12 ms·
Millions of usable hard drives are being destroyed
- JoeAltmaier 3y agoThis? https://www.bestbuy.com/site/shop/large-hard-drive https://www.bestbuy.com/site/shop/large-hard-drive
- ars 3y agoSince when does bbc run ads pretending to be articles? This is an ad for cdi.
- dewey 3y agoAs this is not a 1:1 press release, it seems not much different then them reporting on other tech news ("apple vision pro site:bbc.co.uk").
- rasz 3y agoIts very different. Its as if BBC ran article about saving whales by using the new apple vision pro ski googles and why arent more people doing it?!?11
- kobayashi 3y agoSeems like a submarine. http://www.paulgraham.com/submarine.html http://www.paulgraham.com/submarine.html
- lode 3y agoThey also regularly fall for PR bullshit 'articles' from What3Words: https://www.bbc.co.uk/search?q=what3words&d=NEWS_GNL https://www.bbc.co.uk/search?q=what3words&d=NEWS_GNL
- re-actor 3y agoFrom the very very start
- chinathrow 3y agoWhy don't they have a requirement to disclose it?
- ReactiveJelly 3y agoDefense in depth is the reason.
- Gordonjcp 3y agoOkay, but a single pass of /dev/zero will destroy all the data beyond hope of recovery.
- CoastalCoder 3y agoPerhaps one difference is verifiability, and the risk of being mistaken.
- netrus 3y agoBut you can't see from the outside if the drive was wiped. How can I be sure that I do not mix up the to-be-wiped and the wiped drives with 99.999% accuracy? That I did not unplug the drive before the whipping was finished? It's much easier with physical destruction.
- Gordonjcp 3y agoThis is about the only valid objection in all the replies to my post. You're bang on - you might not know it's been wiped. 99.9999% of people will never need to care about it that much.
- d33 3y agoFor that to work you have to trust the firmware. Overwriting with something random, saving what was fed and then cross-referencing that against the storage could work better, but there's still some non-zero chance that something you're looking for is in a buffer, unreachable part of the disk or the like. Encrypting the hard drive and then removing the key has a better chance of rendering the data unusable.
- treis 3y agoOnly if you're sure 1 -> 0 is not detectably different from 0 -> 0. There's almost certainly secure ways to delete. But not worth it for a five year old drive that may have had sensitive information on it.
- thedougd 3y agoSurprised it doesn't mention compliance frameworks as a culprit. NIST 800-88 calls for destruction if the data is highly sensitive and the drive is leaving the organization. Wrt risk management, it's not worth deviating from NIST. https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=917935 https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=91793...
- gumby 3y agowho would want to claim that their data isn't "highly sensitive"? How embarrassing that would be! This isn't a sarcastic remark: I think a lot of human activity can be explained this way.
- thedougd 3y agoIn particular, if the data doesn't belong to the hosting organization, but their clients, they probably have to consider it highly sensitive.
- Damogran6 3y agoIt isn't even data sensitivity. Laptop stolen? What was on it? "zOMG, We Don't KNOW!?!!!1" Was it encrypted? Yes Was the lid closed? Yes Order another laptop and move along.
- more_corn 3y agoI faced this same problem. My company policy required destruction of data before drives can leave the colo. I even had a hydraulic drive crusher in the cage to crush failed drives. However. The Linux utility shred can do a multi-pass random rewrite followed by zeros. (That last is critical for the next step) Then to verify, grab a random block and sum the data. If it’s not zero you crush the disk. Bake that script into a NetBoot image, wipe the boot drive’s boot blocks and reboot. I decommissioned about $5M worth of servers while preserving the disks. This preserved the hardware for reuse. If you want to be sure send a random selection of the wiped drives to your data recovery team. They won’t be able to get anything back.
- 3y ago
- pierat 3y agoNow why don't these companies keep the drives in-house instead of destroying? That, I don't know. But aside that, regarding the encryption... If you used the drive without encryption at any time, then its possible to recover the unencrypted data. You'd need to guarantee that your drives were *always* used with encryption from the start to end. And that's a hard guarantee. So yeah, if they were leaving the org, I'd destroy them too.
