3 ms·
It's not usually landfills which are the vector for this kind of leak, it's second-hand disk sales. This includes both decommed hardware and items scavenged fro
by ericbarrett 4y ago
It's not usually landfills which are the vector for this kind of leak, it's second-hand disk sales. This includes both decommed hardware and items scavenged from failures: often the failure was transient, or in the chassis; the maintenance vendor will test and resell the disk if it passes. They are supposed to be wiped, but this takes a long time and is almost never verified so the process is often incomplete.
Some such vendors have a blanket destruction policy for old hardware, but this obviously means higher prices, so it's usually only borne by medical and military institutions. And there have been notable cases where this was supposed to happen but the disks ended up on eBay, unwiped, regardless.
SSDs make this even more likely because they have pools of storage which are screened off from normal access but are typically readable through special code in the firmware; as failing sectors are swapped out, sensitive plaintext can remain behind, unable to be wiped by a conventional dd-style blast. (HDDs have this too, but in much smaller quantities.)
- spullara 4y agoI don't believe that AWS sells its retired equipment, at least I could find no evidence for it and thus I think the likelyhood that someone gets a hold of an unwiped/unshredded SSD from them to be exceedingly low. I am surprised that drive manufacturers haven't built in encryption at rest though since it would be pretty easy to generate a key on first boot and then make it easy to wipe by just making a new key and thus essentially scrambling all the data on the disk instantly without having to wipe them at all.