can't. If you're always doing it yourself, and is a low risk enough target to be able to reasonably rule out a compromised system or firmware, then that's a sufficient solution.
That said, a lot of the time, drives are being discarded when they stop working, and people assume they're unrecoverable, and are unable to confirm or overwrite data. Drives like that are a great source of data for anyone prepared to try some repairs.
That surprises me. Recently? And you've done that by transplanting the platters into a new drive? (Assume we wrecked the heads completely when we removed the platters)
> Even partially damaging platters is insufficient.
Really? You've recovered data from part-broken platters that have been removed and scratched or partially shattered?
> The problem with that is that you're trusting that people have actually done that
Sure, but unless the CEO is going to inspect every drive destruction, you're trusting people have actually done the rest too. There's trust here somewhere.
> and that nothing went wrong
You can usually see from the command output if it has.
> and that the drive firmware was not compromised.
If the firmware was compromised all bets are off anyway, the data's already been exfiltrated using spin speed modulation to transmit your data out as audio, as far as you know...
Few years since the last time. I've done that by opening a damaged drive that didn't want to spin up, and "helping" the motor get it started. The first time I tried this was a long, long time ago, and I ran that drive for ~6 months open and exposed, but that time was certainly with far lower densities. I've not tried this with wrecked heads, but given I tried this just by connecting a drive, I'm unwilling to risk assuming damaging the heads is sufficient as well - maybe it is; it certainly would make it harder. I'll happily believe that I've just gotten lucky in getting data out this way, but the point is it's clearly possible whether or not it may be rare for it to work that well, and it's an unnecessary risk.
> Really? You've recovered data from part-broken platters that have been removed and scratched or partially shattered?
Scratches, yes.
Partly shattered I haven't tried; I haven't had a reason to. If you make sure every platter is shattered, then it might well be sufficient. I've yet to see someone enforce shattering plates - most attempts at drive destruction I see tends to be people who haven't even bothered opening the drive, but have just tried destroying it from the outside and ended up damaging PCBs etc. but nothing more (reality is that most IT department in smaller shops don't even have hex tools small enough to open a modern drive); I have never had reason to try to recover data from drives people have made serious attempts at physically destroying the platters properly on.
> Sure, but unless the CEO is going to inspect every drive destruction, you're trusting people have actually done the rest too. There's trust here somewhere.
That's true, but it is easier to enforce visual inspection of a physical object than to try to forensically verify that a drive has been digitally overwritten in a way that is actually meaningful. Of course at some point you have done enough.
More importantly, by insisting on a standard of visual inspection to confirm a drive is destroyed or severely damaged, you ensure the commercial value of the drive itself reduces the incentive to remove drives that may or may not yet have been properly wiped.
> You can usually see from the command output if it has.
Assuming the person doing the destruction cared enough to pay attention.
> If the firmware was compromised all bets are off anyway, the data's already been exfiltrated using spin speed modulation to transmit your data out as audio, as far as you know...
Or it hasn't, and someone replaced it exactly because it's a simple means of bypassing a non-physical destruction process and carry the drives out right in front of security even if someone else needs to sign off on the wipe. It may seem contrived, but replacing firmware is a well enough attack by now that is seems like a pointless risk.
To be clear, I'm not questioning that you can ensure you have wiped the data digitally if you do it yourself and take enough care. But I don't think that is a good basis for a company to set policies around, because it's too hard to enforce once you take into account potential malicious interference and/or profit potential.
Heads are entirely ruined very easily, to the point where I'm not convinced you could insert the platters into a new drive of the same model without wrecking those too.
> Assuming the person doing the destruction cared enough to pay attention.
And we're back to trust. No method works if you have no trust in it being carried out. Including destruction (see the post we're replying to.
Honestly I think, as with most data safety discussions, we're not talking about realistic threat vectors nor about common avenues of attack.
And when we're talking about compromised drive firmware that is smart enough to use one method of exfiltration that neatly suits your argument but not another that doesn't, I think we're not really arguing about anything useful any more.
And yet for that to matter you need to ensure they actually are wrecked. I have no doubt you are able to destroy drives well enough for it to be impossible to get data out. That is not the point.
The point was that a lot of the damage that people think is sufficient to render a drive inoperable isn't. Most drives I've seen that people think they've destroyed does not have destroyed drive heads or shattered plates; most of them have not even been opened.
Maybe you do a proper job at it. But most people don't even know how to do the prerequisite damage.
But when you suggested that just opening the drive is enough, you were wrong.
