Millions of usable hard drives are being destroyed
bbc.com
bbc.com
https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=91793...
This isn't a sarcastic remark: I think a lot of human activity can be explained this way.
Laptop stolen? What was on it? "zOMG, We Don't KNOW!?!!!1" Was it encrypted? Yes Was the lid closed? Yes Order another laptop and move along.
However. The Linux utility shred can do a multi-pass random rewrite followed by zeros. (That last is critical for the next step) Then to verify, grab a random block and sum the data. If it’s not zero you crush the disk.
Bake that script into a NetBoot image, wipe the boot drive’s boot blocks and reboot.
I decommissioned about $5M worth of servers while preserving the disks. This preserved the hardware for reuse.
If you want to be sure send a random selection of the wiped drives to your data recovery team. They won’t be able to get anything back.
Modern flash devices are supposed to be able to prevent this, the protocol has allowances for it, but I think the risk of stray data remaining on such drives is actually much higher than on HDDs, because there are a lot more relocations in SSDs than on spinning rust, and because you absolutely cannot trust the typical drive firmware to implement any of the parts of the spec that are not required for booting windows, even on supposed "enterprise" drives.
I call bullshit on this, unless you can show me a single example of this ever happening anywhere.
Real world and lab conditions are different.
Given how high stakes somethings can be, nothing would surprise me.
Its why people don't worry about Apple and Privacy/Security. They arent the best in the business, but unless you are a VIP, no one is going to waste the latest 0click pegasus exploit on you.
It does seem far fetched that someone would go to the trouble of putting a 3mm chunk of platter on a testbed only to most likely recover something that may as well be random noise.
Bullshit is too weak a word.
My employer just shredded somewhat new-ish enterprise grade SSD worth a few $M. It hurt to watch :(
* someone didn't prep and use the drives before using OS level encryption
* someone didn't ignore swap space, eg config mistake
* some process was supposed to set up / a person set up, but didn't
Are you going to audit all those drives? It's literally cheaper to just destroy them, far far cheaper.
Try the English slang word for bullshit, bollocks.
Or that if we wish to keep it PG: deceptive nonsense.
There's an ATA command to protect the encryption key with a password (and you'll be asked on boot for the password), but if the password isn't set, there's still an encryption key. Just make that irretrievable and the information is theoretically irretrievable.
But yeah, funny how superstitions still control the world and people still say "The HDD needs to be shredded so we're absolutely sure!"
Today we have secure erase which is necessary to clear SSDs and I doubt there is any actual technology to recover from thia mechanism. A lot of hysteria has been shown around drive clearing in the standards and until the standards reflect the reality of what is really possible and what is really sufficient I can not see companies changing.
Just shred it. You can't mistake a shredded drive for a non shredded drive. The margin for human error is much smaller.
Do remember that winning award is significantly less profitable than selling your secrets to the military.
NSO Group makes more money hacking iphones, than they make on bug bounties.
Do remember that winning award is significantly less profitable than selling your secrets to the military.
NSO Group makes more money hacking iphones, than they make on bug bounties.
(but also I agree with you on the formatting our drives)
You might doubt it, but you also cannot provide much evidence against it. Trim commands just tell the controller to erase data – what they actually do internally isn't easy to discover without a major operation and internal knowledge.
The best bet is not trusting the drives at all, perhaps by storing only encrypted data, then throwing away the key.
1. Nuke the key and an encrypted drive is indistinguishable from noise. 1a. When SAN sizes get STUPIDLY LARGE, miltiple writes are cost and energy prohibitive, crushing is cheap, cert revocation is cheaper and leaves a device with residual value. 2. In the datacenter, data at rest is not a target, the attack happens higher up the stack where the OS/SQL/App can read the data 3. Areal density is such that a drive in a RAID array doesn't have much to offer up*
(* = I'm willing to lose #3 if #1 is utilized.)