- slackfan 3y agoAh, you have never been on the IT side of any shop have you? The risks to keep running said hardware, or performance, or storage space, or power consumption or whatever are too high so you aren't going to be using it. So you decom it and do what, stick it in a closet? Decommissioned hardware that is put in storage inevitably walks home with an enterprising employee to whom the risks from the business perspective are simply not a factor.
- hospitalJail 3y ago>hardware, or performance, or storage space, or power consumption or whatever are too high I just upgraded my 10 year old laptop because I wanted to do AI Art locally. I ran video games, CAD, cellphone emulators, my programs, etc... on this computer and it still works. Heck, I still use it in a different room now. Its not the 2000s anymore, we don't need tons of processing power to open web browsers and M$ Office. Decommissioning could be a rare event in the future.
- TowerTall 3y agoWithin an enterprise hardware get decommissioned when the hardware warranty expires, which in many cases are 3 years (last time I checked).
- cameronh90 3y agoA typical office laptop is pretty useless after about five years. Even if the standard consumer stuff works fine, all the annoying enterprise security and remote management software that you're required to deploy just seems to suck up more and more resources every year. Unless you're lucky enough to work in an industry where that sort of thing isn't needed... But even if you forget the software side, most office workers don't take great care of their devices. Even a solid ThinkPad will often have bits falling off it after that amount of time.
- bell-cot 3y agoBecause (sad to say) at scale, with human nature, you can’t trust that any sort of HD Erasing & Disposal procedure will always be followed.
- ce4 3y agoExactly, 99.999% accuracy (wrt. to zeroing HDDs) is not enough. And the stop-gap measure for the remaining 0.001% is to have a policy that mandates shredding HDDs. Maybe until there's 100% disk encryption
- veave 3y ago>"You don't need an engineering degree to understand that's a bad thing," says Jonmichael Hands. Someone without an engineering degree will say it's a bad thing because it seems like pointless waste. Someone with an engineering degree will tell you of reasons why it should be done.
- pdimitar 3y agoI find it strange how preachy a part of HN can get about less CO2 emissions and being eco-friendly but then unequivocally support en extremely eco-unfriendly initiative like physically destroying usable storage devices. If you have principles, this is your litmus test. Show everyone that your principles hold even when there's a risk for you (and that risk is only perceived IMO, and not real if you have good procedures in place; and if you don't have those then you are at risk of many other problems). Personally I don't find it that hard to have a designated "hard drive exit area" where 1-2 guys' job is basically plugging in HDDs and running `shred` on them (which overwrites them with random data in several passes) all day long.
- JumpCrisscross 3y ago> If you have principles, this is your litmus test Principles are often in conflict. There are multiple reasonable solutions to this problem.
- V__ 3y ago> "They have a zero-risk policy. It can't be one in a million drives, one in 10 million drives, one in 100 million drives that leaks. It has to be zero." At some point human error will kick in, a firmware bug will prevent a complete override of the disk, or some new technology will be able to detect overridden data.
- hallgrimur1471 3y agoYes but shredding the drives isn't zero risk either. For example, there is a risk a disk would be stolen before it reaches the shredding place.
- pixl97 3y agoSo measure the risk probability and show it to me? There are multiple ways to shred. When you get drives from the bank, they have a semi down in the parking lot doing it on site. Other companies tag each device then document each one getting tossed in the shredder. If one of these devices shows back up after destruction then there is going to be some legal hell to pay. It's nearly impossible to tell if a disk has been erased by looking at it from the outside. But a shredded device, well that's easy enough.
- NotYourLawyer 3y ago> The irony is that shredding devices is relatively risky today. The latest drives have 500,000 tracks of data per square inch. A sophisticated data recovery person could take a piece as small as 3mm and read the data off it, Mr Hands says. I call bullshit on this, unless you can show me a single example of this ever happening anywhere.
