5 ms·
I used to be cavalier about HDD disposal, and then one day I helped a friend recover some files from their apparently dead HDD. We did not recover the files bu
by KiwiCoder 13y ago
I used to be cavalier about HDD disposal, and then one day I helped a friend recover some files from their apparently dead HDD. We did not recover the files but we did find unencrypted passwords to email accounts and other sensitive information that he had forgotten about.
So while I trust device/disk wiping tools are effective, I'm much less trusting of my own memory about the files on any given storage device. Moreover, and perhaps more importantly it's rarely possible to guarantee that software is consistently doing the right thing with your sensitive data.
Therefore my rule is now to donate unwanted hardware but never to donate or dispose of storage devices without being certain the data is unrecoverable. This is a harder problem than it might at first appear.
Secure disposal of hardware is a problem growing worse in proportion to the number of devices we allow (or by inaction permit) to manage our personal data.
- sillysaurus2 13y agodispose of storage devices while being certain the data is unrecoverable I use Derek's Boot and Nuke bootdisc for this purpose. http://www.dban.org/ http://www.dban.org/ It's straightforward to use, but it's also configurable if you want to be extra certain the data is gone. I think the default is 3 passes of filling the harddrive with random data generated via Mersenne Twister.
- omh 13y agoUnless you're very paranoid then a single pass of zeroes should be sufficient. The bigger problem is what to to with a dead hard disk. It's usually easier to buy a new one rather than replace it, but an attacker could perhaps repair the disk to steal the data. At work we send any non-wipable disk to be physically shredded. At home I think I'd just hold on to all disks indefinitely.
- maxerickson 13y agoThere's lots of ways to damage the platters, at which point the data probably won't justify exotic recovery methods. For a drive with bitcoin on it, just move the coins to new addresses before disposing of it.
- x3c 13y agoOpen it, take the disc out and microwave it.
- gmac 13y agoDangerous?
- ihsw 13y ago"Is It A Good Idea To Microwave An XBOX 360?" http://www.youtube.com/watch?v=vzodemYzswQ http://www.youtube.com/watch?v=vzodemYzswQ "Is It A Good Idea To Microwave A PlayStation 3?" http://www.youtube.com/watch?v=4rWyJXpezPs http://www.youtube.com/watch?v=4rWyJXpezPs "Is It A Good Idea To Microwave A Nintendo Wii?" http://www.youtube.com/watch?v=OydTZpbp0EE http://www.youtube.com/watch?v=OydTZpbp0EE
- atwebb 13y agoDrive a few nails through the case, it's fun and destructive! When drives were much larger, we used to take them apart, use the platter for mirrors/silly decorations and the magnets to magnetize tools around the office.
- bluedino 13y ago>> Unless you're very paranoid then a single pass of zeroes should be sufficient. If you're paranoid it won't matter how many passes of zeroes you do. After 1 it's done. If you're still paranoid, hard drives make great rifle targets.
- willvarfar 13y agoThese days there is a proper secure wipe built into most drives themselves. Its part of the ATA spec. https://ata.wiki.kernel.org/index.php/ATA_Secure_Erase https://ata.wiki.kernel.org/index.php/ATA_Secure_Erase Yet if you ask how to wipe a disk on a forum, you'll get user-space ideas like `dd` and `shred` :(
- techdragon 13y agoA lot of people want a more physically certain level of data destruction than such a command provides. If I saw that a drive wrote 3-5 passed of junk data before zeroing the disk then I would trust it but such firmware level info is rare to impossible up find.
- phamilton 13y agoMany SSDs do on the fly AES encryption. Secure wipe is then just a destruction of the private key. All the encrypted data stays put.
- venomsnake 13y agoSince when there is private key in AES? And that requires a paranoid person to trust that a company does not holds the keys in escrows somewhere or are by any way retrievable.
- KiwiCoder 13y agoTo clarify - the hard part is not the destruction of data you know about, it's the identification of data on devices you don't know about, or forget. Computers with hard disks are obvious, but also consider mobile phones, tablets, games devices (that increasingly ask for sensitive information), PVRs, and so on. There may be a point, if we haven't already reached it, where I can't dispose of a toaster without worrying about how to wipe its memory.
- jzwinck 13y agoDon't forget office printers! Some have hard drives or other nonvolatile storage. You know, in case you want to run off a second copy of that fax from 2009.
- dzhiurgis 13y agoHow about cat /dev/random > file ?
- Anderkent 13y agoDoesn't that effectively do: unlink(filename) create(filename) write(filename, random) ? Though something that opens the file in append mode then seeks to 0 would probably overwrite the same HDD locations.
- finnw 13y agoYes. It will truncate the file first, then allocate new blocks for the new random data, likely leaving the old blocks lying around. You can avoid this with the 'conv=notrunc' option of 'dd'[1]. It will overwrite existing blocks instead of truncating (and possibly reallocating): notrunc Do not truncate the output file. This will preserve any blocks in the output file not explicitly written by dd. The notrunc value is not supported for tapes. [1]:https://developer.apple.com/library/mac/documentation/Darwin/Reference/ManPages/man1/dd.1.html https://developer.apple.com/library/mac/documentation/Darwin...
- pbhjpbhj 13y agoDBAN's good, there are a couple of other ways I've used including dd. Here's a blog post about it http://alicious.com/secure-drive-data-wiping/ http://alicious.com/secure-drive-data-wiping/ including references to some papers where they looked at the probability/possibility of recovery.
- DocG 13y agoI am related to computer refurbishment charity company. We get also old stuff from other company's and it is always in contract, that hard drives must be at least destroyed mechanically. No rewriting or deleting. Mechanical only. We remove platters, break them. After that, the value of data is far less for these things than the cost of recovering.
- driverdan 13y agoSSD + full disk encryption = no data recovery. Even without full disk encryption the data will be gone pretty quickly with TRIM.