But there's always some mouthbreather n00b or auditor or person that took a forensics class once that stands in the way.
The point is: I'm tired of 'well what if?'...that comes up EVERY time there's a question about data destruction....'we should shred it "just to be sure"' is stupid.
Someone without an engineering degree will say it's a bad thing because it seems like pointless waste. Someone with an engineering degree will tell you of reasons why it should be done.
https://www.bloomberg.com/opinion/articles/2022-09-20/morgan...
Last year Morgan Stanley got rid of old computers without wiping them, they were auctioned by the moving company, and it ended up costing Morgan Stanley $35 million in fines.
Does anybody actually want hard drives this old? Isn't the whole point that the risk of failure and therefore data loss is too high by this point? Even if you're using them to store data redundantly, you're running the risk that when one drive fails, the backup will also encounter failure due to the stress of reading its entire contents at once in the attempt to create a new backup.
A hard drive being in warranty or not doesn't indicate much about its likelyhood of working. There's a market for 5 year old hard drives that seem to be working, and at the same time, if you have budget, replacing your hard drives every 5 years will likely get you decent incremental capacity increases.
Statistically I would say it does very much.
https://en.wikipedia.org/wiki/Bathtub_curve
Also drives can start building up bad sectors that you cannot write to, but may be able to read data from.
> Also drives can start building up bad sectors that you cannot write to, but may be able to read data from.
Bad sectors are a pre-failure indicator. It's totally reasonable to stop using drives when they collect enough bad sectors. My threshold is 10 for drives you don't regularly monitor and can't easily replace, and 100 for drives with automated monitoring and simple replacement procedures.
I wasn't ever able to figure out reliable pre-failure indicators for ssds. In my experience they work nearly perfectly, until they disappear, never to respond to commands again. Thankfully, at a much lower rate of failure (per drive) than mechanical disks.
Sure, I would! I frequently use hard drives much older than this, and while I know there's an increased risk of failure, it has never happened to me -- so that risk appears to be quite tiny.
https://www.backblaze.com/blog/how-long-do-disk-drives-last/
The risk is anything but tiny.
"How long do drives last? It would appear a reasonable estimate of the median life expectancy is six years and nine months."
In any case, should a hard drive fail, it's not of great significance because of redundancy and backups. Also, spinning platter drives usually give plenty of warning of impending failures.
Used hard drives remain very attractive to me.
There are RAID levels with N+2 redundancy, or more with some of the fancy stuff.
You're also getting stats from Backblaze, which have the hard drives in a server, constantly powered on, under significant load. A drive that was sitting on a shelf isn't going to be less reliable just because the manufacture date is three years ago and the warranty has expired. A ten year old drive can have the same number of power on hours as a one year old drive.
Moreover, sometimes the data isn't unique. If you need a drive to host a mirror for some Linux distro it's not like you're hosting the only copy in the world.
And if the data is critical, you need better than RAID regardless. What's your plan if a voltage spike takes out multiple drives in the same machine at once? Lightning doesn't care how old your drives are.
Also, fuck Chia. It was supposed to be a low-power "proof of storage", but it's really "proof of prior work" and burns even more energy than proof of work since you need to constantly power the cryptographic calculations AND storage.
For any company dealing with sensitive data, relaying on it to resell seems like a horrible idea. It’s not hard to imagine sufficiently motivated attacker (likely state sponsored) just buying up drives and waiting few years for when they can easily break the encryption.
"Few years" ... "easily" ... yeah, nope.
I'm pretty sure that even 15 year old luks/truecrypt/bitlocker setups are not "easy" to break today, and have very little reason to suspect that current day cryptosystems would be any more likely to get broken in "few years"
"Easily" means very different thing if you talk about script kiddies vs state sponsored actors.
Furthermore this scenario relevant for this thread, decrypting discarded hard drives, has very limited opportunities for complex attacks such as evil maids, cold boots, or other such more active methods.