- hospitalJail 3y ago>I call bullshit on this, unless you can show me a single example of this ever happening anywhere. Real world and lab conditions are different. Given how high stakes somethings can be, nothing would surprise me.
- NotYourLawyer 3y agoI can imagine lots of plausible/implausible things. If they’re not practically possible, I’m not gonna worry about them.
- hospitalJail 3y agoOh for sure, you aren't a high value target. Its why people don't worry about Apple and Privacy/Security. They arent the best in the business, but unless you are a VIP, no one is going to waste the latest 0click pegasus exploit on you.
- NotYourLawyer 3y agoDeveloping a 0 click exploit is a lot easier than recovering useful data from a small, physically damaged chip of a hard drive platter.
- harvey9 3y agoYou would need a lab in the real world to do this recovery, if it is possible.
- tyingq 3y ago
- rasz 3y agoThis article again, its a submarine for crypto storage staking scam (Chia Network).
- rwmj 3y agoMy friend once worked at a place where the security policy was that every part of the PC including monitors was crushed and shredded. This was a financial services company, but nevertheless totally over the top.
- NoMoreNicksLeft 3y agoI recently had a Dell monitor spaz out. Even powered off and powered back on, it was somehow keeping a (corrupted) image of what it had shown when last plugged in to my laptop. It's unclear how that's possible, but others witnessed it. Had this been during something sensitive being displayed, it might warrant shredding that particular monitor. I have no idea how long the phantom image would have lasted. An hour, a day, a year?
- paulmd 3y ago> I recently had a Dell monitor spaz out. Even powered off and powered back on, it was somehow keeping a (corrupted) image of what it had shown when last plugged in to my laptop. It's unclear how that's possible, but others witnessed it. Stored in the monitor control board somewhere. Especially in the VRR era, monitors need to buffer the image in case it needs to be redrawn, or if the transfer rate is faster than the draw rate. Which will be anytime the monitor isn't drawing at max VRR sync speed.
- cameronh90 3y agoElectronic devices keep state in all sorts of strange ways nowadays. If you have the money, the safest strategy is to shred everything rather than having to do a ton of research figuring out whether a given device needs it. For example, lots of people don't realise how many printers are vulnerable to recovering previously printed documents. In the past, you might have just opened it up and ripped out the hard disk and memory, but nowadays with NAND and DRAM being soldered onto motherboards, do you really trust that's enough?
- TylerE 3y agoWhy merely shred, when you can truck it down to your local steel mill and melt it in a blast furnace? Ain't nothing coming back from that.
- josephcsible 3y agoIMO, the problem is that people have to worry about individual blame and consequences for not being risk-averse enough, but not for being too risk-averse.
- PaulKeeble 3y agoThere have been multiple challenges on hard drives with substantial reward offered for anyone able to take a basic formatted drive with a few MB of files that were overwritten with 0s and recovering the files. Not once did any company accept the challenge let alone complete it. Every data recovery company would tell you that is not possible. Today we have secure erase which is necessary to clear SSDs and I doubt there is any actual technology to recover from thia mechanism. A lot of hysteria has been shown around drive clearing in the standards and until the standards reflect the reality of what is really possible and what is really sufficient I can not see companies changing.
- AnotherGoodName 3y agoSecure erase works well. Every other process we have around it has too much room for human error to creep in. From misconfigured drive encryption to a hdd making it to the erased pile without being erased. Just shred it. You can't mistake a shredded drive for a non shredded drive. The margin for human error is much smaller.
- hospitalJail 3y ago>Not once did any company accept the challenge let alone complete it. Do remember that winning award is significantly less profitable than selling your secrets to the military. NSO Group makes more money hacking iphones, than they make on bug bounties.
