Slashdot Mirror


Unclean Military Hard Drives Sold On eBay

An anonymous reader writes "The Daily Mail reports, 'Highly sensitive details of a US military missile air defense system were found on a second-hand hard drive bought on eBay. The test launch procedures were found on a hard disk for the THAAD (Terminal High Altitude Area Defense) ground to air missile defense system, used to shoot down Scud missiles in Iraq. The disk also contained security policies, blueprints of facilities, and personal information on employees (including social security numbers) belonging to technology company Lockheed Martin — who designed and built the system.' Scary that they did not wipe it to Department of Defense standards, which I believe is wiping the whole disk and then writing 1010 all over it."

280 of 369 comments (clear)

  1. I have to wonder by Lord+Grey · · Score: 4, Insightful
    The article states that this finding was the result of a study where a few hundred drives (300+) were purchased from various places and then scanned.

    A spokesman for BT said they found 34 per cent of the hard disks scrutinised contained 'information of either personal data that could be identified to an individual or commercial data identifying a company or organisation.'

    Later:

    For a very large proportion of the disks we looked at we found enough information to expose both individuals and companies to a range of potential crimes such as fraud, blackmail and identity theft.

    Where are the corresponding crimes? If a third of the used hard drives on the market really contain such detailed personal or business information, wouldn't you think that at least one group of criminals would be buying as many of these drives as possible? Granted that there would be capital outlay, but a lot of that is recovered by selling the drives again through the vary same channels, and the risk of getting caught would be extremely low. Quantity of information is lower than with network-based methods (eg, keyloggers, sniffers, etc.) or other information-gathering methods, but I would think the quality of the gathered data would be much, much higher. Good enough to resell for a relatively high amount.

    It seems, to me, that there is a bit of hyperbole going on here.

    --
    // Beyond Here Lie Dragons
    1. Re:I have to wonder by drinkypoo · · Score: 4, Insightful

      Where are the corresponding crimes? If a third of the used hard drives on the market really contain such detailed personal or business information, wouldn't you think that at least one group of criminals would be buying as many of these drives as possible?

      Uh, what makes you think that they aren't? Your comment is utterly devoid of value unless you can prove a negative somehow. Good luck!

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    2. Re:I have to wonder by Anonymous Coward · · Score: 5, Funny

      Your comment is utterly devoid of value unless you can prove you have something worthwhile to respond with. Good luck!

    3. Re:I have to wonder by noundi · · Score: 5, Insightful

      ... wouldn't you think that at least one group of criminals would be buying as many of these drives as possible?

      Well the black market is a quite complicated. The only groups with enough funding and enough motive to even try to obtain this information (disregarding the middlemen that you're mentioning) would be other nations. Let's say you're an exceptional nerd with enough skills to extract this data into usable form (I think it would be fair to say that many /.-ers fit or could fit this profile given some time to research). How would you go about selling this information to let's say North Korea? Who would you contact? Better yet, who would they allow you to speak to? I doubt you can just pick up the phone and ask the operator to "hook you up with the illest of Kim Jongs". But let's say you actually do get to speak with him (or anybody of importance really). How's your Korean? Ok final hypothesis, let's say you actually do speak Korean. What are you going to say? It's not like you're calling from AT&T to offer him 5$ less monthly fee if he subscribes to the service for 24 additional months.

      Basically I see where you're coming from but I wouldn't take the procedure so lightly. Plus there's possibly a lot more important information floating around somewhere that never "got in the wrong hands" as well.

      --
      I am the lawn!
    4. Re:I have to wonder by Hyppy · · Score: 2, Insightful

      You're on the right track. Quite a few crimes of this nature are not reported, at least not publicly.

    5. Re:I have to wonder by sadness203 · · Score: 5, Funny

      Your comment is so fat it was... oh ... no, wrong joke.

    6. Re:I have to wonder by gadget+junkie · · Score: 1

      people always underestimate the dangers of physical delivery.
      Let's think this through: I am a smartie who knows computers and is interested in blackmail. Where do I get thosehard disks? you see, ebay and such are markets, so you have to tell them where you want those disks sent, under what name, on which credit card....then you must retrieve them, probably giving some proof of identity.
      So, given that my objectives are:

      1. get rich;
      2. do NOT get caught in the process;

      I do not think that's the best option.
      For example, if I had sold the THAAD data to North Korea, i'd probably get a free ticket to some strange place, with refreshments.Waterboarding anyone?

      --
      "If a boss demands loyalty, give him integrity. But if he demands integrity, give him loyalty." (John Boyd, 1927-1997)
    7. Re:I have to wonder by Anonymous Coward · · Score: 2, Insightful

      Do retorts like yours really pass for good reasoning on Slashdot?

      What makes you think that the Universe isn't containing within the eye of a pink singing elephant? Your view on the Universe is utterly devoid of value unless you can prove a negative somehow. Good luck!

      Concentrate carefully: when event e happens, we can make a list of events f_1...f_n that we think might lead to e. Let's hypothesise that one such event f_j leads to e. Our first mission is deductive - to demonstrate that f_j can lead to e, and that e can occur.

      Our second mission, however, is philosophical induction - has it actually been observed sufficiently often that f_j leads to e for us to assume that it is typical for f_j to lead to e?

      You've collected enough points to complete the first mission, and assumed that the second just magically happens. No Western philosophical approach follows the "well that could be the cause, and the set of prerequisites have occurred at least once, so who's to say it's not the cause?" line of argument. It could be used to argue so many nonsenses that the scientific approach would be overwhelmed.

    8. Re:I have to wonder by DZign · · Score: 3, Interesting

      After reading the book 'spies among us' I've learned that making contact for selling information is just as simple as walking
      to an embassy/consulate from the specific country and asking to speak with someone about information..

    9. Re:I have to wonder by sandbenders · · Score: 1

      Hmm. I could probably round up half a dozen Korean-speakers who can run a disk-recovery application properly, given an hour or two. Ok, so, I live in a university town and I have an advantage, I'll admit it.

      But I think that it's entirely possible that someone who has run a couple of small scams successfully could parlay that cash into buying several hundred hard drives. Finding name/SSN sets on one of these hard drives has plenty of value for identity thieves right here in the U. S. of A. It's not only the launch codes that have value, it's also all the other data.

      --
      Eagles may fly, but weasels don't get sucked into jet engines.
    10. Re:I have to wonder by MikeBabcock · · Score: 2, Informative

      First off, blackmail doesn't hit the news, that's the whole point. You tell the company what you've got and threaten to use it against them and get paid off.

      Personally I wouldn't blackmail a defence contractor, all things considered but there are those with larger gonads than I though.

      Secondly, a lot of criminals go with what they're good at. Just because a new avenue of crime exists doesn't mean it will be taken advantage of immediately.

      Just think how long the Internet was a big open place before we started getting inundated with scams and before online database theft started hitting the news.

      It seems to me that you give criminals way too much credit, and should also take security more seriously.

      --
      - Michael T. Babcock (Yes, I blog)
    11. Re:I have to wonder by Lost+Race · · Score: 3, Insightful

      Your comment is utterly devoid of value unless you can prove a negative somehow. Good luck!

      "prove a negative"?

      Follow any of the links and never use that idiotic phrase again.

    12. Re:I have to wonder by rant64 · · Score: 1

      Don't forget to see Burn After Reading for an example of how to get killed in the process. Hilarious.

    13. Re:I have to wonder by cayenne8 · · Score: 1
      "Personally I wouldn't blackmail a defence contractor, all things considered but there are those with larger gonads than I though."

      Yep...a lot going on there. You might 'disappear' before you could collect anything...

      --
      Light travels faster than sound. This is why some people appear bright until you hear them speak.........
    14. Re:I have to wonder by Nutria · · Score: 1

      You really can't prove the negative of a proposition like, "Not (all triangles have three sides)." ?

      Sure you can. "Tri" means "3". Thus, if the shape has something other than 3 sides, then, by definition, it's not a triangle.

      --
      "I don't know, therefore Aliens" Wafflebox1
    15. Re:I have to wonder by noundi · · Score: 1

      I never said it wasn't entirely possible, I simply said that the task is not all that easy as the parents fundamental argument is based on this assumption. In addition to this you have to consider another factor. There's a reason that for example you (as you used yourself as an example), even with the alleged resources, don't conduct this, right? Once again I'm not saying the opposite is impossible but it's worth taking to account that educated people generally tend to think things through, at least for a project with this magnitude. And in the end most of us simply leave it as a slashdotted article, since criminal masterplans aren't really our thing, even if we would be able to execute them. This is called profiling. I'll give you an example. If you would go to your university and ask every person that you consider competent for this task, how many would you actually (honest now) get on board? Now what would happen if you would conduct the same test but instead in a prison (let's say that hypothetically the prison holds the same percentage of competent peers). What would you estimate the outcome to be? Of course the paradox that I'm talking about is that statisticly education != crime. Thus the university would be both a good and a bad source. However as mentioned before, I'm not saying it's impossible, but I would go so far to say that it's highly unlikely, and definetly not as easy as the parent claims.

