8 ms·
Why SSD Drives Destroy Court Evidence, and What Can Be Done About It (2012)
- computator 12y agoThe two most interesting insights I got from this article are that: (1) SSDs are good for privacy for average users since they are cleaning up dirty blocks in the background. However, IMO, privacy-conscious users who are running a daily free-space wipe, a conventional hard disk is superior because it guarantees that all dirty blocks are erased. A free-space wipe on an SSD can't guarantee that reserved or remapped blocks get erased. (2) He says, "Somewhat counter-intuitively, information deleted from certain types of encrypted volumes (some configurations of BitLocker, TrueCrypt, PGP and other containers) may be easier to recover ... if the investigator knows either the original password or binary decryption keys for the volume". If you delete a file in your encrypted volume (but don't do a free-space wipe inside your encrypted volume), then someone who knows your key could potentially recover that file. But that's always been true -- it's true for both SSD and conventional drives. What I think the author is saying is that someone who use an encrypted volume doesn't benefit from the SSD's cleaning of dirty blocks in the background because the entire encrypted volume looks like it's in use to the SSD controller. But I don't see how he concludes that it's "easier". You lose the benefit of the SSD's garbage collection, but to recover a deleted file from inside an encrypted volume (assuming you have the user's key) is neither easier nor more difficult with an SSD vs. a conventional disk.
- sigterm 12y ago> A free-space wipe on an SSD can't guarantee that reserved or remapped blocks get erased. I think most controllers implement a secure erase feature that guarantees the data have been erased from NAND. > the entire encrypted volume looks like it's in use to the SSD controller I have always wondered how encrypted volume worked on an SSD. It seems this will lead to serious performance issues due to ineffective garbage collection.
- Hello71 12y ago> > A free-space wipe on an SSD can't guarantee that reserved or remapped blocks get erased. > > I think most controllers implement a secure erase feature that guarantees the data have been erased from NAND. yes, ata secure erase, which guarantees erasure of the entire drive (excluding vendor specific areas)
- computator 12y ago> most controllers implement a secure erase Yes, a secure erase of the entire disk. That does not help with erasing the free space (a free-space wipe). Erasing the free space can't be done purely at the controller level since the controller can't tell which blocks are free and which used.
- jcromartie 12y agoBut you can image the logical filesystem on the SSD, do the free-space wipe, and then restore the image to the wiped SSD. If you could find a way to automate on a Mac with FileVault then you'd be popular.
- JulianMorrison 12y agoDon't even image it, tar it up. That way you get defragmentation too.
- deleted 12y ago[deleted]
- DanBC 12y agoBut free-space wiping is pointless and not a security benefit on regular spinning platter drives.
- Karunamon 12y agoWait, what? The whole point of wiping free space is to prevent file recovery tools from doing a low level scan of the drive and retrieving deleted data, since a delete doesn't actually zero out the space, it just marks it as available for reuse.
- Freaky 12y agoBitLocker at least supports TRIM with SSDs on NTFS volumes: https://blogs.msdn.com/b/e7/archive/2009/05/05/support-and-q-a-for-solid-state-drives-and.aspx https://blogs.msdn.com/b/e7/archive/2009/05/05/support-and-q... > When Bitlocker is first configured on a partition, the entire partition is read, encrypted and written back out. As this is done, the NTFS file system will issue Trim commands to help the SSD optimize its behavior. It's also planned for FreeBSD's geli: http://lists.freebsd.org/pipermail/freebsd-fs/2013-March/016773.html http://lists.freebsd.org/pipermail/freebsd-fs/2013-March/016...
- marbu 12y agoOn Linux systems, you can configure LUKS encrypted volume to use trim[1], but there are additional consequences you need to consider before doing that[2]. [1] http://lukas.zapletalovi.com/2013/11/how-to-trim-your-ssd-in-fedora-19.html http://lukas.zapletalovi.com/2013/11/how-to-trim-your-ssd-in... [2] http://asalor.blogspot.cz/2011/08/trim-dm-crypt-problems.html http://asalor.blogspot.cz/2011/08/trim-dm-crypt-problems.htm...
- x1798DE 12y agoRegarding point #2, I think "may be easier to recover" means easier than if it weren't encrypted for the reason you stated (the blocks are in use and won't be trimmed), not easier than on a conventional drive.
- pwnna 12y agoAre there any chances that governments could compel SSD manufacturers to introduce artificial backdoors allowing for data recovery? Or is that a certainty? I see that being pretty difficult as you would need to have 2x the storage in an SSD without being easily detected by anyone taking it apart.
- autokad 12y agoi would be shocked if they did not already have a back door in place
- pasbesoin 12y agoI'd like to take advantage of the hardware AES encryption present in many SSD implementations. But I have difficulty believing it's not back-doored. I'm not doing anything nefarious, but these days law enforcement seems ever more determined to gin up evidence and argument to suit their purpose. Also, if they can use the back door, how long until a malicious third party can?
