3 ms·
Seagate wipes the drives they get returned [1]. I imagine other companies have similar processes. [1]http://www.seagate.com/ww/v/index.jsp?locale=en-US&name=da
by pdubs 15y ago
Seagate wipes the drives they get returned [1]. I imagine other companies have similar processes.
[1]http://www.seagate.com/ww/v/index.jsp?locale=en-US&name=data_overwriting&vgnextoid=f52d29e293eae110VgnVCM100000f5ee0a0aRCRD http://www.seagate.com/ww/v/index.jsp?locale=en-US&name=...
- Silhouette 15y agoI appreciate the effort they go to, and perhaps for typical home users they might consider it an acceptable risk. However, for my business dealings, Seagate's statement there has limited value, because I still have to release the faulty drive into some sort of postal/courier system with any retrievable data intact and trust that it reaches Seagate to be securely wiped. Unless they provide a specialist collection service with the appropriate certifications that they have taken responsibility for destroying the drive securely, nothing that only kicks in when something reaches them via a third party is likely to be an acceptable risk if you're dealing with data protection for credit card data, medical records, etc.
- ComputerGuru 15y agoWhy aren't you encrypting?
- Silhouette 15y agoAs I mentioned before, in some cases, we do. Obviously if you're dealing with, say, sensitive customer data like card numbers or any sort of legally privileged information, then you have to have robust security in place across the board. More often, in the particular cases I'm familiar with, we're talking about commercially sensitive information, where we have to weigh up the costs of complete end-to-end encryption by default against the loss of productivity that results when things like big network file transfers slow way down. In a self-funded small company, with limited staff time and limited cash, total encryption is not always the answer. For example, I think you can reasonably have a policy that encryption of any removable media is required but anything screwed into a rack in the office is biased toward performance, and in fact that is basically what we do in most cases. But it does limit the value of the kinds of warranties we're talking about, because we're not going to just hand over a hard drive that has probably had sensitive company documents on it to some random delivery service. Similarly, from a personal point of view, I don't consider theft of my home computers to be a very high risk, so I don't routinely encrypt all the hard drives, even though I have some potentially sensitive data like downloaded bank statements and bills on there. Instead, I expect to keep the hard drives for a relatively long time anyway, and then have them securely wiped/destroyed when they are too old/broken to be useful any more. Just to be clear, I'm not saying these choices are anyone's problem but my own. I accept the cost of the occasional hard drive failure as a natural consequence of these policies. I'm just saying that it means hard drive manufacturers' long-term warrantes are effectively not worth anything to me or the companies I run. I suspect that in practice plenty of other people/small businesses follow similar procedures, and therefore the warranties probably aren't worth much to them either.
- pdubs 15y agoIf you send it by a secure courier service or even certain types of post I would think that liability no longer rests with you. If damaging information leaks you could then likely sue the carrier and/or Seagate. A likely solution would be to use a vendor that can appropriately wipe the device before sending it to the manufacturer for warranty. There's really nothing else a hardware manufacturer can do on their end. If you're dealing with information that sensitive, some sort of degauss, replace, and recycle is just part of operating cost.