ShredOS – Secure disk erasure/wipe
github.com
github.com
Of course this comes with the risk that someone exploits the firmware and extracts the key, rendering secure erase useless, but in most cases that's good enough.
Your great, great grandchildren will be embarrassed of the websites you visited.
Asymmetric algorithms like RSA are the ones you should be worrying about, and I can't imagine any reason someone would do disk encryption with an asymmetric algorithm.
This works on the economic argument that if you could easily recover data from a disk that's been rewritten, drive manufacturers would exploit that already to increase storage.
If your threat model includes attackers who bypass the firmware to read overwritten data, you are probably boned several other ways.
Of course this matters less on slow disks, where the bottleneck is the writing speeds anyway.
Assuming you can trust the drives to actually encrypt:
>In the current form nwipe does not sanitize solid state drives (hereinafter referred to as SSDs) of any form (SAS / Sata / NVME) and / or form factor (2.5" / 3.5" / PCI) fully due to their nature: ...
https://github.com/martijnvanbrummelen/nwipe
The ShredOS page suggests the use of hdparm for SSDs but things are fairly complicated:
* https://github.com/martijnvanbrummelen/nwipe/blob/master/ssd...
Yeah:
> Given that the support for sanitization is optional and not a mandatory aspect of the respective standards the support accross vendors can vary largely. The following table does not claim or warrant to be complete, it is highly advised to always validate the information with the manufacturer:
It'd be nice if the INCITS/SATA/SAS folks could make it mandatory.
Interesting and that they don’t mention Enhanced Security Erasure; that SATA command would take care of the broken sectors and firmware reserved sectors. HDPARM is capable of issuing the command if the SSD/HDD supports it and HDPARM is the tool they seem to be using. Not sure what they are using for NVME though as they use PCIE…not SATA commands. Maybe sedutil from OPAL? Anywho, tor most drives whether SSD, HDD or NVME you can ‘erase’ it by simply setting and deleting my the KEK and UEK but to securely erase you want to do security enhanced erase data command that runs locally in the drive and is independent of the OS.
It however _is_ absolutely necessary for magnetic media (HDD even when supported by SSD, and tape).
But in both cases, if you want to be _absolutely_ sure nobody can read data from a drive after parting with it use Bitlocker (Windows), FileVault (Mac) or LUKS/dm-crypt (Linux/BSD)
As far as legends on the high magic of contemporary flash memory goes, you would want to simply tell your SSD/NVMe to secure erase the drive instead of writing data yourself. ShredOS doesn‘t seem to implement this.
That and the fact that SSDs hold back part of the usable storage for optimizations means DBAN can't even seen the whole drive.
How are you going to explain to the TSA officer that the disk does not contain encrypted data?
(IMHO the very concept is obsolete in the era of SSDs & SMR.)
and meanwhile in an alternate universe
"So you say that this device just happens to contain a bunch of random data? That sounds mighty suspicious. We'll keep you here until our technicians have taken a look at it. Get comfy, it'll be a while."
nvme format -s1 /dev/nvme0n1
to use secure erase on your NVMe drives, with similar commands available under hdparm for SATA drives:https://grok.lsu.edu/Article.aspx?articleid=16716
The "DoD style" erase commands no longer provide adequate security for highly virtualized I/O devices like SSDs where blocks may be remapped as spares out of the directly accessible range and thus skipped by the pass. In fact, the DoD itself stipulates only physical destruction of hard drives is acceptable, and many bases have secure warehouses where old drives are stocked awaiting destruction.