      --
      I am the lawn!
    16. Re:I have to wonder by asdf7890 · · Score: 1

      Where are the corresponding crimes? If a third of the used hard drives on the market really contain such detailed personal or business information, wouldn't you think that at least one group of criminals would be buying as many of these drives as possible?

      My gues is that the value of data on an average drive sourced that way is too low to be worth the average outlay and effort, mainly because the information is out of date (you can have all my bank details from a couple of years ago if you like, it'll get you nowhere as I've changed banks for *everything* since then) or incomplete (i.e. you need some info the user noted on paper and not on the drive as well as the info on the drive).

      Now if the criminals knew with any certainty that the drives being bought were from a certain source and/or had been used up to a particular time, then it might be worth their time and expense to get and scan them. Otherwise they would get better RoI on time spent creating worms/trojans/viruses to collect the data remotely somehow than buying and analysing second hand drives.

    17. Re:I have to wonder by drinkypoo · · Score: 3, Funny

      I'm so sorry I got caught speaking English. Next time I'll try to translate into nerd-speak so that those of you with slide whistles in your assholes will pipe down.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    18. Re:I have to wonder by houstonbofh · · Score: 1

      I can go to a local computer recycler in town, pay cash and walk out with a trunk full of hard drives. If you want bulk, go wholesale.

    19. Re:I have to wonder by Burkin · · Score: 1

      You really can't prove the negative of a proposition like, "Not (all triangles have three sides)." ?

      You mean except for the fact that your proposition violates the very definition of a triangle?

    20. Re:I have to wonder by BrokenHalo · · Score: 1

      Well, in this case one area of hyperbole is where the OP says "The disk also contained ... blueprints of facilities..."

      Now, forgive me if I'm being overly picky, but does anyone here (apart from an old fart like myself) even remember what a blueprint is?

    21. Re:I have to wonder by Plekto · · Score: 1

      Ok final hypothesis, let's say you actually do speak Korean. What are you going to say? It's not like you're calling from AT&T to offer him 5$ less monthly fee if he subscribes to the service for 24 additional months.
      ****
      Easy, actually. USB flash drive in your pocket. Plane ticket.

      The actual number of critical/important documents on any hard drive is usually under a gig or two. Stupidly easy to move about and get to people who have bad intentions - if you have a mind to.

      And simply "deleting" the files - almost any idiot can recover data from that - just get a copy of Easy Recovery Pro or Norton or similar.

      Deleting or destroying the data properly is the only recourse, obviously. But saying that it's too difficult to engage in corporate espionage... It's not 1989 anymore, folks...

    22. Re:I have to wonder by Skevin · · Score: 1

      Maybe it's the caliber of the government IT workers...

      Military Official: Davis, I need you to wipe every hard drive in this container.

      Minimum Wage IT Contractor: Okay. [Opens a pack of lemon-scented WetNaps and starts wiping the outside of the hard drives.] Hard drives wiped, sir.

      Officer: Then I need you to write "10101010" repeatedly on them, until there's no more space!

      MWITC: Okay. [Pulls out Sharpie and draws alternating dashes and circles on the enclosure until there's no more place to put any.] Done, sir.

      Officer: Good. Sign off on this ticket, and we're ready to liquidate them on Ebay!

      --
      "Twice half-assed makes an ass whole." --Solomon K. Chang
    23. Re:I have to wonder by mhall119 · · Score: 1

      Sure you can. "Tri" means "3". Thus, if the shape has something other than 3 sides, then, by definition, it's not a triangle.

      But "angle" means, well, "angle", not side.

      --
      http://www.mhall119.com
    24. Re:I have to wonder by Arancaytar · · Score: 1

      i'd probably get a free ticket to some strange place, with refreshments. Waterboarding anyone?

      Warning to ESL speakers like myself: Waterboarding, despite the misleading name, is not, not, the same as windsurfing. :P

    25. Re:I have to wonder by inode_buddha · · Score: 1

      Actually, yes. --From another olid fart.

      --
      C|N>K
    26. Re:I have to wonder by Nutria · · Score: 1

      But "angle" means, well, "angle", not side.

      You can't have angles on a shape without also having sides.

      --
      "I don't know, therefore Aliens" Wafflebox1
    27. Re:I have to wonder by dumuzi · · Score: 1

      But "angle" means, well, "angle", not side.

      You can't have angles on a shape without also having sides.

      But you could have three angles and three sides without connecting the three sides to make a triangle. Though this would not prove the negative of a proposition like, "Not (all triangles have three sides)."

      To prove the negative of "Not (all triangles have three sides)." You would just have to show a triangle that does have three sides. Most three year olds can do that.

      Though the scrap of wisdom that Doofus was likely trying to convey might have been something more like: You really can't prove the negative of a propostition like "all triangle have three sides"

      Or perhaps the intention was more like "you really can't prove "NOT(all triangles have three sides)"

      Though this still represents a misunderstanding of some scrap of wisdom. One definition of a triangle is "In Euclidean geometry any three non-collinear points determine a unique triangle", therefore a triangle does not need to have any sides, it may consist of three points where the points are not actually connected.

    28. Re:I have to wonder by aamcf · · Score: 1
    29. Re:I have to wonder by Nutria · · Score: 1

      Except that triangle still means "3 angles", so there is no etymological fallacy.

      --
      "I don't know, therefore Aliens" Wafflebox1
    30. Re:I have to wonder by tacarat · · Score: 1

      You really can't prove the negative of a proposition like, "Not (all triangles have three sides)." ?

      Sure you can. "Tri" means "3". Thus, if the shape has something other than 3 sides, then, by definition, it's not a triangle.

      But a square is a rectangle as it meets all the criteria. There's also the "Which month has 28 days in it?" argument in which every month has 28 days. Every shape, except for circles (I hope), has three sides. Some just have those extra value sides included.

      --
      "Common sense will be the death of us all"
    31. Re:I have to wonder by Meski · · Score: 1

      It could be, if you were really bad at windsurfing, be a voluntary form of it.

  2. Unclean? by Nerdfest · · Score: 4, Informative

    I guess we'll need to format them in a purifying fire then.

    1. Re:Unclean? by Anonymous Coward · · Score: 2, Insightful

      I agree. If you have sensitive data on a disk (or paper or anything else) DESTROY it. Fire is best and most useful but other methods are possible.

    2. Re:Unclean? by auric_dude · · Score: 4, Informative

      Or use http://www.dban.org/node/68 - good enough for The Government Of Canada so good enough for these disks?

    3. Re:Unclean? by Mendoksou · · Score: 4, Funny

      It's finally time to start up my competitor to the NSA. The American Security Service (acronym to be determined) will, for the cost of hard drives on ebay (as well as some key other components... you never know what might be hidden in all those GPUs... we'd better test them. And those CPUs... and that RAM... and those computer games...), provide quality security and defense against our enemies. Especially if those enemies happen to be in the games I'm playing at the time.

      --
      DISCLAIMER: I am very rarely serious. If the above comment seems asinine makes no sense, it is most likely a bad joke.
    4. Re:Unclean? by Hyppy · · Score: 3, Insightful

      Most DoD member units approve DBAN already. Especially when it's set to the platter-melting 35-pass Guttman Wipe.

      The problem is when someone DOESN'T follow proper procedures. Rules are great and all, but someone is always going to break them in some way

    5. Re:Unclean? by Nimey · · Score: 3, Informative

      Since you apparently don't know what you're talking about: the 35-pass wipe is bullshit, and even the author says so.

      http://en.wikipedia.org/wiki/Gutmann_method#Criticism

      Essentially some of those patterns are specifically for obsolete MFM drives, and others are specifically for equally obsolete RLL drives. Nowadays you should just use random patterns, and even the DoD is fine with 7 passes.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    6. Re:Unclean? by socsoc · · Score: 1

      I don't get why everybody doesn't use DBAN, private or government (as long as it meets their needs). I proudly tell my staff members that machines have been wiped to DoD levels before disposal.

    7. Re:Unclean? by NotQuiteReal · · Score: 5, Funny

      Aww, you just went for a cheap laugh.

      When you said The American Security Service (acronym to be determined) I thought for sure, you were going to start a wiping service!

      --
      This issue is a bit more complicated than you think.
    8. Re:Unclean? by Hyppy · · Score: 1

      I said "member units." Not every IASO is completely familiar with Peter Gutmann's full paper. Either way, a 35-pass Gutmann wipe is better than a 1 or 2-pass zero wipe. They're erring on the side of caution, but that doesn't mean you need to personally attack me.

      Don't be a prick with such a short fuse.