- hospitalJail 3y ago>Not once did any company accept the challenge let alone complete it. Do remember that winning award is significantly less profitable than selling your secrets to the military. NSO Group makes more money hacking iphones, than they make on bug bounties. (but also I agree with you on the formatting our drives)
- akvadrako 3y ago> Today we have secure erase which is necessary to clear SSDs and I doubt there is any actual technology to recover from thia mechanism. You might doubt it, but you also cannot provide much evidence against it. Trim commands just tell the controller to erase data – what they actually do internally isn't easy to discover without a major operation and internal knowledge. The best bet is not trusting the drives at all, perhaps by storing only encrypted data, then throwing away the key.
- riffic 3y agoMr. Hands, lol
- dark-star 3y agoWe recently had to destroy over 700 harddisks (10TB) because the customer didn't trust that a secure erase and full overwrite ways enough to make sure no data could be recovered. It was really painful to watch....
- WirelessGigabit 3y agoDid the customer not use encryption? I guess I would have trust issues with the services the customer offered.
- dark-star 3y agoThey were a provider for other customers with high security requirements (this is Europe, so the GDPR is very much in effect here) and they apparently had contracts with those customers that the drives were not to be re-introduced into the market in any way.
- Bedon292 3y agoI was looking at cleaning up some of my old drive, and I was basing my decisions on outdated information. At some point in the past it used to be necessary to do many overwrites to truly erase the data, and I was just stuck on that. Took me a bunch of research on modern drives and latest best practices before I was able to convince myself what I "knew" was no longer valid, and things have changed. I imagine that is where a lot of folks are at on this. Basically: It used to be possible, so maybe it still is. Not worth the risk, lets just go with the old best practices to be safe.
- dark-star 3y ago> At some point in the past it used to be necessary to do many overwrites Even that has almost always been just a cargo cult. Some people (mainly from the hacker community) claimed that US government agencies can still read data from harddrives that have been erased. It has never been proven by any independent data recovery company. It might have been somewhat true for MFM or RLL drives (these were before my time in IT), but at least since IDE drives, it was no longer true. However, the cult around "multiple erase cycles" still held, mainly because of companies like Norton etc. who sold snakeoil tools to "securely" erase your data
- throwaway22032 3y agoThe thing I find bizarre about all of this is that 99.99% of the data people think is super important would only be interesting to a few very specific parties. If you format a hard drive, and sell it on eBay through a generic username, then the person who buys that is not going to do some sort of FBI style forensics on the disk. It would be like going through every single bin on every high street on the off chance that you happen across some celebrities' bank statements.
- crazygringo 3y agoYou don't need FBI style forensics, you just plug in a drive and there are the files, if the drive hasn't been erased. Are you really OK with things like your bank account information or health records information or your e-mail history showing up on some rando's hard drive they bought from eBay, because it originally came from a cloud provider?
- gregw134 3y agoRelevant Matt Levine article: https://www.bloomberg.com/opinion/articles/2022-09-20/morgan-stanley-lost-some-hard-drives https://www.bloomberg.com/opinion/articles/2022-09-20/morgan... Last year Morgan Stanley got rid of old computers without wiping them, they were auctioned by the moving company, and it ended up costing Morgan Stanley $35 million in fines.
- gumby 3y agoThis is precisely the "reuse" shredding is designed to prevent.
- crazygringo 3y agoThis article mentions disposing of hard drives that have reached their five-year mark and are no longer under warranty. Does anybody actually want hard drives this old? Isn't the whole point that the risk of failure and therefore data loss is too high by this point? Even if you're using them to store data redundantly, you're running the risk that when one drive fails, the backup will also encounter failure due to the stress of reading its entire contents at once in the attempt to create a new backup.
- toast0 3y agoIf you have a good plan to recover from failures and you regularly monitor for pre-failure indicators, that the warranty expired shouldn't be a reason to drop the drives. A hard drive being in warranty or not doesn't indicate much about its likelyhood of working. There's a market for 5 year old hard drives that seem to be working, and at the same time, if you have budget, replacing your hard drives every 5 years will likely get you decent incremental capacity increases.
