6 ms·
For those who don't speak french, this Youtuber bought a second-handed SSD to do some forensics and raise awareness. He managed to recover the partition, inside
by drouar_b 5y ago
For those who don't speak french, this Youtuber bought a second-handed SSD to do some forensics and raise awareness. He managed to recover the partition, inside he found qcow2 image of a company, he managed to mount it and recover the full data, including source code of their app, a ssh key and S3 credentials of the company
- jve 5y agoThanks. Is there any info whether drive was formatted or not?
- drouar_b 5y agoThe drive had a quick format, so he managed to recover the partition with testdisk
- foxpurple 5y agoThese days every single drive should have full disk encryption. And then you can format by simply securely wiping the key part.
- quietbritishjim 5y agoSSDs work in an odd way: they have more capacity than they claim, and when you overwrite some data you're really just writing to some of that spare space while the old version is just marked as free [1, 2]. Admittedly, at that point it's going to be very hard to retrieve the old data (you'd need to bypass the remapping logic presented by the controller circuitry), but it's theoretically possible. If you're paranoid, it's best to rewrite the whole thing even if it's encrypted, ideally several times (at that point a little original data could technically be left over but it's unlikely and it's not going to be feasible to get any of it if it was encrypted). [1] https://databasearchitects.blogspot.com/2021/06/what-every-programmer-should-know-about.html https://databasearchitects.blogspot.com/2021/06/what-every-p... [2] https://news.ycombinator.com/item?id=27572218 https://news.ycombinator.com/item?id=27572218
- tpetry 5y agoIf you only ever write encrypted data to the disk you don‘t care about spare ssd cells. The data was always encrypted you wouldn‘t even need to format before giving away.
- quietbritishjim 5y agoIn general I'd agree, but the parent comment mentioned "wiping the key part" so I guess they had the assumption that the password is weak enough that its vulnerable while that data is accessible, so I was assuming the same thing. (As you're no doubt aware, the encryption key for full-disk encrypted disks are encrypted by the decryption password and stored on the disk itself, at least when not using a TPM.)