    9. Re:Unclean? by Big+Nothing · · Score: 1
      --
      SIG: TAKE OFF EVERY 'CAPTAIN'!!
    10. Re:Unclean? by Rastl · · Score: 1

      We had to send back a personal notebook under an in-warranty replacement. I used DBAN to make sure that disk was going back devoid of anything of potential use. I know there's a faint chance of someone using forensic tools to recover it but FFS at least it takes care of the casual user problem.

      And yes, I was "assured" that they wipe the disks before refurbing them but a quick run of DBAN is just common sense.

      Oh wait, we're talking about a government contractor here ...

    11. Re:Unclean? by Nathrael · · Score: 4, Funny

      Fire is best and most useful but other methods are possible.

      Nuke it from orbit. It's the only way to be sure.

      --
      A good education is a bit like a STD - it makes you unsuitable for a lot of jobs and gives you a desire to spread it.
    12. Re:Unclean? by Runaway1956 · · Score: 1

      Same or similar reason that not everyone uses network security? Ignorance. I have a PILE of hard drives from old computers that I have browsed through. One of them contains an ancient NT4 network server. Not much on it - but the really funny thing is, I can log onto that company's network as administrator, because it STILL HAS the same admin password. If I were dishonest, there is SO MUCH I could do......

      --
      "Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
    13. Re:Unclean? by longrangebunnykiller · · Score: 1

      Instead of 0's and 1's, I've found that it's better to write 2's and 3's to the disk. 2-3 times better, in fact.

    14. Re:Unclean? by Barny · · Score: 1

      even the DoD is fine with 7 passes.

      Funny that, I know SIGINT (Australian signals intelligence) don't trust ANY form of drive erasure, with the cost of drives, they just burn them.

      Considering the amount of budget these departments, why would they take the risk?

      --
      ...
      /me sighs
    15. Re:Unclean? by neomunk · · Score: 1

      Do you (or anyone else reading) know of an actual case in which data was recovered from a 1 or 2 pass 0 wipe on modern drives?

      I don't think it's been done successfully, but would be interested in being proven wrong.

    16. Re:Unclean? by Kirth+Gersen · · Score: 1

      This issue has come up before. My conclusion was that a single pass might indeed be insufficent and it was hard to say how many would be enough.

      Why would an attack method which would recover very small fractions of the data from the disk be valuable to the attacker? One suggestion I thought was plausible was this: with sufficiently advanced techniques some good data may be retrieved (for instance, a drive may mark a failing sector as bad and never allow it to be accessed again by normal means, but it may occasionally be readable by drive-specific utilities).

      This acts as known plaintext and may reduce the time needed to break encryption (of a separate data source which was fully available to the attackers because it was believed to be safe) from several universes to a few days.

      Btw, this known-plaintext idea makes me think it's probably a bad idea to encrypt a system disk which also contains data.

    17. Re:Unclean? by jgalun · · Score: 1

      even the DoD is fine with 7 passes.

      Funny that, I know SIGINT (Australian signals intelligence) don't trust ANY form of drive erasure, with the cost of drives, they just burn them.

      Considering the amount of budget these departments, why would they take the risk?

      I'm not so sure the original poster is correct that the DoD is fine with 7 passes. Consider ISL 2007-01. It says that "Sanitization of memory and media is required when the memory or media is no longer needed to store classified information. Clearing is required before and after periods of processing as a method of ensuring need-to-know protection, and prior to maintenance."

      And if you look at the matrix on page 19, overwriting is not acceptable for sanitization. Only degaussing or destruction are acceptable. It sounds like whoever disposed of this hard drive just did not follow guidelines, or that the drive was disposed of before ISL 2007-01 was released.

    18. Re:Unclean? by Nimey · · Score: 1

      I think you're right, actually. Change that to say "DoD used to be fine with 7 passes".

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    19. Re:Unclean? by tzanger · · Score: 1

      I keep an eye on the Canadian government surplus auctions. Every single computer going through there is sold WITHOUT hard drives.

      I imagine they either re-use them internally or destroy them.

    20. Re:Unclean? by couchslug · · Score: 1

      "I guess we'll need to format them in a purifying fire then."

      Hard drives are of trivial value, as are obsolete computers. Mandate that every Federal agency destroy all their discarded computers by shredding. Don't try to save a nickel, just destroy the machine. It is trivially easy. Just do it.

      --
      "This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
    21. Re:Unclean? by calmofthestorm · · Score: 1

      Even zeroing the device in a single pass is enough to deter most criminals or dragnet methods, shred is enough to defeat all but the most expensive cryptanalysis.

      There are levels of paranoia between strategic high-yield nuclear weapons and selling unwiped.

      --
      93rd rule of Slashdot: No matter how obvious my sarcasm is, my comment will be taken seriously by someone.
    22. Re:Unclean? by Anonymous Coward · · Score: 1, Interesting

      I don't get why everybody doesn't use DBAN

      Speaking as someone who owns a box of obsolete unwiped drives (some of them have been sitting in that box for over a decade), here's how it happens.

      At some point, I need to replace drives; either the box just can't physically hold more (so I'm taking small drives out and putting bigger ones in) or I'm upgrading to a totally new computer and for whatever reason I don't want to use the old drives.

      Somehow I move my old data to my new drives. Now I have the old drives. They need to be wiped, but..

      For the next few days, they're a good backup. Maybe that new drive is going to fail. This is a time when failure does happen to be more likely than usual. So, I shouldn't wipe 'em right away.

      I want 'em disconnected from the box right away, though.

      So the "plan" is .. um, I'll wipe 'em, but I'll do that .. later because (in all seriousness) later really is better than now. Some limited procrastination (and "limited" really is the key, here) is not only acceptable, but actually The Right Thing.

      It's just that I never get to it. And then things happen, and I eventually I can't even talk to my old drives. I don't have a SCSI adapter. I have these SCSI drives, with personal information sitting on them, but no way to get at it myself. (If I wait much longer, the PATA drives are going to have the same problem.) The only practical(?) solution is a sledgehammer and fire, rather than "wiping."

      And so they sit there in that fucking box. I can't use 'em and I can't throw 'em away. :(

    23. Re:Unclean? by TehDuffman · · Score: 2, Interesting

      I don't know if its just the Marines but we just get a sledge hammer and take turns beating the shit out of the hard drives. Seems to do a good enough job to me.

    24. Re:Unclean? by Jah-Wren+Ryel · · Score: 1

      even the DoD is fine with 7 passes.

      Not for classified data - there is no official procedure to declassify a hard disk. 7 wipes may be sufficient in some cases for moving a classified disk from one classified program to another related classified program, but never for complete declassification.

      --
      When information is power, privacy is freedom.
    25. Re:Unclean? by BrokenHalo · · Score: 1

      I think I might have mentioned this before, but it's still relevant:

      Once upon a time, I used to be a blacksmith, and I've still got my tools. The best way I've found to deal with unwanted HDDs is to heat them up to ~700-800 deg. C in my forge, then wallop the hell out of them with my power-hammer. Hot things, sparks and lots of noise == Fun. ;-)

      Incidentally, why won't Slashcode implement the standard &deg (;) html entity?

    26. Re:Unclean? by TemporalBeing · · Score: 1

      There's really two states of operation here that can be answered by one question: Did the system in question have sensitive (e.g. classified) data on it?

      If no, then the 7 pass is okay.

      If yes, then it must be destroyed and may never be used for non-classified uses again.

      So if it did have sensitive/classified data on it, then whoever disposed of it did not follow procedure - in which case there will be prison time for someone after an investigation occurs. Otherwise, the consequences will be unknown - though prison is likely, but not likely for as long.

      --
      Truth is like the sun. You can shut it out for a time, but it ain't goin' away. - Elvis Presley (source: imdb.com)
    27. Re:Unclean? by zerocool6900 · · Score: 1

      Actually yes I have recovered usable data from a HDD that was wiped twice and had started on a third. I just installed my Ontrack Data Recovery Pro and let it run....granted the files weren't perfect and didn't recover many either but some jpgs, rtfs, and a few short mp3s survived.

      --
      Some people never learn...no matter how many times something happens to them.
    28. Re:Unclean? by TemporalBeing · · Score: 1

      7 wipes may be sufficient in some cases for moving a classified disk from one classified program to another related classified program of equal or greater classification, but never for complete declassification.

      There fixed that for you.

      Moving to a lower classification level is the same as declassifying.

      --
      Truth is like the sun. You can shut it out for a time, but it ain't goin' away. - Elvis Presley (source: imdb.com)
    29. Re:Unclean? by stile99 · · Score: 1

      I guess we'll need to format them in a purifying fire then.

      Ummm...nobody picked up on the Thomas Covenant reference, or did I read a little too deeply?