- pixl97 3y ago> not doesn't indicate much about its likelyhood of working. T Statistically I would say it does very much. https://en.wikipedia.org/wiki/Bathtub_curve https://en.wikipedia.org/wiki/Bathtub_curve Also drives can start building up bad sectors that you cannot write to, but may be able to read data from.
- toast0 3y agoThe bathtub curve is real, but it's hard to know where it is for a given model and production date. My personal experience is that hard drives often continue working past their warranty date, so I'd guess the other end of the bathtub is closer to ten years than five. I've run server fleets with a few thousand drives, and didn't find the other end of the curve because five year old drives are both out of warranty and relatively low capacity; we would retire systems with old drives because a new system would have much more capacity, rather than because the drives were old, but we still didn't run too many old drives. > Also drives can start building up bad sectors that you cannot write to, but may be able to read data from. Bad sectors are a pre-failure indicator. It's totally reasonable to stop using drives when they collect enough bad sectors. My threshold is 10 for drives you don't regularly monitor and can't easily replace, and 100 for drives with automated monitoring and simple replacement procedures. I wasn't ever able to figure out reliable pre-failure indicators for ssds. In my experience they work nearly perfectly, until they disappear, never to respond to commands again. Thankfully, at a much lower rate of failure (per drive) than mechanical disks.
- justapassenger 3y agoCryptographic encryption is safe for as long as your crypto is secure. For any company dealing with sensitive data, relaying on it to resell seems like a horrible idea. It’s not hard to imagine sufficiently motivated attacker (likely state sponsored) just buying up drives and waiting few years for when they can easily break the encryption.
- zokier 3y ago> just buying up drives and waiting few years for when they can easily break the encryption. "Few years" ... "easily" ... yeah, nope. I'm pretty sure that even 15 year old luks/truecrypt/bitlocker setups are not "easy" to break today, and have very little reason to suspect that current day cryptosystems would be any more likely to get broken in "few years"
- justapassenger 3y agoYou do know that state sponsored actors are already archiving encrypted traffic that they were able to tap into, between nodes of interest for them, with the same purpose, of trying to decrypt it later? "Easily" means very different thing if you talk about script kiddies vs state sponsored actors.
- zokier 3y agoState sponsored actors are not magic. Basic crypto primitives and systems that have been already available for long time have proven to be robust against even the most well-resourced attackers. Everything we've seen so far indicates that generally attacks happen by running malware, exploiting opsec failures, or some such leaks/implementation faults, and not attacking cryptosystems directly. Furthermore this scenario relevant for this thread, decrypting discarded hard drives, has very limited opportunities for complex attacks such as evil maids, cold boots, or other such more active methods. Notably Snowden said following, and while no doubt some progress has been made since I believe the basic idea be still valid: > “Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on. Unfortunately, endpoint security is so terrifically weak that NSA can frequently find ways around it.”
- justinclift 3y ago> By comparison a cryptographic erase takes just a couple of seconds. Wasn't there an in-depth analysis a while back of (drive) vendor provided encryption, with the end result being that they were pretty shitty implementation that shouldn't be trusted?
- al2o3cr 3y agoMr Hands (lolz) wants everyone to know that the only correct way to destroy usable hard drives is via his company's crypto-mining scheme. He's not... HORSING AROUND
- Damogran6 3y agoI've had this argument til I'm blue in the face. 1. Nuke the key and an encrypted drive is indistinguishable from noise. 1a. When SAN sizes get STUPIDLY LARGE, miltiple writes are cost and energy prohibitive, crushing is cheap, cert revocation is cheaper and leaves a device with residual value. 2. In the datacenter, data at rest is not a target, the attack happens higher up the stack where the OS/SQL/App can read the data 3. Areal density is such that a drive in a RAID array doesn't have much to offer up* (* = I'm willing to lose #3 if #1 is utilized.) But there's always some mouthbreather n00b or auditor or person that took a forensics class once that stands in the way.
- deepsun 3y agoHow do you "nuke" the key? It may still be on the drive (or other drives, or magnetic tape backups).