- DanBC 12y agoLet's hope the drive manufacturers have implemented the encryption correctly. Here's an example where makers of external drive enclosures didn't: Enclosed but not encrypted: http://www.h-online.com/security/features/Enclosed-but-not-encrypted-746199.html http://www.h-online.com/security/features/Enclosed-but-not-e...
- malandrew 12y agoBut they could never use such a technique against a savvy tech user who knows that the erase command deletes the internal encryption key on an SSD. Using the technique in any court case would be tantamount to publicizing it and destroying the reputation of the hard drive manufacturer in question, as everyone would know a back door exists in their devices.
- Canada 12y ago
- stcredzero 12y agoSSDs are very different from spinning platters. Instead of creating complicated devices that try to mimic spinning platters, why not have a different storage model entirely?
- wmf 12y agoYeah, why not rewrite every filesystem? But there is http://www.fusionio.com/blog/under-the-hood-of-the-iomemory-sdk http://www.fusionio.com/blog/under-the-hood-of-the-iomemory-...
- stcredzero 12y agoYeah, why not rewrite every filesystem? Just write one new one. Or use ioMemory. I don't understand that one well enough to decide yet.
- mantraxC 12y agoThey're very different in terms of implementation, but actually have somewhat similar bottlenecks. RAM, SSD and HDD, all have penalty for random seeking of data and benefit from pre-fetching sequential data into faster memory. The differences we do have in SSDs have been solved by the SSDs internally remapping blocks to facilitate even wear, and by "trim", which now all major operating systems support. If you will push forward a new FS, you'll need a better reason than the switch to SSD.
- stcredzero 12y agoRAM, SSD and HDD, all have penalty for random seeking of data and benefit from pre-fetching sequential data into faster memory. But the latencies are different, especially between the 1st two and the 3rd. Cost per MB are also very different between the three. Are you saying that a few orders of magnitude doesn't make a difference to determining optimal caching strategies? The differences we do have in SSDs have been solved by the SSDs internally remapping blocks to facilitate even wear, and by "trim", which now all major operating systems support. Totally doesn't address what I refer to above.
- warmfuzzykitten 12y agoI would think that feature is an added benefit and nothing should be done about it except ensure TRIM is enabled and active. We should not be running our private lives with a goal of assisting lawsuits and prosecution, particularly actions against ourselves.
- anigbrowl 12y agoMany businesses and professional individuals operate under a legal requirement to keep records that can't be satisfied if they are too reliant on SSD storage. Also, deleting information after the commencement of legal proceedings can be a criminal offense.
- wmf 12y agoUndeleting data was never guaranteed on hard disks or SSDs and thus doesn't satisfy data retention requirements anyway. RAID isn't backup and forensic tools aren't archives.
- fleitz 12y agoEvidence is evidence, it both exonerates and convicts.
- Sanddancer 12y agoSpoliation of evidence is one of those things that courts really, really dislike. If you're found to have intentionally destroyed evidence, the court can give instructions to the jury essentially saying to assume any destroyed evidence was showing guilt.
- Spooky23 12y agoIf you have a routine practice of erasing things, you're fine. It's not an issue to erase your hard disks, or shred your paper documents. But it is problematic when you do so when there is a reasonable expectation if litigation.
- sbierwagen 12y agoInteresting that this is essentially a fight between two arms of the government: spooks, who want to delete information forever, and cops, who never want any information deleted at all.
- jlarocco 12y agoActually, most computer forensics has nothing to do with the government. My girlfriend does it for a large company, and almost all of it is relatively boring stuff, like recovering email and documents when they get sued and loading it into Clearwell or EnCase for the attorneys to review.
- newaccountfool 12y agoI'm currently doing a Degree in Digital Forensics, would you mind me asking what your girlfriends salary is like?
- sirdogealot 12y agoI really wish we could do away with the formalities involved when asking "what do you make?". It just seems so ancient. I have no problem telling anybody my average income and exactly what it is I do. It's not like the servant is asking the king how much he makes anymore. We're all pretty much the same monetarily these days.
- 6cxs2hd6 12y agoThe phrase "would you mind me asking" is simply being polite and respectful, not obsequious (IMO).
- sirdogealot 12y agoI agree completely. For myself, it's more the fact that newaccountfool felt the need to ask permission to ask a question. I love asking questions. And I love answering them whenever possible. I suppose that I wish we all held fewer secrets or assumed secrets.
- _mgr 12y agoFor anyone that's interested - http://ro.ecu.edu.au/cgi/viewcontent.cgi?article=1124&context=adf http://ro.ecu.edu.au/cgi/viewcontent.cgi?article=1124&contex... The above is a terrible write-up of my undergrad research project / dissertation.
- computator 12y ago> above is a terrible write-up To clarify, do you mean that the OP (the Belkasoft article) is a terrible write-up of your work, or that the link you provided (of which you're a co-author?) is a terrible write-up?
