Hard drive, SSD puncher of physical media with 12 tons of pressure
tomshardware.com
tomshardware.com
Kinda wonder what’s on there. Just because somebody didn’t want anybody to see. Probably just boring business records or something though.
They are coated and only the connectors are exposed.
You are not destroying anything you just make it hard to access
However you're wrong about this. As we know from when capacitors and batteries leak, the acid or alkali in those can get inside chip packaging by being wicked through the leads, which will destroy them thoroughly from the inside as well.
The mild phosphoric acid in your cola beverage is nowhere near strong enough to cause corrosion inside of chip packaging, lol. I doubt that it is even enough to remove a significant quantity of the anodic plating on the chip leads to permit the base metal to be attacked.
If you wanna do it efficiently on scale then something like this is much better option: https://m.youtube.com/watch?v=iqU9QSwHcNg
And for SSDs you'd want something like this: https://phiston.com/product/mediadice-ssd-disintegrator-2c/
For our scale at the time (destroying 10s of drives a month) it worked fine and it was a great stress reliever.
Get off a frustrating customer call? Go take 15 and take it out on the stack of drives needing destruction.
* https://www.nsa.gov/Resources/Media-Destruction-Guidance/NSA...
Who? And why?
Drives are extremely dense. If there were any way to store a value and still have any remnants of the old one, we would have slapped an error-correcting code on it and used that effect to double drive density.
Companies who believe in this magical spare capacity to read values that have been overwritten suffer from an entirely irrational fear. A paranoia that there is always a possibility.
The actual, non-theoretical possibility of recovering customer data is those companies being hacked by bored teenagers or everyday ransomware. Not empty drives.
The much more simple issue, is that drives that have not been erased look exactly like drives that have been erased. Does the drive contain data? Who knows until you hook it up to a computer.
Meanwhile It's very easy to distinguish a drive that has been crushed and can be e-wasted, from a drive that has not been crushed, and can't be e-wasted.
No matter what a drive looks like, you simply erase it again. Does the drive contain data? Send it to erasure one more time, and then it doesn't.
I expect the objection that someone could still mess this up, there is still a risk of an employee being terribly confused and putting a drive directly into the trash, instead of the erase box.
But my point is, if this is a realistic problem with your employees, you have bigger problems. Even if you destroy instead of erasing, your employees could also throw drives into the nearest kitchen trashcan instead of putting them in the destroy box. Your front desk could just let someone through because they had a good story, and they'll make an exception just this time. Your employee clicked on the wrong button and you have ransomware. These are real things that happen every day and result in data leaks.
If erasing drives is too complex to have it handled reliably, the organizational capacity is already too low to handle sensitive data. You will lose the data one way or the other.
Of course, this clarification only matters if your threat model involves dealing with top-secret data and/or nation-state enemies.
I'm not sure if I wasn't clear or if you didn't read my comment correctly.
Encrypting is not enough to prevent data recovery if data was written to disk prior to encrypting it.
In other words, if you want to be 100% sure about your data being safe, you must encrypt first (when the drive is brand new), or you must physically destroy the drive.
But if your threat model is that relaxed, you can just encrypt the whole drive, toss the key, and then format the device. This would likely be quicker than doing 10x write passes.
As a note, write passes are really only good for HDDs due to wear-leveling algorithms in every SSD.
In many compliance-heavy fields, there are specific requirements around data destruction, sometimes involving physically destroying the storage medium up to some given standard.
I’d assume this device targets that market.
If they are strict enough to not allow for cryptographic erasure (or the data is above a specific sensitivity), this device would likely not be in compliance either -- physical destruction generally requires shredding/grinding to a specific particulate size, or incineration, and this device does not appear to do either.
I'm also not saying that all compliance standards related to data security require physical destruction; just that these absolutely exist, mostly in defense and similar areas.
But, I mainly made my comment in reply to this part of your comment:
>I’d assume this device targets that market.
Because I don't think there is any market where this SSD punching device would be compliant and cryptographic erasure wouldn't be compliant. At least, in my career, I have not seen any environment or standard where this would be considered compliant but cryptographic erasure wouldn't be.
I didn't explicitly say this in my original comment since it seemed implicit given the context.
I am very explicitly saying cryptographic erasure is not required if you are following physical destruction standards (in ISO 27001 and NIST 800-88, at least).
The boot password might be needed to be configured but it's unlocks your SSD. It's enough for the SSD to forget the AES key
I expected this to be an hobbyist implementation, not an ad.
This will significantly complicate data recovery and render data where the drill impacts it destroyed, but it will in theory still be possible to decap/analyse platters or nand with a SEM microscope and reconstruct data off the surviving parts of the storage medium.
The cost may not be worth it even to some state actors, but such a cost is peanuts to the NSA, CIA, or any other organisation tasked with geopolitical standing. Depending on who's after you, they may even pass it to these organisations to get the data for them at cut-rate.
Only sure-fire way is to toss it in one of those big grinders data destruction companies like Iron Mountain have. They even let you watch it go in.
I wonder if/when there's a data destruction company that employs professional magicians, who swap out the drives from under you at some point, while you watch "your" drive going into the grinder, never the wiser.
Centuries of prior art on disappearing!
Melting tungsten?
This is what rsync.net does with drives that need to stop existing.
I do, indeed, watch it go in and I strongly recommend a canister respirator when entering a shredding/destruction facility.
I cannot believe the operators of these devices - which are pulverizing glass and circuitry, among other things - don't wear lung protection as they stand over the machine-turning-drive-into-dust.
To my sibling who wondered about sleight of hand:
I can only speak for the machine I take drives to but it is an immediate and brutal reaction with sparks flying and pieces flying up ... and sometimes the machine jams and they back it out and re-feed it ... there is no question as to what is occurring to that specific drive.
Not so much anymore. Increasing data density and the two step nature of the technique make it much less applicable. There are newer techniques but they're more expensive and much more sensitive to the physical state of the media being scanned.
I mean this is probably why the CIA and NSA spend so much on tailored access operations and on zero day vulnerabilities instead. Not only is it easier to get the data in flight but it's much more likely to be timely for their purposes.
Bending the platters is, in practice, irrecoverable due to the sheer amount of data that's impossible to read in any reasonable amount of time unless the platter can be rotated while keeping the reading tool aligned.
With a cleanly drilled hole, and some preparation (carefully machining out the area around the hole with precision tools), the platters would be a lot more suitable for partial data recovery.
I’ve never tried one of these but I have one of their paper shredders and they are far better built than the usual semi-disposable made-in-China junk.
Step 1: take the screwdriver, dismantle the drive, and remove the platter(s).
Step 2: take the screwdriver and gouge the platters.
Step 3: take the screwdriver, lay each platter across it on the floor and stamp your foot down, hard.
Destroying the metal casing is fun but it doesn’t really do an awful lot in terms of making your bits harder to read.
Your procedure absolutely makes sense if you have a single-digit number of drives to destroy once in a while at home, not if you have to destroy dozens regularly.