- ac29 3y agoIf I can store drive encryption keys on a HSM in my old, consumer grade laptop, I would hope that large storage systems have at least the same degree of protection.
- deepsun 3y agoBut if that HSM module or machine suddenly dies, the system would lose all the customer's files. Not good.
- awesomeMilou 3y agoIf I understand it correctly, the HSM on the HDD dying is about as likely as a HDD PCB failure. Of course in these scenarios you can't just swap the PCB's to recover the data, but in an Enterprise setting you would have mitigated this anyways, by using a form of redundant storage. If you rely on just one drive for your data's continued existence, you're doomed anyways. [0] https://wiki.archlinux.org/title/Self-encrypting_drives https://wiki.archlinux.org/title/Self-encrypting_drives
- SkyPuncher 3y agoFrom a risk management perspective, most storage devices have a "table stakes" requirement to "not lose data". Performance, storage duration, reliability, etc, etc, etc, etc, are all secondary to "do not lose data". You're dead in the water if you lose data. Everything beyond "don't lose data" can and is proprietary implementations of read/write; often with tricks being used to increase speed. While it's challenging (if not impossible) to recover data from most "blanked out" drives, there is often no guarantee that a blanking process actually renders the underlying data unusable. For example, I believe many SSDs will simply mark a block as "unused" rather than physically rewriting the data in that block. When the block gets used again, you simply set it to the new values. Whether it's practical, right now, to recover data really doesn't matter. These drives are leaving an organization forever. You will have absolutely no control over them. If a technique comes out to recover data from them, you cannot risk having drives floating around that are now recoverable.
- paulmd 3y ago> For example, I believe many SSDs will simply mark a block as "unused" rather than physically rewriting the data in that block. When the block gets used again, you simply set it to the new values. Most SSDs (everything that follows the OPAL standard) actually encrypt all data all the time, and support a "secure erase" mode that destroys the encryption key from the TPM and renders the data inert. Copy the flash chips to your heart's content, if you believe the premise of encryption then it'll be a couple million years before you have any chance of cracking the key. There's no reason this can't also be used on hard drives - or via a higher-level solution like Bitlocker. Again, if you believe in the idea of Bitlocker, then if you lose (or destroy) the key the data is unusable, that's the entire sales pitch of Bitlocker. Drive data is completely inaccessible if removed from their PC and the TPM it contains, and people don't like this because Windows 11 is turning this on by default now. Physically crushing a drive is needless and wasteful unless you fundamentally disagree that cryptography exists and can work. And it also completely eliminates the possibility that your e-waste vendor is screwing you around behind your back. Fine, have a bunch of white-noise data if you like. The problem is that businesses like to reduce a 1-in-a-trillion chance to zero, and they're punished if something does happen. And I'm sure hard drive companies like the extra sales and probably nudge them into it too. But it's overall a market failure and a needless e-waste stream, of the kind that the EU does like to eliminate.
- 3littlefish 3y agoThe wastage is shocking. Given the huge demand for (and sometimes shortage of) materials (as well as the time, money, and resources involved in creating them) there should be an established and secure process that is security/compliance approved and would allow for acceptable recycling of these hard drives.
- Kab1r 3y agoHow risky is it to just encrypt disks or filesystems, storing the key in tpms or secure enclaves and then just discarding the key instead of actually deleting the data?
- lostmsu 3y agoThe article says Seagate refurbishes SSDs after cryptographic erasure and resells with 5 year warranties. Where can I browse them? I've only seen their refurbished HDDs.
- dryark 3y agoThey aren't just destroying hard drives. Companies are destroying iPhones too instead of reselling them. I know of at least one major tech company that is destroying several thousand old iPhones instead of letting my iOS automation company buy them from them.
- RecycledEle 3y agoThis is nothing new. I think I remember seeing an ad for unbelievable cheap 330 MB ESDI drives in Computer Shopper in the early 1990's. But when I called they said they had to shred them instead of selling them.