4 ms·
> Deleted file recovery on a modern SSD is next to impossible for the end user OK, he’s talking about SSDs, but I want to mention that I’ve easily recovered ma
by computator 7y ago
> Deleted file recovery on a modern SSD is next to impossible for the end user
OK, he’s talking about SSDs, but I want to mention that I’ve easily recovered many large deleted files from SD or micro-SD cards (formatted as FAT32 or exFAT) using Norton Unerase or an equivalent utility.
Are the controllers for SSDs that different from the controllers for SD cards? Has anyone tried Norton Unerase or an equivalent program on an SSD? I’d like to hear a first hand account to help confirm (or deny) what the author claims.
- ajphdiv 7y agoFor the end user it is difficult. Files can be recovered as long garbage collection hasnt happened yet. SSDs require the space to be empty before new data can be written to it. So often times the deleted space is empty. If files are stored in the recycle bin or trash those can still be easily recovered. It was once explained to me that writing to a HDD is like painting. Where new data can just be painted over the top of the old discarded data. While writing to an SSD is like writing on a chalk board where the old data has to be removed before you can write over it.
- toast0 7y agoIt would likely depend of if the filesystem uses TRIM to notify the SSD of deleted sectors. If it doesn't, the deleted files should retain their data until the filesystem reuses the sector, as normal. If trim is used, the SSD doesn't have to retain the data, but it doesn't necessarily make it unreadable immediately, there are many implementation strategies for trim.
- wtallis 7y agoEnterprise SSDs for the most part promise that reading a trimmed range of the drive will return zeros. Consumer SSDs usually won't make that strong of a guarantee, so that if you're running enterprise software that requires this behavior you have to pay extra for enterprise drives. As originally formulated, the TRIM command was supposed to be more of a hint that the SSD could ignore if it was too busy or if the TRIMMed block was too small for the drive to do anything useful with.
- astrobe_ 7y agoThat's because for FAT, erasing a file just means flagging the file allocation table entry as deleted, which normally makes the filesystem software put the linked list of sectors pointed by this entry back to the free sectors list (I'm pretty sure I am wrong on some details here, but I think the general idea is correct). In other words, when you "delete" a FAT file, you are not even erasing a whole directory entry, you just merely flip one bit in that entry. The data blocks get actually "erased" when they are reused by the FS software. Recovery of basic deletion is therefore pretty much guaranteed as long as you didn't write something else on the disk. What the author is talking about is more "serious" deletion, sometimes called "shredding" [1]. To actually erase the data from the disk, you use software that overwrite your file with random data before deleting it. This is supposed to work if the filesystem is as clever as FAT - that is somewhat dumb (but so simple that SoCs such as ARM Cortex Ax can boot from them directly). SDs and SSDs add another challenge because they constantly lie to the filesystem software; they have their own inner controller mainly to manage bad sectors and do wear-leveling, so when the FS requests to fill a sector with zeros, they might say "ok" but actually just remap the sector internally to another empty sector. So the data is still somewhere on the chip, and an evil scientist with lots of pointy probes can in theory read them back. [1] https://linux.die.net/man/1/shred https://linux.die.net/man/1/shred