    30. Re:Unclean? by Nimey · · Score: 1

      Wiped with what? I've had someone get lots of data back from a hard drive that was slow-formatted with the WinXP installer, but we haven't tried this stunt with something that's been run through DBAN.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    31. Re:Unclean? by iwein · · Score: 1

      Disappointing really. Especially in a military organization you'd think they could think of some cool ways to increase the entropy of a hard disk.

      --
      Show a man some news, distract him for an hour. Show a man some mod points, distract him for the rest of his life.
    32. Re:Unclean? by Chris+Mattern · · Score: 1

      "enough to deter most criminals"

      "enough to defeat all but the most expensive cryptanalysis"

      Or you can just take a ten-pound sledgehammer to them and be sure. If the data on them is of any importance at all, the pathetic prices they'll fetch on Ebay are in no way worth it.

    33. Re:Unclean? by rts008 · · Score: 1

      What about as you said, formatting with the Windows installer(say XP/NTFS), then reformatting with a Linux live cd in ext3?
      I've no reason to ask except curiosity, but have often wondered how effective this would be regarding 'wiping' a HDD.

      --
      Down With Slashdot BETA!!! I've been around the corner and seen the oliphant; you can only abuse me from your perspecti
    34. Re:Unclean? by Nimey · · Score: 1

      No idea, but it's an interesting idea. I don't have the time to try it, though -- that recovery I mentioned took most of a day to run.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    35. Re:Unclean? by rts008 · · Score: 1

      Well, thanks for the reply!
      I was just curious in relation to the topic of discussion, and thought you might have some insight here for me. :-)

      If you can 'spill the beans*', what software did you use for this so I could find out...I am recovering from surgery and on 'temporary disability' while I recover.
      If you check my posts, you can confirm that I have had way too much time to hang out here!(too much time to post while drunk!- check my 'foes' list!)

      *If not, any ideas of what I can use with GNU/Linux(Kubuntu 9.04) to check this?

      Don't put too much effort in this, as it is more of a 'what if' thing for me, and not a vital 'need'. (don't be afraid to just 'blow it off', as it would just be an 'academic exercise' for me:-)

      My brother does this kind of stuff for the US State Department, but we are not 'exactly' on speaking terms for the moment.(my next project to tackle, but it's complicated)

      --
      Down With Slashdot BETA!!! I've been around the corner and seen the oliphant; you can only abuse me from your perspecti
    36. Re:Unclean? by Nimey · · Score: 1

      The program was some commercial package for Windows. When I see my co-worker who did that I'll ask him.

      We're just a Midwestern public university, no classified stuff here. Basically I screwed up and we had to try to recover someone's data.

      --
      Hail Eris, full of mischief...

      E pluribus sanguinem
    37. Re:Unclean? by metaforest · · Score: 1

      Back in the day, I used to ride around on an old 3-speed bike collecting techno-fruit that had fallen from the corporate trees in and around Montain View, CA....

      My arch nemesis: Atari Security Service.... They drove around in white Ford Broncos(the shift supervisor) or white CJ-5 Jeeps( the rank & file) they caught me a couple of times, but I altered my raid tactics and they never knew I was there.

      Along with valuable caches of ICs, engineering prototypes, demo units, cosmetic QA failed units, and retired test equipment, many coffee stained "Confidential" documents passed through my paws... HR reports with employee data, engineering documents, source code, executive policy memos, and even legal documents, litigation and contract drafts....

      I do miss being a larval geek in the Sillycon Trench....

  3. Scary that they sold the disk at all by Anonymous Coward · · Score: 5, Insightful

    You can wipe a disk with "dd if=/dev/zero of=/dev/sda" and nobody will get anything from it after that, but the problem isn't the technical feasibility of securely wiping a hard disk: It's a problem of procedure. If hard disks are sold, there's always going to be a mishap where disks which were supposed to be wiped are not and sold with the data intact. Also, why was this data not encrypted? Anyway, hard disks are just not worth enough to take these risks. Destroy the disks and do it in-house.

    1. Re:Scary that they sold the disk at all by bleh-of-the-huns · · Score: 4, Interesting

      There are much quicker ways then that. In fact, at my old office, we had NSA approved degaussing equipment for hard drives, that destroyed the data permanently (no amount of forensics will be able to retrieve it), but left the drive itself intact for reuse or resale.

      The fun part of course is that when you turn it on.. 2 or 3 floors of lights all dimmed at the same time for a few seconds while it powered up and it hummed.. loudly... Thats a powerful magnet :)

      --
      I came, I conquered, I coredumped
    2. Re:Scary that they sold the disk at all by s0litaire · · Score: 3, Informative

      i'd use "dd if=/dev/urandom of=/dev/sda" Urandom is slower but better..

      --
      Laters Sol "Have you found the secrets of the universe? Asked Zebade "I'm sure I left them here somewhere"
    3. Re:Scary that they sold the disk at all by rongage · · Score: 5, Informative

      Modern drives have "servo tracks" on them - used for setting the head position. If you use an eraser powerful enough to wipe the drive, then the servo track is most likely also wiped - rendering the drive totally useless to most folk.

      --
      Ron Gage - Westland, MI
    4. Re:Scary that they sold the disk at all by Anonymous Coward · · Score: 1, Insightful

      Degaussing a hard drive permanently damages it (if you can do it, that is). Not only will all servo information be lost, modern hard drives also store the firmware on the disks. Deleting the firmware significantly reduces the reuse potential and resale value of a hard disk.

    5. Re:Scary that they sold the disk at all by A+beautiful+mind · · Score: 2, Informative

      You've got it backwards. Urandom reuses the entrophy pool, so it will not block, but will be slower. /dev/random is the real deal.

      --
      It takes a man to suffer ignorance and smile
      Be yourself no matter what they say
    6. Re:Scary that they sold the disk at all by chad.koehler · · Score: 1

      But if you use /dev/urandom you never know WHAT they'll be able to get off of your harddrive! For you know you SS# could be there! ;)

    7. Re:Scary that they sold the disk at all by samos69 · · Score: 3, Informative

      Yup, we just purchased a Verity degausser to wipe some drives before donating them to charity and have found that the servo track is wiped and they become completely useless... £1800 wasted, but it's damn fun to wipe things with!

    8. Re:Scary that they sold the disk at all by Anonymous Coward · · Score: 2, Funny

      No, there is a probability that the random data is the same as the original. Would you take that chance?

    9. Re:Scary that they sold the disk at all by multisync · · Score: 2, Informative

      i'd use "dd if=/dev/urandom of=/dev/sda" Urandom is slower but better..

      If you have access to dd, you probably have access to shred. It makes several passes using different patterns (25 by default), and has the option of zeroing the drive on the last pass. I believe it meets DOD standards. I'm not sure how effective it is with slack space, which often holds recoverable data even after running utilities that are supposed to wipe data off drives, but dd wouldn't be any better.

      --
      I don't care why you're posting AC
    10. Re:Scary that they sold the disk at all by c6gunner · · Score: 1

      To be fair, he did say "for reuse or resale". He didn't specify what KIND of use. You could use it a a paperweight, a doorstop, a hammer ... the possibilities are endless! And then you're done using it, you can always sell it on e-bay.

    11. Re:Scary that they sold the disk at all by pipatron · · Score: 1

      The comparison was between /dev/zero and /dev/urandom, /dev/random was never involved.

      --
      c++; /* this makes c bigger but returns the old value */
    12. Re:Scary that they sold the disk at all by GargamelSpaceman · · Score: 1

      Military standards are to write 1010 all over the drive... Hmm. I bet the FBI could get those top secrets afterwards. Really I don't even know if I'd trust degaussing for anything really important. Or fire for that matter, unless it were hot enough to actually melt the entire drive to a puddle of slag. How many times has someone burnt a paper in a fireplace only to have the ashes remain, still clearly readable? Opening the drive, removing the platter and using a grinding wheel to turn it into iron filings seems pretty foolproof. Also grind away any and all chips on circuit boards that may have cached data ( not sure if they do but why take the chance ). That would seem appropriate for matters of national security.

      --
      ...
    13. Re:Scary that they sold the disk at all by Teferison · · Score: 1

      It doesn't have to end up as a constant magnetization for someone to be able to recover the data. A predictable pattern would suffice.
      Actually not even overwriting the disc with random data might be enough to ensure that noone can recover the data. Dedicated forensic experts can read overwritten data, by distinguishing between a 0 -> 1 and a 1 -> 1 magnetization (Simplified example).

    14. Re:Scary that they sold the disk at all by wvmarle · · Score: 1

      Exactly what I was thinking.

      OK the US military has some mighty expensive wars to finance, but I doubt they are this short on cash that they would have to sell hard disks on e-bay of all places. Instead of simply tossing them in a shredder. It is not that they are worth much or so.

      I would expect that this is a drive from some employee's personal computer who took home data (either on USB or copied it to his home computer over the VPN) to work on it, and later sold his hard disk on eBay.