If I can get data out of a drive that has been opened without any equipment or experience with data recovery, then that's a pretty low bar. Maybe I got lucky, but other people might get lucky too. It's a pointless risk.
Maybe destroying the heads is sufficient - I haven't tried recovering from that, so I don't know, and so I won't claim to know. Unlike when you assumed opening a drive is enough, even though it isn't. But given your assumptions on that are wrong, I don't trust your assumptions about damaging the heads either.
> And we're back to trust
Trust in things that can be verified more easily by less specialized staff matters. Hence why the more thorough physical destruction the better.
> And when we're talking about compromised drive firmware that is smart enough to use one method of exfiltration that neatly suits your argument but not another that doesn't, I think we're not really arguing about anything useful any more.
The one method only requires the drive to return false results that sufficiently convincingly suggests to someone verifying the destruction that the drive is clean. It just requires a pre-prepared firmware update to be downloaded to the drive, pretending to wipe the drive, and walking out with them.
The other is complex and error prone and requires an ongoing communications channel to the outside.
That you even suggest the two are equivalent in complexity is ludicrous.
Zeroing filling a hard drive isn’t hard.
Renting physical hard drives does seem pretty dumb, though.
The hard drives had been used for data sharing servers at the prefectural government office and were replaced with new ones in the spring.
The prefectural government had deleted the data, but the successful bidder of the hard drives was able to restore them by using special software. The government is trying to locate the remaining nine hard drives, which were also sold online in July to August.
The data servers had been leased from Fujitsu Leasing Co., which commissioned Broadlink Co. to scrap the replaced hard drives.
Zero-filling, one-filling, and random-filling all the bits of a hard drive is sufficient to make previous data effectively unretrievable. That doesn’t sound like what happened here.
https://skeptics.stackexchange.com/questions/13674/is-it-pos...
I would bet a lot of money they dragged the files to the "recycle bin" then maybe emptied it
If they were external drives it's likely they were on FAT32 which makes it even easier
It's a way to shift inventory management to the supplier, the alternative would be to employ people to try to sell used 1U servers & components.
Those companies will then pick up your used server, wipe it, and sell it to someone else. Depending on the contract that'll include physically intact hard drives.
`shred --force --zero /dev/sda`
should wipe the whole drive, overwriting 3 times (the default) with random bits and once with all zeroes.
This whole destruction thing is very economically and environmentally nonsensical to me.
This satisfies the infeasibility requirement of NIST SP 800-88 without relying on flash vendors to have appropriately implemented ATA command standards like secure erase, which almost none fully do.
This is also as opposed to relying on the self-encrypting feature on most modern flash. Whether you're dealing with high enough asset value to warrant this level of interest or are just beholden to the same standards, you should reach out to your flash vendor for clarification.
Why rely on hardware encryption, when software encryption is basically free?
Eg:
cryptsetup open --type plain --key-file /dev/urandom --key-size 256 $DEV crypttmp
dd if=/dev/zero of=/dev/mapper/crypttmp bs=4k
[1] https://www.japantimes.co.jp
[2] https://en.m.wikipedia.org/wiki/Category:English-language_ne...
The NHK world news linked in the original article is probably the best place to get Japanese news from a Japanese perspective in English, but you also have to be a bit careful. While the NHK is very similar to the UK's BBC in many ways, news stories are frequently very soft on government policy. So it's sort of the opposite of the Japan Times ;-) The quality in general is much better IMHO, though.
If you don't mind relying on Google Translate (which is getting quite good these days) the TBS news website is very good: https://news.tbs.co.jp/ There is video for most stories and a transcript written under the video. This is actually what I used for studying to learn to understand the news. The quality of the stories vary, but they make a good counterpoint to the NHK. Keep in mind that all Japanese news offices tend to have a cozy relationship with the government, so you need to keep your mind open.
If you have an interest in Japan, keeping abreast of these Japanese news is useful as I have found numerous blatant errors in foreign reporting of Japan -- sometimes to the point where they translate something a Japanese official says exactly the opposite to what they are saying. I don't think this is true only of Japanese news either. World news is full of shenanigans and it really is an eye opening experience to follow the news from the perspective of a different country/culture.
Assuming they were leased, since the client returned them (instead of purchasing them), physicial space may have been a reason.
Well anyway, the US Government has managed to export all my personal data multiple times anyway, this can't be worse than that. The most they'd ever be able to get out of the Kanagawa government is the address where I lived when I was there and probably the license plate to the car I had.