Notably Snowden said following, and while no doubt some progress has been made since I believe the basic idea be still valid:
> “Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on. Unfortunately, endpoint security is so terrifically weak that NSA can frequently find ways around it.”
While it's challenging (if not impossible) to recover data from most "blanked out" drives, there is often no guarantee that a blanking process actually renders the underlying data unusable. For example, I believe many SSDs will simply mark a block as "unused" rather than physically rewriting the data in that block. When the block gets used again, you simply set it to the new values.
Whether it's practical, right now, to recover data really doesn't matter. These drives are leaving an organization forever. You will have absolutely no control over them. If a technique comes out to recover data from them, you cannot risk having drives floating around that are now recoverable.
Most SSDs (everything that follows the OPAL standard) actually encrypt all data all the time, and support a "secure erase" mode that destroys the encryption key from the TPM and renders the data inert. Copy the flash chips to your heart's content, if you believe the premise of encryption then it'll be a couple million years before you have any chance of cracking the key.
There's no reason this can't also be used on hard drives - or via a higher-level solution like Bitlocker. Again, if you believe in the idea of Bitlocker, then if you lose (or destroy) the key the data is unusable, that's the entire sales pitch of Bitlocker. Drive data is completely inaccessible if removed from their PC and the TPM it contains, and people don't like this because Windows 11 is turning this on by default now.
Physically crushing a drive is needless and wasteful unless you fundamentally disagree that cryptography exists and can work. And it also completely eliminates the possibility that your e-waste vendor is screwing you around behind your back. Fine, have a bunch of white-noise data if you like.
The problem is that businesses like to reduce a 1-in-a-trillion chance to zero, and they're punished if something does happen. And I'm sure hard drive companies like the extra sales and probably nudge them into it too. But it's overall a market failure and a needless e-waste stream, of the kind that the EU does like to eliminate.
At the end of the day, physically destroying something is clear and easily understandable to absolutely anyone who is put in charge of device disposal. No conditionals, no complex configurations. Take the hard drive out and destroy it.
But aside that, regarding the encryption... If you used the drive without encryption at any time, then its possible to recover the unencrypted data. You'd need to guarantee that your drives were *always* used with encryption from the start to end. And that's a hard guarantee.
So yeah, if they were leaving the org, I'd destroy them too.
Decommissioned hardware that is put in storage inevitably walks home with an enterprising employee to whom the risks from the business perspective are simply not a factor.
I just upgraded my 10 year old laptop because I wanted to do AI Art locally.
I ran video games, CAD, cellphone emulators, my programs, etc... on this computer and it still works. Heck, I still use it in a different room now.
Its not the 2000s anymore, we don't need tons of processing power to open web browsers and M$ Office. Decommissioning could be a rare event in the future.
Even if the standard consumer stuff works fine, all the annoying enterprise security and remote management software that you're required to deploy just seems to suck up more and more resources every year. Unless you're lucky enough to work in an industry where that sort of thing isn't needed...
But even if you forget the software side, most office workers don't take great care of their devices. Even a solid ThinkPad will often have bits falling off it after that amount of time.
As to bloat and performance, the standard amount of RAM in a laptop has barely budged in over 10 years. In 2012, a typical consumer laptop might have had 8G RAM and the higher end models 16G RAM.
In 2023, a quick search shows basic home laptops still for sale with 4G RAM, and typical consumer laptops around the $1000 price mark come with 16G RAM as standard.
CPU performance has increased a bit in that time, but not by a whole lot, especially single-threaded. An old laptop might be a bit slow, but it's usually RAM and operating system support which makes it obsolescent. Apps and web pages either fit in memory or they don't; the OS you're running either supports the latest app / browser (and thus web pages) or it doesn't.
Also it's not the useability it's the manufacturing warranty that goes with it. Personal use is a very different thing from business risk.
