full disk encryption is a thing. it's amazing how people who are otherwise technically competent leave such obvious incrementing evidence on computer
full disk encryption is a thing. it's amazing how people who are otherwise technically competent leave such obvious incrementing evidence on computer
Related example: https://en.wikipedia.org/wiki/H._Beatty_Chadwick
https://veracrypt.eu/en/VeraCrypt%20Hidden%20Operating%20Sys...
It just keeps piling up!
Just actually get rid of the evidence. Throw your laptop into a shredder and buy a new one. At least get a new hard drive.
Or at least do a full wipe (including backups) and reinstall. "Here's my FDE key, but I erased everything after I left that place and I don't have their stuff anymore."
I discourage this behavior but there could be many cases when this could be useful.
1. You run rm
2. Your filesystem uses trim to mark the pages as invalid
3. The drive's garbage collector finds blocks containing invalid pages and consolidates valid pages into new blocks and marks the old blocks as invalid.
4. Then the drive resets the block to empty and marks it as available.
This improves write performance because SSDs can only write to empty pages (they cannot overwrite pages that have already been written, instead they'd have to first reset the page and then write a new page) so by proactively resetting pages, they have pages ready to be immediately written.But this also means that the blocks containing your deleted file will be proactively reset/emptied which means it will uncharge the cells which is equivalent to all the bits being `1`, thereby destroying the file.
https://boingboing.net/2013/09/11/how-the-feds-asked-microso...
Some good comments here:
https://old.reddit.com/r/sysadmin/comments/26vm25/why_is_the...
There's more resources on google and I remember attending a talk at either blackhat or defcon on why you shouldn't be using bitlocker.