    15. Re:Scary that they sold the disk at all by BetterSense · · Score: 1
      the shred man page specifically says that it is ineffective on journaling file systems. From TFMP:

      CAUTION: Note that shred relies on a very important assumption: that the file system overwrites data in place. This is the traditional way to do things, but many modern file system designs do not satisfy this assumption. The following are examples of file systems on which shred is not effective, or is not guaranteed to be effective in all file system modes: * log-structured or journaled file systems, such as those supplied with AIX and Solaris (and JFS, ReiserFS, XFS, Ext3, etc.)

      http://linux.die.net/man/1/shred

    16. Re:Scary that they sold the disk at all by Anonymous Coward · · Score: 1, Informative

      Every single-pass pattern is "predictable": Just read it. In fact, if you can recover data from a single pass wipe, you also have the generation before the current data, so you can theoretically recover data further back. The patterns don't matter. What matters is the signal to noise ratio.

      Dedicated forensic experts can read overwritten data

      That is a myth. Granted, there is a theoretical possibility due to magnetization processes not being 100%, tracks having widths and heads not always being in the same position over the track. If you believe in any of these effects making recovery of overwritten data possible, then the number of overwrites is just a matter of how paranoid you are. If that possibility bothers you, your adversaries must have technology which is unavailable to all commercial data recovery businesses (and probably doesn't even exist). If that is the case, destroy the drive: It's the only way to be sure. For everyone else, "dd if=/dev/zero of=/dev/sda" is exactly as good as specialized wiping software. (Beware of people hawking 35-pass overwrite software: These patterns are historic and have no relevance to modern hard disk technology. Touting this procedure as somehow better than a single pass zeroing proves that the person does not understand the topic at hand.)

    17. Re:Scary that they sold the disk at all by systemeng · · Score: 2, Informative

      The mistake in thinking that it's a bad thing to never have the data be the same is roughly speaking part of how the Germans lost WWII. The British broke the Enigma cypher by figuring out that a given letter was _NEVER_ encoded as the same letter. That tiny blip in the probability function allowed breaking many coded messages if they could get a small amount of cleartext such as the weather report.

    18. Re:Scary that they sold the disk at all by Thaelon · · Score: 1

      You've clearly never worked for the DoD. I have. And I highly suspect that the drive wiping procedures dreamt up by the DoD are more as a result of some middle manager, or pseudo techie wanting to get bullet points on his resume for making some procedure "more secure" or something rather than real technical reason.* Add a few generations of this crap and you get the procedure we have today.

      There's no sound technical reasoning for doing anything than a dd if=/dev/zero of=/dev/sda or /dev/random as you like. It's just that too many people adhere to the brain dead fallacy of "if wiping it once is good, wiping it twice is more betterer!"

      dd it once, that stuff is gone. Me, I'd just use DBAN cause it's easier.

      Unless the hard drive manufacturer specifically built in hardware methods of hiding the data from normal use, or making copies to hidden locations, dban or dd are more than sufficient for even the most sensitive data. All else is senseless wankery and a waste of time.

      *People who look for jobs in the government are typically more after something stable, possibly with decent pay and long term with good benefits more than they're after challenging problems to sharpen their skills. As a result it's chock full of cruft.

      --

      Question everything

    19. Re:Scary that they sold the disk at all by Barny · · Score: 1

      unless the platter is heated to a temperature above the material's Curie temperature

      Thermite is damn cheap to make :)

      --
      ...
      /me sighs
    20. Re:Scary that they sold the disk at all by Orgasmatron · · Score: 2, Insightful

      Don't forget that modern drives use material with obscenely high coercivity so that the domains don't spontaneously flip their neighbors. If you use a magnet powerful enough to randomize the platters, you'll warp all the steel parts.

      --
      See that "Preview" button?
    21. Re:Scary that they sold the disk at all by jimicus · · Score: 2, Insightful

      The problem with shred (and indeed any such utility) is that it doesn't account for application behaviour. What if some application that uses the file re-writes it - eg. because of some change to the file - to a different filehandle than the one the file was originally read from?

      What if at some point the file was read into memory and that memory was swapped out by the OS? There are lots of quite reasonable scenarios where there are fragments of the file sitting around indefinitely.

    22. Re:Scary that they sold the disk at all by nick13245 · · Score: 1

      i'd use "dd if=/dev/urandom of=/dev/sda" Urandom is slower but better..

      If you have access to dd, you probably have access to shred. It makes several passes using different patterns (25 by default), and has the option of zeroing the drive on the last pass. I believe it meets DOD standards. I'm not sure how effective it is with slack space, which often holds recoverable data even after running utilities that are supposed to wipe data off drives, but dd wouldn't be any better.

      Shred works on a filesystem level to delete individual files on the drive. Worse than that, it only works on a subset of filesystems (primarily Linux and Unix based).

      You want something that wipes *everything* from the drive, no matter what the filesystem is. dd, or dcfldd (which is what I prefer to use) does a sector by sector copy of data from a source to a destination. So the following command:

      dd if=/dev/urandom of=/dev/sda

      Will effectively fill the hard drive with random data making and data recovery impossible.

    23. Re:Scary that they sold the disk at all by Amouth · · Score: 1

      http://www.ontrackdatarecovery.co.uk/columbia-drive-recovery/

      that one allways gets me..

      http://news.sky.com/skynews/Home/Sky-News-Archive/Article/20080641316604

      love to qoute this

      "
      He said it was the most challenging project every undertaken by Kroll, especially when you considered "it had been through re-entry, hit the earth and then sat in the outdoors".
      He added that even though a modern disk could not have been recovered in the same way, he said: "Disks that may have been unrecoverable five years ago may be recoverable today - never assume that your data may not be recoverable."
      "

      --
      '...if only "Jumping to a Conclusion" was an event in the Olympics.'
    24. Re:Scary that they sold the disk at all by Spoke · · Score: 1

      Dude - shred is used to write directly to the disk. No files or applications involved here.

      The disk's data is completely gone.

      What I typically do is stack up disks to be wiped in one box and when I get a bunch of them, plug them into a system with a bunch of IO controllers and boot up DBAN - Darik's Boot and Nuke. A lot easier than wiping disks one by one.

    25. Re:Scary that they sold the disk at all by couchslug · · Score: 1

      I treat any hard drive I discard to a couple of shots with a hand sledge.
      The defaulting to a techy solution like wiping is understandable, but why bother?

      --
      "This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
    26. Re:Scary that they sold the disk at all by calmofthestorm · · Score: 1

      I'm more worried about secret NSA firmware that backs up all the data to a second set of platters in the bad sectors or something than I am about being able to recover past a round or two of shred. Which is to say, not really because I don't care about any data /that/ much. Keeping my nosy neighbor (granted, I'm at a nerd school) out is good enough for me. So cryptroot, full 33 pass of shred on LUKS storage, and a pass or two of shred on the full device followed by 0 is good enough for me.

      Would mod you insightful but...yeah... mouse so far away.

      --
      93rd rule of Slashdot: No matter how obvious my sarcasm is, my comment will be taken seriously by someone.
    27. Re:Scary that they sold the disk at all by rrohbeck · · Score: 1

      Also, the coercivity of the magnetic coating keeps going up. Yesterday's degausser may not be strong enough for today's drives.
      This applies even more to tape cartridges. Insufficiently degaussed DLT tapes have been a problem every now and then (LTO uses magnetic servo tracks but DLT doesn't so degaussing them is common.)

    28. Re:Scary that they sold the disk at all by rrohbeck · · Score: 1

      Doesn't make a difference for modern (PRML) drives. The data is randomized before it is encoded and written because pathological data patterns decrease the signal/noise ratio in PRML.

    29. Re:Scary that they sold the disk at all by Frank+T.+Lofaro+Jr. · · Score: 1

      How would the drive read the firmware if it has to have firmware to tell it how to read the disk?

      Now, firmware UPDATES could conceivably be stored on the disk...

      --
      Just because it CAN be done, doesn't mean it should!
    30. Re:Scary that they sold the disk at all by greed · · Score: 1

      There's a better reason. Thermite is damn FUN to make. Well, damn fun to watch melt stuff.

    31. Re:Scary that they sold the disk at all by Chris+Mattern · · Score: 1

      You can wipe a disk with "dd if=/dev/zero of=/dev/sda" and nobody will get anything from it after that

      Sure they can. It takes some specialized equipment and some know-how, but it can be done. The problem is that magnetic bits retain a faint impression of their previous setting. If you just do a one pass writing of zeros, somebody with sensitive magnetometers used correctly will be able to pull off just about everything that was on that disk.

      Anyway, hard disks are just not worth enough to take these risks. Destroy the disks and do it in-house.

      No argument on this one; the fact that erasing your disks *isn't* so cut-and-dried makes it an even better idea.