- _mgr 12y agoThe link I provided, of which I am a co-author. Technically I didn't write the paper though.
- TrainedMonkey 12y ago"Modern SSD drives employ smart wear leveling techniques [3] that, instead of re-using existing blocks of memory, will write to a different block when data stored in a certain block is being modified." Can this behavior be exploited to enable a hardware based file versioning system? For example, SSD explicitly exposes to OS, where new blocks are written and which blocks they are overwriting. This would allow FS to cheaply track multiple versions of files. When a portion of a file is overwritten with some new change, this version is discarded and SSD is instructed that rest of blocks that were storing changes for that version of the file are expendable as well. Depending on SSD capacity and usage, a simple algorithm of overwriting oldest block first, would provide several versions for each changed file virtually for free.
- computer 12y agoWhat you're describing is basically copy-on-write: https://en.wikipedia.org/wiki/Copy_on_write https://en.wikipedia.org/wiki/Copy_on_write, which is a part of most modern filesystems (ZFS, BTRFS, etc). That makes it software-based, but the idea is the same: you can easily make snapshots, roll back to previous versions, etc.
- sean-duffy 12y ago"SSD Drives" - Solid-State Drive Drives?
- 54mf 12y agoSolid State Disk Drives. :)
- TheSpiceIsLife 12y agoThere are no 'disks' in an SSD
- mantraxC 12y agoThe RAS syndrome strikes again.
- j4kp07 12y agoMisleading title. Newer technology has no inherrent responsibility to live by old forensic standards of past generations. A Solid State Drive (not, Solid State Drive Drive) does not "destroy" court evidence. Firstly, show me the court record where the data was first introduced. Secondly, lookup the legal terms for destroying court records/evidence then explain to me how this scenario applies. Yes, I'm splitting hairs, but so does your title.
- wil421 12y ago>A Solid State Drive (not, Solid State Drive Drive) does not "destroy" court evidence. This struck me also. The author was writing as if the newer devices should be the same as older HDs. IMHO destroying potential court evidence is a good thing for the user. Sort of like a 5th amendment drive.
- kabdib 12y agoDidn't mention read disturbance. MLC and TLC flash (esp. the latter) have semi-destructive reads, so that you need to re-write a block after several thousand reads as well as on any write. So you can't treat a drive as a ROM, even if you disabled physical writes somehow. Of course, you probably have enough read cycles available to do quite a few full scans of a drive...
- pmorici 12y agoI'm confused why they went to the trouble of building a custom FPGA setup, you can just buy a Universal chip programmer that can read the contents of flash for around $1,000. The article also doesn't address the fact that many SSD drives encrypt data before writing it to the flash which makes this approach impossible. http://www.dataman.com/ http://www.dataman.com/
- random_number 12y agoHi, I'm the author of the first reference cited by this article, and the coiner of the term 'self-corrosion' for this phenomenon. First of all, thank you to the author of the headline article for their interesting article and for citing our research. I'd say our main findings were a little bit different to what is described in the article, though I'd agree with most of what was written there. We discovered that SSD drives can wipe themselves (with their own GC) even in the absence of TRIM commands and despite the use of forensic write-blockers that block both writes and trims being sent on the ATA/SATA bus. To my mind, that's what is really shocking - you get this phenomenon even when the very best forensic tools are used and even on OS's that aren't using TRIM. (My coauthor was a professional forensic investigator armed with professional equipment). For example, imagine if you had some data on your disk that was fragmented all over the disk. If the disk has a garbage collector that wants to consolidate flash sectors so it can erase the leftover space after consolidation (e.g. to improve performance), then you're going to get deleted data being purged without any TRIM command being involved after the consolidate/erase operation. If I remember right (it's been a few years), some firmwares also detect fast-formatting operations in OS's that don't support TRIM and use that as a clue to trigger automatic GC. That was the really stunning one for us. A fast format by the user led to the disk wiping itself just minutes later under forensic conditions. Of course this sounds great for privacy, self-wiping and so on, but the problem is that it could look like this accidental wiping was an intentional attempt to destroy evidence (e.g. manual wipe, logic bomb or something). That's where things get tricky. It looks like the link isn't working, here's a working link: http://graemebell.net/publications//upload/bellbodd2010-preprint.pdf http://graemebell.net/publications//upload/bellbodd2010-prep... or http://researchrepository.murdoch.edu.au/3714/1/solid_state_drives.pdf http://researchrepository.murdoch.edu.au/3714/1/solid_state_... That paper was written for any educated person to understand, not just forensic experts, so I hope you enjoy it if you do take a look. We talk about both the technical and legal side of things in the paper. Thanks for reading, and I'll check in on this comment later in case anyone has questions.
- random_number 12y agoOne other thing, if you want to try this out at home, all the code we wrote for our experiment was given at the end of the PDF paper as open source scripts, feel welcome to try it on more modern disks/OS and tell us what happens :-)