Data Mining Used Hard Drives
linuxwrangler writes "One hopes the /. crowd knows the perils of discarding storage with sensitive data but this article drives home the point. Two MIT grad students bought used drives from eBay and secondhand computer stores. Among the data found on the 158 drives were 5,000 credit-card numbers, porn, love-letters and medical information."
There IS pornography on your computer!
Another reason to securely erase your data. In the end, _you_ are responsible for data under the Data Protection Act (in the UK anyway)
I only sell broken ones.
I have been pwned because my
It's long been know that laptop theives are often more interested in the data than the computer.
Some computers sold on eBay are sold for the data.
Picked 6 or 7 old 4gig HDDs from my father's company a few years ago, found their company credit line information, personal (and some very erotic) email, and a surprisingly large collection of nudie photoshopped Gillian Anderson photos. Oh yeah, and like 100 different (and I must say, very well-done) quake2 "crackwhore" models and skins lol. I love the people who don't clear their HDDs, it's like treasure chests, you never know what you're gonna get.
------- "From bored to fanboy in 3.8 asian girls" ----------
They are using the NEW, IMPROVED RIAA/MPAA counting system.
I can get creditcard numbers faster on kazaa.
Thats not so bad. My dad happens to be a garbage man and often brings along an occasional system he's scavanged from the dumpsters along his route. Currently I have in my possession an old IBM Aptiva with some guys bank account information on it (He did his checking and stuff with it apparently), but worst of all I have what appears to be an old Gateway tower used to store Medical information for a major hospital in the area my father works. I have over 2 gigs of peoples medical history, including what they were put in the hospital for, insurance information, release dates ect.
I should really do the honost thing and reformat it but its always fun to flip the thing on and just page through stuff.
PGP (for windows or mac, ie not GPG) has two commands related to this: wipe file and wipe free space. They overwrite the appropriate sectors of the disk with several patterns designed to ensure that no matter what (common) encoding scheme the hard disk uses, every bit will have been set at least once, zeroed at least once, and overwritten with pseudorandom data at least once. If you set in on a lot of passes, it does an even better job. This would be a cheap (free, except for time and bandwidth to download it) way to make sure your sensitive data doesn't get out.
That said, experts would tell you that the only reliable way to make sure sensitive data doesn't get out is to thermite your drive.
Also, what's the one-line unix command (running MacOS X here).
I hereby place the above post in the public domain.
People still don't get it. My old boss wondered why I was "wasting my time" doing stuff like writing all zeros to drives of computers we were giving to charity. "I only told you to format them!"
I tried to explain the concept to her, but for an IT manager, she was woefully bad at technology.
Actually, come to think of it, she was about average...
Don't you wish your girlfriend was a geek like me?
or do like this guy did...
icanstilltellyourwifebill.com
he brought a hard drive, found all this cool stuff on it.. & put it to DVD for the masses
You tried your best, & you failed miserably,
The lesson is:
Never Try
Anyone happen to know any share/freeware programs out there for Windows 2k that will recover deleted files. I am intrested in running it on my computer to actually see what I can recover and see how well PGP's disk wipe function works.
But the CC info bothers me. Presumably, this is a corporate drive that got resold (Unless you know of 170 ppl with 25 credit cards a piece, in which case it's time to re-evaluate the financial system in this country).
Personally, I have a standing policy in my department to take apart every HDD, take a magnet to each platter, and send the platters to Iron Mountain for destruction. Then again, we deal with large financial institutions, so we have to be extreme and obsessive-compulsive, which brings me to my actual point;
This stuff should be regulated. If you store personal info on an HDD for business purposes, you should have a legal responsibility (i.e. one that comes with repricussions if not met) to ensure that even after a drive is retired, the data is safe.
Just my $.02
In regards to Wiping data, do yourself a favor and check out http://www.heidi.ie/eraser/
Beyond the wonderfull wiping the program does, there is the option to make an emergency boot floppy that wipes the HD with DOD style 7-pass or a GutherSomething 36 pass! Niffty for the paranoid.
Why not remove the hard drive and donate the computer to a local school. Even at a couple of years old the computer is still useful for students and the school would be more than happy to pick up a new hard drive for it.
1979? I was there, home skillet.
50 MB? Try 5 MB.
SCSI? Not in production.
Sun? Sure...
Linux? Try CP/M.
hexedit? Try debug.
Asian Students? First wave Vietnamese refugees, maybe.
E-mails? If you were working on ARPA.
Porn? Maybe PG rated adventure games...
Tax dollars at work? In 1979, we had to walk
10 miles up hill (both ways) to pay our taxes, and they only accepted krugerrands and virgins without
herpes, both of which were in even shorter supply
and higher demand than they are now.