    32. Re:Scary that they sold the disk at all by Agripa · · Score: 1

      Most hard drive cases are composed aluminum and stainless steel. Neither of these will provide significant shielding against a magnetic field used for degaussing.

      Steel, iron, and mu-metal are commonly used for magnetic shielding.

    33. Re:Scary that they sold the disk at all by metaforest · · Score: 1

      Modern drives have "servo tracks" on them - used for setting the head position. If you use an eraser powerful enough to wipe the drive, then the servo track is most likely also wiped - rendering the drive totally useless to most folk.

      This wasn't the case on SCSI drives up to about 4GB. They had enough smarts to rewrite their own servo tracks if you did a low-level format.

      Most PATA drives of the same vintage had relatively dumb controllers and could not be recovered. They were also less than half the price of comparable SCSI drives, and a lot less reliable.

      From personal experience, it was fairly simple to recover data from a SCSI drive with a control board failure by replacing the control board. There was no assembly specific information stored on the drive controller for units made from the same line of drives. This was true even if the swapped controllers we from drives with different capacities, as long as the controller was the same model.

      Not so with ATA drives... Servo tracks are written using a special machine that determines the unit specific parameters. Those unit specific parameters are then stored on the controller during final controller/CAN assembly, calibration, and test.

      It is likely that this is also true of modern pSCSI and SAS drives, as it seriously reduces the complexity of the drive controller. This also reduces QA costs and QA failures at final assembly.

  4. please... by VMaN · · Score: 5, Interesting

    Before people start discussing if drives should be overwritten 32 or 2^32 times, please show me ONE proven example of a regularly zeroed drive being recovered.

    This challenge has stood for more than a year.
    http://16systems.com/zero.php

    1. Re:please... by canix · · Score: 5, Insightful

      It is possible that the people most likely to have the resources and expertise to do this (i.e. govt. security depts.) don't want to announce that they have this capability ...

    2. Re:please... by sakdoctor · · Score: 5, Funny

      In the UK, the government uses magnetic fields generated by train seats to erase sensitive data.

    3. Re:please... by RivieraKid · · Score: 1, Redundant
      If only I had mod points.

      It's both funny and tragic because it's true.

      --
      "Necessity is the plea for every infringement of human freedom. It is the argument of tyrants; it is the creed of slaves
    4. Re:please... by tsalmark · · Score: 1

      Even if it is doable, no one is going to buy random 0'ed drives to run through an electron microscope just to see if there maybe a few thousand dollars worth of blackmail on it.

    5. Re:please... by WoLpH · · Score: 3, Insightful

      Why would any company enter a challenge like that? What data recovery company would comply to this: "You also must publicly disclose in a reproducible manner the method(s) used to win the challenge."?

      Regardless of wheter it is possible or not, it is definately not worth the trouble for anyone.

    6. Re:please... by Hyppy · · Score: 5, Insightful

      $500 to recover a drive, eh? If I had a data recovery business, I'd hang up on you too. If you want people to take you seriously, then perhaps you should present yourself in a serious manner. Offering $500 and a basement-made "King of Data Recovery" title is not a serious challenge. It's a slap in the face to any legitimate data recovery business to be "challenged" like that.

    7. Re:please... by phillips321 · · Score: 1

      I thought the same thing. Surely dd is good, but i prefer to use shred, especially if I'm deleting some 'ill shit'!

    8. Re:please... by tiananmen+tank+man · · Score: 1

      The reward is a $60 harddrive with a 80gig capacity, yea who wouldnt want to spend a lot of time recoverying data for that.

      That site mentions that they will send the harddrive to any "established, professional data recovery company" with free shipping and then down the page it says "Send a self-addressed, postage-paid box with packaging material to the address listed below and we will mail the drive to you."

    9. Re:please... by fulldecent · · Score: 1

      No matter that you must include reproducible instructions on how to do this.

      --

      -- I was raised on the command line, bitch

    10. Re:please... by MikeBabcock · · Score: 1

      The last reputable data recovery company I dealt with charged us $1500 to recover a dead laptop drive. They gave us a new drive that was nearly perfectly recovered from the old dead, dropped, damaged drive.

      That may seem like real money to some people, but it was worth it to the client in question. Why on earth would they do even more work for one third the money?

      --
      - Michael T. Babcock (Yes, I blog)
    11. Re:please... by rcamans · · Score: 1

      Actually, there are companies in the data recovery business, and they do advertise this capability. Some actually post success stories.
      All you have to do is google drive recovery. Duh.

      --
      wake up and hold your nose
    12. Re:please... by commodoresloat · · Score: 2, Funny

      It's a slap in the face to any legitimate data recovery business to be "challenged" like that.

      But I thought a slap in the face was the proper way to announce your challenge!

    13. Re:please... by wvmarle · · Score: 1

      They would still only go after hard disks that are known to have contained interesting information. Dragnet scanning like was done for TFA doesn't sound feasible at all with zeroed disks.

      Assuming such a drive can be recovered in the first place, it will not be a trivial task to do. AFAIK there are currently no commercial offers to recover such a disk, so it may be so that the government/CIA/MI5 are be able to, it's then for sure really really tough.

      And why should they in the first place? Enemies that want to keep their data secret will use encryption for a start, and then presumably destroy disks physically when disposing of them. It is easier to kidnap someone and get the information that way.

    14. Re:please... by LanMan04 · · Score: 1

      Yeah, because labs with electron microscope really need that $500...

      --
      With the first link, the chain is forged.
    15. Re:please... by canix · · Score: 1

      Since "drive recovery" seems to show just companies who deal with deleted data or disks which have had a mechanical failure, do you think you could post a direct link to a company that can recover data from a disk that was deliberately and completely overwritten rather than a pithy comment?

    16. Re:please... by maxume · · Score: 1

      Not even for $500 and an obsolete drive?

      --
      Nerd rage is the funniest rage.
    17. Re:please... by Hyppy · · Score: 1

      Touche, monsieur!

    18. Re:please... by Wierdy1024 · · Score: 1

      Nice find - I've bookmarked that page to send to people who argue about which "secure shredder" program is better...

    19. Re:please... by Tycho · · Score: 1

      That method works, but for the day or more it took them to do that, using the Secure Erase ATA command on that drive would have been more secure and taken only an hour or two. The Secure Erase command is part of the ATA standard and present on every ATA drive larger than 15GB. The command "dd" cannot access and erase every sector as ATA drives do not allow access to certain sectors, like reallocated sectors. Even though SCSI drives do not have this limitation, I still wouldn't erase one with "dd", there are probably better open source tools. An even better and faster option for even more secure erasure on ATA drives, is to use the drive in encrypted mode. When done with the drive, toss the encryption key. This makes any data on the drive practically unusable. Reuse of the drive is still possible with a standard reformat after unlocking the drive.

      More reading:
      Hard Drive data erasure methods are described on page 27 of the PDF or page 19 as printed on the document:
      http://csrc.nist.gov/publications/nistpubs/800-88/NISTSP800-88_rev1.pdf

      Describes different methods of data sanitization on magnetic hard drives. Discusses hard drives exclusively, unlike the NIST paper above.
      http://cmrr.ucsd.edu/people/Hughes/DataSanitizationTutorial.pdf

      Page from the author of the above paper with a DOS program that can send a Secure Erase ATA command to a drive, no source though:
      http://cmrr.ucsd.edu/people/Hughes/SecureErase.shtml

      However, t13.org the website of the ATA standards body is here, and has the last drafts of standards available here (nearly as good as the actual standards, which cost money):
      http://www.t13.org/Documents/MinutesDefault.aspx?DocumentType=4&DocumentStage=2

      Start here though for the Secure Erase Command:
      http://www.t13.org/Documents/UploadedDocuments/docs2009/d2015r1a-ATAATAPI_Command_Set_-_2_ACS-2.pdf

      --
      Impersonating Tycho from Penny Arcade since before there was a PA.
    20. Re:please... by calmofthestorm · · Score: 1
      --
      93rd rule of Slashdot: No matter how obvious my sarcasm is, my comment will be taken seriously by someone.
    21. Re:please... by Torg · · Score: 1

      Hard drives do not write to the *exact* same position all the time. Additionally when they do so they effect more then the precise amount of magnetic medium below the write heads. It is technically feasible (with modification of the firmware on the drive or physically removing platters) to half step the read heads and read the spaces next to where data was written.

      Devices that do this generally take one drive and attach another that can hold the recovered data. A simple search in your favorite search engine with "forensic data recovery" will revel companies that can do this and hardware available for the task.

    22. Re:please... by MarkGriz · · Score: 1

      It is possible that the people most likely to have the resources and expertise to do this (i.e. govt. security depts.) don't want to announce that they have this capability ...

