Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Secure deletion: a single overwrite will do it
H Online ^ | 1/17/09

Posted on 03/11/2009 1:29:17 PM PDT by LibWhacker

The myth that to delete data really securely from a hard disk you have to overwrite it many times, using different patterns, has persisted for decades, despite the fact that even firms specialising in data recovery, openly admit that if a hard disk is overwritten with zeros just once, all of its data is irretrievably lost.

Craig Wright, a forensics expert, claims to have put this legend finally to rest. He and his colleagues ran a scientific study to take a close look at hard disks of various makes and different ages, overwriting their data under controlled conditions and then examining the magnetic surfaces with a magnetic-force microscope. They presented their paper at ICISS 2008 and it has been published by Springer AG in its Lecture Notes in Computer Science series (Craig Wright, Dave Kleiman, Shyaam Sundhar R. S.: Overwriting Hard Drive Data: The Great Wiping Controversy).

They concluded that, after a single overwrite of the data on a drive, whether it be an old 1-gigabyte disk or a current model (at the time of the study), the likelihood of still being able to reconstruct anything is practically zero. Well, OK, not quite: a single bit whose precise location is known can in fact be correctly reconstructed with 56 per cent probability (in one of the quoted examples). To recover a byte, however, correct head positioning would have to be precisely repeated eight times, and the probability of that is only 0.97 per cent. Recovering anything beyond a single byte is even less likely.

Nevertheless, that doesn't stop the vendors of data-wiping programs offering software that overwrites data up to 35 times, based on decades-old security standards that were developed for diskettes. Although this may give a data wiper the psychological satisfaction of having done a thorough job, it's a pure waste of time.

Something much more important, from a security point of view, is actually to overwrite all copies of the data that are to be deleted. If a sensitive document has been edited on a PC, overwriting the file is far from sufficient because, during editing, the data have been saved countless times to temporary files, back-ups, shadow copies, swap files ... and who knows where else? Really, to ensure that nothing more can be recovered from a hard disk, it has to be overwritten completely, sector by sector. Although this takes time, it costs nothing: the dd command in any Linux distribution will do the job perfectly.


TOPICS: Computers/Internet
KEYWORDS: deletion; files; overwrite; secure
Navigation: use the links below to view more comments.
first previous 1-2021-4041-44 next last
To: Bloody Sam Roberts

Full height 5MB for me. Seems weird even typing that since I have a 1TB drive that cost about $100.


21 posted on 03/11/2009 2:59:00 PM PDT by uncommonsense
[ Post Reply | Private Reply | To 9 | View Replies]

To: Aunt Polgara

Tandy Model I.... wrote to cassette tape (mutiple times for backup).


22 posted on 03/11/2009 3:05:09 PM PDT by DigitalVideoDude (It's amazing what you can accomplish when you don't care who gets the credit. -Ronald Reagan)
[ Post Reply | Private Reply | To 20 | View Replies]

To: LibWhacker

Sheryl Crow told me a single wipe was enough too. I still prefer to play it safe.


23 posted on 03/11/2009 3:19:04 PM PDT by Paul Heinzman (Idealism is fine, but as it approaches reality the cost becomes prohibitive. --William F. Buckley Jr)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Aunt Polgara

First job out of grad school, boss had a bunch of old 8-inch floppies from the 60s. Instructed me to get the data off them and put it all on 5.25-inch floppies. Note: I had never seen an 8-inch floppy before and he had nothing with an 8-inch drive in it that I could've used to copy the data. I guess he thought I could read it with my X-ray vision. ;-)

You couldn't buy a new 8-inch drive if you wanted to. They had been obsolete for years. And he was unwilling to pop for an old used system (though it was doubtful I could've found one in working order), even if I could find such a system for 20 or 30 bucks. "Use your connections in the math department and borrow one," he sez impatiently, as if a good math student could've figured that out for himself... LOL! I didn't tell him I'd need connections in the cemetary, not the math department.

24 posted on 03/11/2009 3:50:27 PM PDT by LibWhacker
[ Post Reply | Private Reply | To 20 | View Replies]

To: DigitalVideoDude
Had it.
Later, I was so cool with my Osborne portable computer. I think it weighed about 700lbs:

25 posted on 03/11/2009 3:54:37 PM PDT by MeanWestTexan (Beware Obama's Reichstag Fire.)
[ Post Reply | Private Reply | To 22 | View Replies]

To: MeanWestTexan

Check out the size of that built-in VGA monitor, or was it just an amber screen? Wow.