If you read the article you'll notice that many of the drives belonged to businesses; the CC#s were probably in customer lists. Now why was the parent modded "+5 insightful" rather than "-1 didn't RTFA"?
I hereby place the above post in the public domain.
Take 'em apart and use the magnets as fridge magnets. They hold up an enormous amount of paper, although they do tend to nip one's fingers occasionally :)
I dont bother sanitizing them, squeezing or anything else. I just shoot them.
.357 magnum, after being accelerated to about 1700 fps from a Marlin 1894C lever-action carbine.
They're great target practice when set up at 50 yards. Plus, they're rendered more or less ultra-highly unreadable, with half the platters coated in vaporized lead spall, and then with the platters dramatically warped, penetrated, stretched and shattered. Many areas are complete and totally lost, the ones that arent, would require precise magnetic microscopy to observe the actual state.
These pictures were of a seagate 40mb eide, splashed with a 158grn jacketed hollowpoint in
No database code or data, just typical home directories and stuff. And they were running SCO, but boot blocks and stuff don't generally get written to tapes, so no chance of warezzing from it.
I also snag SCSI hard drives and SyQuest cartridges when they show up for five bucks or less at thrift stores, since most of that is Mac stuff and I'm a Mac-head.
Once I got a 6100 at a thrift store. I presume the owner stopped using it when the PRAM battery died. (When a 6100's PRAM battery dies, the video settings go with it, and unless you're using a fixed-frequency monitor, you get no video unless you hold down command-option-P-R. Looks like real bad a hardware problem when it's just the battery.) I could tell it was used by some college guy, studying to be a lawyer, I think.
"Thrift store hard drives are like a box of chocolates... you never know what you'll find!"
--
"Open source is good." - Steve Jobs
"Open source is evil." - Microsoft
Now days the dod drills a hole through the platter on drives that are bad that have to be RMA'd and have contracts so all they have to return is the top of the drive with the label. as for drives they no longer need i do not know. im guessing they write 0 and 1 patterns on the drive 7+ times. (even then data recovery services could recover it)
Speaking of this, whatever happened to the BIOS lowlevel format option? My old Laser 386 allowed you to lowlevel format any of the harddrives through CMOS setup... it would seem like that's a pretty simple feature to add, and plenty useful.
I have had 2 drives fail well within the warranty period, and did not return them for just this reason.
All Troll + "offtopic" mods are meta moderated as "Unfair", because you abused the system.
Nothing beats the companies who decided that a great site for their "offsite backups" was in the other tower.
--
"Open source is good." - Steve Jobs
"Open source is evil." - Microsoft
- Get out your favorite Linux installer CD or download a copy of Tom's RTBT and write it to floppy or CD-R.
- Boot from the floppy or CD.
- Log in as root.
- Run dd if=/dev/zero of=/dev/hda to erase the master drive on the primary IDE controller (/dev/hdb etc. for the remaining disks)
That's all. It erases all the blocks normally accessible by the disk controller and is probably safe enough for most people. Bad blocks that have been replaced may still contain a little bit of data, and inter-track data may be recoverable by analog means.It's not enough to write 0's to remove traces of a file. Writing random patterns is much better and for older drives you can even do better than random (i.e. more erasing in less passes). The shred(1) command from the GNU fileutils will take care of this for you in Unix-alikes.
e s/ shred/1
_ del.html for an informative paper about the details of how secure deletion works.
http://btr0xw.rz.uni-bayreuth.de/cgi-bin/manpag
See also http://www.cs.auckland.ac.nz/~pgut001/pubs/secure
Backup all important data to both magnetic and optical media (another HD/tape -and- cd/dvd).
Re-format HD using the NTFS file system if the drive is larger than 2 GB, otherwise install NT Server from the earliest available service pack.
Install Windows NT 4 Server, apply service patch 6. Make sure you use a meaningless administrator password.
Upgrade MS Internet Information Server to version 4.0 from NT Option Pack. Create a default web site using the following as the index page (*.htm, *.html, *.shtml):
Why are Chinese, Dutch, German, and Russian Hackers So Homosexual?"
Chinese, hackers, IIS rules, Counterstrike, Dutch, mothers, US ALL THE WAY, Germany sucks, script kiddie, porn, pr0n, disable X10 ads, warez, firewall, Bill Clinton, rar, zip, romz, roms, direct downloads, Long Live Pakistan, How do I secure III?, index of, Ronald Reagan Library
Boot the HD in a computer with an internet connection.
Wait about four days.
Repeat the process three times.
Reformat the drive.
Donate/Discard.
Hey, at least it won't have -YOUR- important data on it.