      And even more likely is that these people have no interest in recovering your deleted tax returns, novel you've been working on for 3 years, or your 100 GB collection of porn

      --
      Beauty is in the eye of the beerholder.
    23. Re:please... by VeNoM0619 · · Score: 1

      Zombie porn?

      --
      Disclaimer: I am not god.
      We may not be created equal
      But we can be treated equal.
    24. Re:please... by BikeHelmet · · Score: 1

      One of my Uncle's HDDs (almost?) lit itself on fire.

      It was an external Samsung drive. Something happened to the motor, and then smoke started streaming up out of it, and there was an awful putrid smell. I was quick to unplug it before it lit anything on fire. (it was sitting on a desk ontop of piles of paper)

      Data recovery was quoted at $2800, so my Uncle opted to do nothing, despite having plenty of important documents stored on it. Years later he made a new friend that worked at a data recovery place, and the guy did it for him for about $180. :)

      What really pissed me off, was Samsung wouldn't replace the drive or cover the data recovery costs. They wanted his old one to be sent in, but if he had sent that in he'd lose any chance of getting his data back.

      I wonder if he'd have faced the same arguments if their HDD had burned his house down when it died. Somehow I think those cheap bastards got off lucky. I'm never recommending Samsung drives again!

    25. Re:please... by noidentity · · Score: 1

      Yes, I have a drive with some uh test data on it that I am challenging anyone to recover. The prize is $100, and you must send me all the data (including the 3 GB direcory named "dissertation") so I can er verify that you have properly recovered it. This isn't data I've lost! It's a real challenge of data I've specially crafted for the test.

    26. Re:please... by Chris+Mattern · · Score: 1

      Wow. $500. Kiddo, this type of data recovery typically costs TEN TIMES that. You can't find anybody willing to do it for a 90% discount. What a surprise.

    27. Re:please... by rts008 · · Score: 1

      I was 100% with you until...

      ...or your 100 GB collection of porn

      No self-respecting geek would pass up adding to their pr0n collection!

      --
      Down With Slashdot BETA!!! I've been around the corner and seen the oliphant; you can only abuse me from your perspecti
  5. DoD wiping standards by mati.stankiewicz · · Score: 5, Informative

    "which I believe is wiping the whole disk and then writing 1010 all over it."

    Taken from DoD 5220.22-M Wipe Standard:

    "[...]DoD requires overwriting with a pattern, then its complement, and finally with another pattern; e.g., overwrite first with 0011 0101 [35h], followed by 1100 1010 [CBh], then 1001 0111 [97h]. The number of times an overwrite must be accomplished depends on the storage media, sometimes on its sensitivity, and sometimes on differing DoD component requirements. In any case, a purge is not complete until a final overwrite is made using unclassified data."

    1. Re:DoD wiping standards by Hyppy · · Score: 1

      For sensitive drives, many U.S. units do in fact destroy the platters. Usually, it's a matter of smashing the drives into teeny little bits, then melting them.

    2. Re:DoD wiping standards by bleh-of-the-huns · · Score: 4, Interesting

      Certain 3 letter facilities in the US do that.. in fact, any electronic equipment going in.. never leaves. I have seen the destruction of a thumb drive that accidentally made it into the facility (many people arrived for a meeting there), but was caught on the way out and destroyed.

      Same facility provides all electronic equipment needed for various press events and what not.

      --
      I came, I conquered, I coredumped
    3. Re:DoD wiping standards by mevets · · Score: 1

      Oblig,
      In Soviet Russia, the drive wipes you...

    4. Re:DoD wiping standards by Sancho · · Score: 1

      I can't find that anywhere in the actual document. Which page is it on, and which edition of the document?

    5. Re:DoD wiping standards by infalliable · · Score: 1

      I heard of DoD personnel taking hard drives to drill presses to render them useless. I'm not sure if they were also degaussed/erased prior to or what information was originally on them.

    6. Re:DoD wiping standards by TheLink · · Score: 1

      Yep don't bring your phones, ipods in too...

      I wonder:

      What if you had photographic memory and were a good artist. Would they let you out?

      What if you had memory issues with your brain and thus have a prosthetic memory installed to help you?

      --
    7. Re:DoD wiping standards by drinkypoo · · Score: 4, Funny

      What if you had memory issues with your brain and thus have a prosthetic memory installed to help you?

      What if the aliens came, and took you back to your home planet?

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    8. Re:DoD wiping standards by dragonjujotu · · Score: 1

      Actually, it really depends on how good the IT/ET units are. A good unit will follow that DoD reg. for overwriting the drive, then proceed to vent some frustration on the hard drive through creative means, and then they will turn them in to the proper disposal authority. Lazy/greedy units will just sell them on eBay or throw them in a dumpster where may civilian will pick it up and sell it on eBay or use it.

      --
      Yes, I am obsessed with ellipses.
    9. Re:DoD wiping standards by Barny · · Score: 1

      Yeah, we got a local installation of SIGINT, I have a friend or 2 who work there (and are allowed to talk about the destruction of drives).

      They don't bother with erasure, ANY media, usb sticks, cds, dvds, HDD... ANYTHING, gets put in the furnace before it leaves a building, and is made all nice and melty.

      They don't take chances to make back a pittance on second hand parts, and for that I am glad :)

      --
      ...
      /me sighs
    10. Re:DoD wiping standards by Runaway1956 · · Score: 1

      "In any case, a purge is not complete until a final overwrite is made using unclassified data."

      This. Wiping, randomizing, etc, yada yada yada is all fine and dandy. But, when you OVERWRITE the damned platters with SOMETHING, then you have pretty much screwed the pooch when it comes to data recovery. Gonna sell a hard drive? Use a couple different wiping tools like DD and /dev/urandom. Then, make sure it's full of music. Download a few dozen songs without burdensome copyrights attached, and fill the drive up. A script can easily create a directory structure, so that you can write the same songs 25,000 times to ensure the disk is entirely overwritten.

      Doing so ensures that data recovery people don't have to merely search for clues and listen to echoes of ghosts - first they have to unearth the clues and the echoes.

      --
      "Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
    11. Re:DoD wiping standards by Erich · · Score: 1
      Typical government:

      1100 1010 [CBh],

      Can't even convert 0b1010 to the correct hex digit (A).

      --

      -- Erich

      Slashdot reader since 1997

    12. Re:DoD wiping standards by Amazing+Quantum+Man · · Score: 1

      I've seen this. I was talking with our IT guy while he was drilling some drives.

      --
      Fascism starts when the efficiency of the government becomes more important than the rights of the people.
    13. Re:DoD wiping standards by internerdj · · Score: 1

      All you hardware guys can kiss it. This is just further proof that at the smallest level a computer is just bits...

    14. Re:DoD wiping standards by TheLink · · Score: 1

      Depends on the state of the planet I guess.

      Anyway it's just a matter of time till prosthetic memories become possible.

      1) We already have PDAs and phones with "reminder" apps, cameras, microphones etc.
      2) Already people can control devices by just "thought" alone.
      3) The blind can see in low res via eye implants, or they can see via other means - mesh on tongue (while that's not so practical, it proves that alternate channels can be used for seeing).

      When the technology provides this, there would be other issues as well - e.g. DRM.

      The **AA might want to prevent/charge people for using their augmented memories and sensors. Whether just to replay or to "telepathically" (wireless) communicate with others.

      They'd probably want a lot more than a penny for "your" thoughts.

      --
    15. Re:DoD wiping standards by Cboyd0319 · · Score: 1

      The DSS (Defense Security Service), the guys that came up with the wipe standard, updated this June 28, 2007.

      Section 54 of this document details the update.

      Basically, the deal is that wiping a drive is no longer an option for sensitive or classified material. The media HAS to be physically destroyed.

      "Effective immediately, DSS will no longer approve overwriting procedures for the sanitization or downgrading (e.g. release to lower level classified information controls) of IS storage devices (e.g., hard drives) used for classified processing."

  6. Financial Firms Do the Same by __aajwxe560 · · Score: 5, Informative

    I perform computer forensics work, and part of my research towards obtaining my degree was going to the MIT Swap Meet (great event) and buying used hard disks from vendors on occasion. In about 90% of the cases, the user appeared to have simply "deleted" the files, with nothing more. Now, I would expect this for a normal home user, not knowing any better, but the biggest thing of concern was the number of drives that came from various corporate entities. I was able to see and read data from drives that clearly came from several major banks, including mortgage apps, SSN's, corporate planning documents, etc. Again, the files appeared to have been simply "deleted" by the IT folk, instead of securely wiped, making it trivial at best to read everything.

    So while this example is no better, I believe it highlights an ongoing problem that involves better user education and disk encryption helps solve.

    1. Re:Financial Firms Do the Same by Moschaef · · Score: 1, Interesting

      At our company the policy is to destroy all drives withdrawn from operations. The problem is with our local IT support telling management they've destroyed the drive but then selling them for their own personal gain. They're already stealing property so I doubt that they're much concerned about proprietary/sensitive data.