Keep them and do what with them? If you're an enterprise running many disks, you're generally replacing them with higher capacity disks and the old disks are less useful. Or maybe you have some policy on retiring drives based on age or ssd wear. Or maybe you eliminated a storage tier for whatever reason.
If we had to replace a drive in a computer (or upgrade it from a HDD to SSD), we had to purchase a new drive. We were not allowed to re-use a drive. However, we could re-issue an entire computer to another user.
Makes zero sense, but that's what the compliance industry came up with. It's a money-making deal for everyone involved, except the companies that need to comply with it.
When you do a “secure erase”, the drive will internally regenerate a new key and overwrite it in its NVRAM. Crucially, the algorithm must be securely random and the old key must be reliably overwritten. But if those conditions are met - presto! Everything on the drive that was written with the old key is now unreadable and entirely unrecoverable.
If you actually want to “lock” the drive, the key would be generated by a KDF from the password, the one saved in NVRAM would not be used.
It’s more complicated than that, if you want to support enabling a password without wiping the drive. That would involve encrypting/decrypting a stored key with the password. But either way you can definitely secure erase a modern unlocked drive, if you trust the implementation!
Had this been during something sensitive being displayed, it might warrant shredding that particular monitor. I have no idea how long the phantom image would have lasted. An hour, a day, a year?
Stored in the monitor control board somewhere.
Especially in the VRR era, monitors need to buffer the image in case it needs to be redrawn, or if the transfer rate is faster than the draw rate. Which will be anytime the monitor isn't drawing at max VRR sync speed.
For example, lots of people don't realise how many printers are vulnerable to recovering previously printed documents. In the past, you might have just opened it up and ripped out the hard disk and memory, but nowadays with NAND and DRAM being soldered onto motherboards, do you really trust that's enough?
You can either make hundreds of policies that discover where all this data is, or you make one policy that destroys everything.
I know which one has the least risk.
It was really painful to watch....
I guess I would have trust issues with the services the customer offered.
I imagine that is where a lot of folks are at on this. Basically: It used to be possible, so maybe it still is. Not worth the risk, lets just go with the old best practices to be safe.
Even that has almost always been just a cargo cult. Some people (mainly from the hacker community) claimed that US government agencies can still read data from harddrives that have been erased. It has never been proven by any independent data recovery company.
It might have been somewhat true for MFM or RLL drives (these were before my time in IT), but at least since IDE drives, it was no longer true. However, the cult around "multiple erase cycles" still held, mainly because of companies like Norton etc. who sold snakeoil tools to "securely" erase your data
If you have principles, this is your litmus test. Show everyone that your principles hold even when there's a risk for you (and that risk is only perceived IMO, and not real if you have good procedures in place; and if you don't have those then you are at risk of many other problems).
Personally I don't find it that hard to have a designated "hard drive exit area" where 1-2 guys' job is basically plugging in HDDs and running `shred` on them (which overwrites them with random data in several passes) all day long.
Principles are often in conflict. There are multiple reasonable solutions to this problem.
At some point human error will kick in, a firmware bug will prevent a complete override of the disk, or some new technology will be able to detect overridden data.
There are multiple ways to shred. When you get drives from the bank, they have a semi down in the parking lot doing it on site. Other companies tag each device then document each one getting tossed in the shredder. If one of these devices shows back up after destruction then there is going to be some legal hell to pay.
It's nearly impossible to tell if a disk has been erased by looking at it from the outside. But a shredded device, well that's easy enough.
And running a "shred" with multiple passes requires hardware and electricity to run, which needs to be maintained and scaled to such a level that the process could be done within a reasonable timeframe. Large drives these days could take multiple days each to run plus verification time. And now scale that to thousands of drives. That's a lot of additional hardware and electricity. Where recycling the shredded drive feels more eco friendly. But don't have any actual numbers to support that. Would definitely be interested in actual numbers and how things would play out big picture.
I've only seen their refurbished HDDs.
He's not... HORSING AROUND
You're bang on - you might not know it's been wiped.