26 posted on 03/11/2009 3:57:49 PM PDT by DigitalVideoDude (It's amazing what you can accomplish when you don't care who gets the credit. -Ronald Reagan)
[ Post Reply | Private Reply | To 25 | View Replies]

To: DigitalVideoDude

All the guys at MIT were super-jealous.

I would take it to class and type on it.

(Sigh. I was suck a frickin dork.)


27 posted on 03/11/2009 3:58:52 PM PDT by MeanWestTexan (Beware Obama's Reichstag Fire.)
[ Post Reply | Private Reply | To 26 | View Replies]

To: DigitalVideoDude

It was a green screen, if I remember right. Monocolor.


28 posted on 03/11/2009 3:59:43 PM PDT by MeanWestTexan (Beware Obama's Reichstag Fire.)
[ Post Reply | Private Reply | To 26 | View Replies]

To: MeanWestTexan

10 CLS
20 PRINT “HELLO WORLD”
30 GOTO 20
RUN


29 posted on 03/11/2009 4:27:39 PM PDT by DigitalVideoDude (It's amazing what you can accomplish when you don't care who gets the credit. -Ronald Reagan)
[ Post Reply | Private Reply | To 27 | View Replies]

To: DigitalVideoDude

How BASIC.


30 posted on 03/11/2009 4:35:21 PM PDT by MeanWestTexan (Beware Obama's Reichstag Fire.)
[ Post Reply | Private Reply | To 29 | View Replies]

To: uncommonsense
Seems weird even typing that since I have a 1TB drive that cost about $100.

I know. I just went over the 1TB threshold for my home setup. I'm at 1.2 TB and have enough storage to image and backup every thing on 4 PCs and keep a rotation of 3 for all. Sweeeet.

31 posted on 03/11/2009 4:59:35 PM PDT by Bloody Sam Roberts (Despite all my rage, I am still just a rat in a cage...)
[ Post Reply | Private Reply | To 11 | View Replies]

To: ShadowAce

ping


32 posted on 03/11/2009 10:19:38 PM PDT by JoJo Gunn (In this dance of Life, I have two left feet.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: JoJo Gunn

How do you clear cookies...never had a need before but to vote more than once on this poll, guess I need to learn.


33 posted on 03/11/2009 10:24:38 PM PDT by TatieBug
[ Post Reply | Private Reply | To 32 | View Replies]

To: TatieBug

Well, since I’m an old 9x user I might not can help you with IE7 or Vista, if it’s what you’re running.

Try Control Panel>Internet Options>Settings>View Files. Go up to the top and click on View and select “by internet address”, and the cookies should all show first. Be careful not to erase any site that you’d have trouble remembering a password.


34 posted on 03/11/2009 10:46:09 PM PDT by JoJo Gunn (In this dance of Life, I have two left feet.)
[ Post Reply | Private Reply | To 33 | View Replies]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

35 posted on 03/12/2009 5:13:24 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Andonius_99

Or, in an office environment, try “Dr. Thinking’s Low Level Format With Extreme Prejudice (tm)”. Open up the drive (already doing pretty extreme things to the data integrity right there). Take out the platters and shred.


36 posted on 03/12/2009 7:52:47 AM PDT by Still Thinking (Quis custodiet ipsos custodes?)
[ Post Reply | Private Reply | To 3 | View Replies]

To: LibWhacker

“dd” is an incredibly powerful, and often overlooked tool. I’ve used it for all kinds of things. It’s also one of the oldest Unix commands.


37 posted on 03/12/2009 9:13:48 AM PDT by zeugma (Will it be nukes or aliens? Time will tell.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Aunt Polgara
Geeze, you guys must be babies... our first home computer didn't even have a hard drive.. everything was on 5.25 inch floppies. :-)

8" here. Not counting the homebrew with ASR-33 teletype and paper tape.

38 posted on 03/12/2009 10:17:51 AM PDT by sionnsar (Iran Azadi | 5yst3m 0wn3d - it's N0t Y0ur5 (SONY) | "Tax the rich" fails if the rich won't play)
[ Post Reply | Private Reply | To 20 | View Replies]

To: sionnsar

Tape player here (like the kind you used to use in your car). Sounded like a dial up modem if you listened to it.


39 posted on 03/12/2009 11:34:31 AM PDT by MeanWestTexan (Beware Obama's Reichstag Fire.)
[ Post Reply | Private Reply | To 38 | View Replies]

To: Tarpon

You have some knowledge of Professor Peter Gutmann’s work on secure data deletion and recovery, has Gutmann been promoting snake oil for the last decade?

http://www.cs.auckland.ac.nz/~pgut001/


40 posted on 03/12/2009 3:13:53 PM PDT by JerseyHighlander
[ Post Reply | Private Reply | To 7 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-44 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson