Encrypting the hard drive and then removing the key has a better chance of rendering the data unusable.
You're bang on - you might not know it's been wiped.
99.9999% of people will never need to care about it that much.
[1] https://nascompares.com/2022/09/12/wd-red-pro-22tb-hard-driv...
Everything past those days though, the data is very thoroughly scrambled for spectral whitening before being written to disk so there's no practical difference between /dev/urandom and /dev/zero.
>so a 1TB drive might actually have 2TB worth of flash on it.
That's overly optimistic
It doesn't work as well as you'd think on spinning platters, either. Although it does increase the amount of effort needed to read the data on them.
With the proper equipment and expertise (and helped out by the error correction mechanisms), you can recover a substantial amount of data that has been "overwritten" on an existing track.
This is why "data shredding" applications erase the old data by overwriting it with random data multiple times. That increases the chances that one of those writes will also write over any older data that was shifted slightly to the side.
But that's no guarantee. This problem is why organizations that need an extreme level of security require the complete physical destruction of the platters when decommissioning.
I wasn't, exactly, but I also wasn't correct in the modern day. Retrieving erased information from hard drives like this was certainly a thing (a thing that I myself have seen done, so I know first-hand).
However, after hard drives moved beyond MFM it stopped really being possible.
So what I was saying isn't wrong, exactly, but certainly isn't relevant to today's hardware.
Hard disks don't record zeros and ones...
It's an extremely difficult problem, and in the best case you won't get a complete copy of old data. That's why this isn't an avenue of attack that you're likely to ever encounter.
This is the sort of thing that would only be considered by very wealthy attackers (governments and corporations), and even then only if they're very certain that the drive contains data of unusually high value.
But it is possible, and has been done, to extract useful data that has been overwritten a single time with zeros.
It's not possible, because there's no way to distinguish what the previous value was.
While the second one relies on active attack hiding data for exfiltration, first poses statistically possible scenario where a sector containing sensitive data like password or part of mbox with "We are operating a fucking unlicensed securities exchange in the USA bro" becomes weak read (still fully completed, but slow) and gets remapped. Anyone with PC-3000 can recover this data.
There's almost certainly secure ways to delete. But not worth it for a five year old drive that may have had sensitive information on it.
If you're saving stuff on old MFM drives today, you're probably not in the demographic that cares about wiping drives for disposal.
A 512-byte sector with 100 bytes stuck is "unreadable", but I wouldn't want my secrets to be read out in some raw mode from the 412 good bytes.
There are methods available that will allow recovery of second, third or even fourth generation data to be recovered from magnetic disks. Writing /dev/zero "over" an SSD won't necessarily accomplish what you expect either.
The data is *gone*.
There is no way to recover it. If you know anything about how hard disks work, you'll see why.
There's this theoretical idea that you can get a kind of "latent image" of a mark or a space on the platter even if it's been overwritten, but hard disks haven't written things as literal north-to-south or south-to-north flips for 30 years or so. The data is written as changes of level and phase in a signal, and it's thoroughly scrambled to reduce the chances of a long run of patterns of all zeroes or all ones making the signal hard to recover.
Essentially, you'd be taking a list of floating point numbers, multiplying them all by another much smaller floating point number, adding on another floating point number, and trying to imagine what the original was.
It's not possible.
No, the NSA does not have a big magic machine that does it.