99.9999% of people will never need to care about it that much.
Encrypting the hard drive and then removing the key has a better chance of rendering the data unusable.
There's almost certainly secure ways to delete. But not worth it for a five year old drive that may have had sensitive information on it.
If you're saving stuff on old MFM drives today, you're probably not in the demographic that cares about wiping drives for disposal.
>so a 1TB drive might actually have 2TB worth of flash on it.
That's overly optimistic
It doesn't work as well as you'd think on spinning platters, either. Although it does increase the amount of effort needed to read the data on them.
With the proper equipment and expertise (and helped out by the error correction mechanisms), you can recover a substantial amount of data that has been "overwritten" on an existing track.
This is why "data shredding" applications erase the old data by overwriting it with random data multiple times. That increases the chances that one of those writes will also write over any older data that was shifted slightly to the side.
But that's no guarantee. This problem is why organizations that need an extreme level of security require the complete physical destruction of the platters when decommissioning.
I wasn't, exactly, but I also wasn't correct in the modern day. Retrieving erased information from hard drives like this was certainly a thing (a thing that I myself have seen done, so I know first-hand).
However, after hard drives moved beyond MFM it stopped really being possible.
So what I was saying isn't wrong, exactly, but certainly isn't relevant to today's hardware.
Hard disks don't record zeros and ones...
It's an extremely difficult problem, and in the best case you won't get a complete copy of old data. That's why this isn't an avenue of attack that you're likely to ever encounter.
This is the sort of thing that would only be considered by very wealthy attackers (governments and corporations), and even then only if they're very certain that the drive contains data of unusually high value.
But it is possible, and has been done, to extract useful data that has been overwritten a single time with zeros.
It's not possible, because there's no way to distinguish what the previous value was.
[1] https://nascompares.com/2022/09/12/wd-red-pro-22tb-hard-driv...
Everything past those days though, the data is very thoroughly scrambled for spectral whitening before being written to disk so there's no practical difference between /dev/urandom and /dev/zero.
There are methods available that will allow recovery of second, third or even fourth generation data to be recovered from magnetic disks. Writing /dev/zero "over" an SSD won't necessarily accomplish what you expect either.
The data is *gone*.
There is no way to recover it. If you know anything about how hard disks work, you'll see why.
There's this theoretical idea that you can get a kind of "latent image" of a mark or a space on the platter even if it's been overwritten, but hard disks haven't written things as literal north-to-south or south-to-north flips for 30 years or so. The data is written as changes of level and phase in a signal, and it's thoroughly scrambled to reduce the chances of a long run of patterns of all zeroes or all ones making the signal hard to recover.
Essentially, you'd be taking a list of floating point numbers, multiplying them all by another much smaller floating point number, adding on another floating point number, and trying to imagine what the original was.
It's not possible.
No, the NSA does not have a big magic machine that does it.
While the second one relies on active attack hiding data for exfiltration, first poses statistically possible scenario where a sector containing sensitive data like password or part of mbox with "We are operating a fucking unlicensed securities exchange in the USA bro" becomes weak read (still fully completed, but slow) and gets remapped. Anyone with PC-3000 can recover this data.
A 512-byte sector with 100 bytes stuck is "unreadable", but I wouldn't want my secrets to be read out in some raw mode from the 412 good bytes.
Wasn't there an in-depth analysis a while back of (drive) vendor provided encryption, with the end result being that they were pretty shitty implementation that shouldn't be trusted?
This is an ad for cdi.
If you format a hard drive, and sell it on eBay through a generic username, then the person who buys that is not going to do some sort of FBI style forensics on the disk.
It would be like going through every single bin on every high street on the off chance that you happen across some celebrities' bank statements.
Are you really OK with things like your bank account information or health records information or your e-mail history showing up on some rando's hard drive they bought from eBay, because it originally came from a cloud provider?
Maybe until there's 100% disk encryption