-dameron
US DoD Spec: 3 passes
German DoD Spec: 7 passes
(from http://www.ontrack.com/library/dataeraser.pdf)
-- R
Data Mining is NOT the process of recovering or otherwise retrieving data. Data Mining is the process of discovering knowledge through data that has already been obtained (usually through statistical and/or AI techniques). I.e., data retrieval/collection is a prerequisite for Data Mining.
Communism was just a red herring.
Last year, my employer of 12 years went out of business. The company was secretly being run improperly for quite a while and the owner closed the doors the same day he found out about the mismanagement.
Being the IT director, I helped the owner, my friend, with the office computers. I planned on wiping all the hard drives and I informed the owner of my plan. He agreed that it was a good idea.
From the next three months, watching the bankruptcy process unfold, I got questioned left and right as to why I wiped the data. The accountants wanted to know why...the lawyers wanted to know why...the liquidators wanted to know why...the court wanted to know why. I understand that a system with an installed OS is more valuable than one that has been wiped clean(the data had been backed up so there was no question of whether data had been destroyed) but this should not be unusual. Nobody asking me these questions were newbies--their jobs involved dealing with bankrupt companies and it was as if they had never seen this before!
Magnetic Speperator...
I have one, honest to god..
It literally removes the magnetic code/signatures from the HDD. I used to work at a data recovery shop (yes one with static room where we physically remove the data etc...) and even we couldn't recover anything off a HDD that has been passed through one...
The only bummer is they draw lots of amperage on a 220... (meaning they literally dim the lights even on my very well powered home...)
The NSA/DOD/Whatever probably uses these when they erase a HDD for redistro/etc...
Erutangis ym si siht.
When I was 14 or 15 (long ago), I took a trip with my friend to visit his father and step mother for the day. We would have to help his father in his print shop for the day, but my friend promised in return we would be able to sneak access to his dads porn collection.
After we ended up working in his dads shop all day, we had dinner, went to his dads house, and his dad left us alone with his computers to play games on. We had brought a palette of 100 disks to hopefully sneak our porn home on, so we began copying all those pcx and gif files onto disks as fast as we could. We couldn't risk looking at them for fear of being caught. It wasn't that unusual to have a huge pile of disks because that was how things got copied in the olden days, his dad thought we were copying some of his games.
Low and behold, we fill all 100 disks with porn (an incredible stash in like 90 or 91). We go home for the evening to each of our houses, divide up the stash, and we both head straight to the computer to um, count our booty.
I get home, pop the first disk into the computer, and just about then I get a phone call -- its my friend, he says "dude, don't look at the pics, trust me." But he's piqued my interest so I have to. I load one up and what do I see? A big juicy cock. We had copied his dads gay porn stash.
Religion is a gateway psychosis. -- Dave Foley
Some sort of explosive device on a trigger next to your mouse?
A shotgun blast? (Hoping you hit the drives and don't get shot...)
Fast acting fantasy software to write random data 144 times over the disk in mere milliseconds?
Don't forget degaussing. Someone is going to have to make the obligatory link to Secure Deletion of Data from Magnetic and Solid-State Memory, so there it is.
Unfortunately, I suspect you're gonna have an unplesant time getting your hard drive to that state...
You need a FREE iPod Nano
First, a little background:
Regarding disk recovery:
Regarding SRAM recovery:
Regarding DRAM recovery:
Based in part on the recovered data, we concluded that candidate A was declared the winner due to a ''mistake'' in mapping ballot slot numbers to candidates. In some cases the slots for candidate A and B were reversed.
An incorrect vote count was reported by the election officials. It is our guess that when we came around asking for the raw data, someone began to collect it. At some point some official(s) discovered the blunder. The system was left on while they stalled for time. When it was clear that we were going to force them to turn over the data someone wiped the system and shut it down.
BTW: The majority of the election officials involved were supporters of candidate B. Even though their blunder caused them to declare candidate A the winner, they still tried to coverup their mistake.
Our conclusion was that the attempt to coverup the mistake was motivated by not wanting to admit the major blunder instead of because of candidate A's influence. This conclusion was reached in part because of messages that we recovered on another system that was not wiped. However we would have never been able to find that other system, nor would we have been able to match the raw slot numbers with the reported vote counts by candidate name without the help of the data recovery consultant and the critical data that they recovered.
I'll offer a few observations:
P.S. I know that some people doubt that one can obtain old data from SRAM and DRAM after poweroff. I did too until it was done for our group. To those who still doubt this: I will refer you to Peter Gutmann's paper on Secure Deletion of Data from Magnetic and Solid-State Memory for another source on data recovery methods.