      We had a similar problem several years back when we switched 1,000+ CRT monitors to LCDs. The CRTs weren't the issue, no one wanted them, rather it was the DVI cables. The techs used the old VGA cables and sold the DVI cables on EBAY for $5 bucks a piece.

      Of course this is something no reader of SlashDot would ever condone... Right...

    2. Re:Financial Firms Do the Same by notarockstar1979 · · Score: 3, Funny

      I created the secure wiping policy for my department. It involves an axe. I get to use it on anyone who tries selling old drives instead of having them shredded.

    3. Re:Financial Firms Do the Same by Abcd1234 · · Score: 1

      Of course this is something no reader of SlashDot would ever condone... Right...

      Because the typical Slashdot reader is a thief?

      Stupid thing is, your post actually had an interesting anecdote and made a good point. And then you decided to close off with a nice, unnecessarily dickish comment.

    4. Re:Financial Firms Do the Same by Abcd1234 · · Score: 1

      Funny thing, I didn't make any comment regarding the "typical" Slashdot reader. I used the term "any".

      Uh. No, you didn't. You said, and I quote:

      Of course this is something no reader of SlashDot would ever condone... Right...

      Any sane reader of the English language would interpret that statement as a sarcastic indictment of the Slashdot community. ie, <sarcasm>no reader of Slashdot would ever condone theft<sarcasm>.

      'course, when it comes right down to it, it just sounds like your grasp of the English language is far weaker than you realize. You should work on that. Maybe then your otherwise insightful posts won't languish without modpoints.

    5. Re:Financial Firms Do the Same by Frank+T.+Lofaro+Jr. · · Score: 1

      Because the typical Slashdot reader is a thief?

      Not a thief, a copyright infringer!

      --
      Just because it CAN be done, doesn't mean it should!
    6. Re:Financial Firms Do the Same by BikeHelmet · · Score: 1

      Recently my HTPC/NAS's primary HDD died. It was a PATA one, because linux doesn't like booting from my board's SATA controller.

      (but all the data drives are SATA)

      I decided to pick up an old PATA HDD to act as a replacement OS drive while I RMA it. I picked up 4GB PATA Maxtor drive from a local business selling old computer parts for cheap. A working install of Windows XP was still on it, along with MS office license keys. My Documents still had piles of files sitting inside it, including letters and invoices containing names, dates, phone numbers, etc..

      I stopped investigating there, and wiped it. Had to get my HTPC back online in time to record TV shows!

      When I went back to the business to ask them about it, they said they do ask if there's any personal info on the drive, but people probably incorrectly answer "No", thinking delete means it's gone. Go figure.

  7. Little OT Anecdote by rodrigoandrade · · Score: 5, Informative

    I used to work for a major OEM whose clients included the military, along with other branches of the US government. The military in particular had a "strict" policy about hard drives: they did NOT RMA them EVER. If a PC of theirs was to be returned or sent in for service, it arrived without the hard drive.

    What's the point of such strict policy towards your supplier if some dumbass from within will just pawn it off on Ebay?? It's not the first time this happens.

    1. Re:Little OT Anecdote by Hyppy · · Score: 1

      Either way, the point of a policy is not to be broken. I'm sure Private Murphy or Contractor Black wasn't following proper procedure when he decided to sell some old hard drives for beer money.

    2. Re:Little OT Anecdote by bleh-of-the-huns · · Score: 3, Interesting

      The problem is not necessarily from a gov branch, but most likely a supporting contractor, in this case Lockheed martin.

      Same reason why those same contractors are forbidden from using VPN from gov facilities (DOD and Federal atleast) to their home offices. In the past, a certain contractor from a certain company at a certain 5 pointed facility introduced some lovely malware that spread like wildfire fromthe contractors company to the gov facility.

      However, like I said, while policy says what not to do, deadlines and management looking the other way sometimes to meet those deadlines and whatnot go against those policies, sometimes nothing happens, sometimes bad things happen.

      --
      I came, I conquered, I coredumped
    3. Re:Little OT Anecdote by Pontiac · · Score: 1

      I'll back this up.. No data devices are allowed off site. The security team has a rather large shredder that all data devices are disposed of in.
      Even systems with small embedded flash drives..
      If it stores data it's ground to tiny pieces.

      --
      If you think it's expensive to hire a professional to do the job, wait until you hire an amateur. --Red Adair
    4. Re:Little OT Anecdote by reddburn · · Score: 1

      Why's it gotta be a Black contractor, man? You racist?

      --
      "Those who believe in telekinetics, raise my hand" - Kurt Vonnegut, Jr.
  8. In other news.. by __aanmys7397 · · Score: 5, Funny

    ..the market is being flooded with Chinese made ground to air missile defence systems, available for a quarter of the price, and half the accuracy.
    Fine Print: THERE IS NO WARRANTY FOR THE SYSTEM, TO THE EXTENT PERMITTED BY APPLICABLE LAW

    1. Re:In other news.. by Icegryphon · · Score: 1

      I eagerly await them to come up on ebay. I do love cheap chinese knockoffs.

  9. Why not just destroy these disks? by JackassJedi · · Score: 2, Insightful

    Why does the DoD not simply destroy the disks in question?

    --
    Power corrupts the few, while weakness corrupts the many.
    1. Re:Why not just destroy these disks? by snspdaarf · · Score: 1

      Exactly. Grind them up. If they can grind up cars in a junkyard, surely someone can make a smaller device to grind up a hard drive.

      --
      Why, without your clothes, you're naked, Miss Dudley!
    2. Re:Why not just destroy these disks? by bleh-of-the-huns · · Score: 1

      My guess was that this was not a DoD system, and probably not at the DoD facilities, but rather at the contractor facilities.

      They are however (which is written into the contract that was signed when the project was awarded) required to comply with DoD regulations. It appears that in this case, probably during a technology refresh would be my guess, that there was a shit ton of old equipment, and the IT folks got lazy, since securely wiping a drive without a degausser of sorts takes a very long time.

      --
      I came, I conquered, I coredumped
    3. Re:Why not just destroy these disks? by camperdave · · Score: 5, Interesting

      Why does the DoD not simply destroy the disks in question?

      Sometimes it's easier to detect a security problem by letting some information leak.

      --
      When our name is on the back of your car, we're behind you all the way!
    4. Re:Why not just destroy these disks? by eth1 · · Score: 1

      Especially if they have fingerprints of the data on each drive, and tracked which one went where for disposal.

    5. Re:Why not just destroy these disks? by systemeng · · Score: 1

      They said it was sensitive information, not classified information. While the rules for military and contractor handling of classified material differ slightly, sensitive information is not protected by the same rules that govern classified information. Leak a classified drive: a bunch of people go to jail. Leak a sensitive drive and everybody goes to slashdot and gets sent to bed without a cookie.

  10. Nearly right... by LoyalOpposition · · Score: 5, Funny

    scary that they did not wipe it to Department of Defense standards which I believe is wiping the whole disk and then writing 1010 all over it.

    That's nearly right. The actual procedure is to wipe it to DoD standards, and then load it up with fake documents.

    -Loyal

    --
    I aim to misbehave.
    1. Re:Nearly right... by H0p313ss · · Score: 3, Funny

      scary that they did not wipe it to Department of Defense standards which I believe is wiping the whole disk and then writing 1010 all over it.

      That's nearly right. The actual procedure is to wipe it to DoD standards, and then load it up with fake documents.

      -Loyal

      So you're saying this Area 51 map and Build-Your-Own Nuke instructions I have here might be bogus?

      --
      XML is a known as a key material required to create SMD: Software of Mass Destruction
  11. Who is really to blame? by sunking2 · · Score: 4, Insightful

    Did lockheed actually own these machines, or do they lease them? My guess is LM (like most larger companies) has a contract with someone like CSC/IBM/etc who actually owns, maintains, and replaces machines. This is probably where the ball was dropped. Every 3 years here CSC replaces 10s of thousands of PCs that they are itching to sell off before they depreciate into worthlessness. I can certainly see them taking short cuts, or missing a few. This is the problem with outsourcing IT infrastructure. They don't always really understand or care about the same thing as you.

    1. Re:Who is really to blame? by Senator24 · · Score: 1

      Did lockheed actually own these machines, or do they lease them?

      They do. I use to work for Lockheed and I was a sub contractor and we basically handled all the PC's. I was hired through a temp agency and most of the guys I worked for were also part of the temp agency. A lot of those guys didn't care if the HD was wiped good enough or not. Just as long as the PC wouldn't boot up. Then the HD's were shipped off and I'm guessing resold.

    2. Re:Who is really to blame? by trekie86 · · Score: 1

      Most likely lockheed didn't own the boxes. They are government owned but managed by lockheed. SOmeone said earlier that they were probably illegally sold and that is probably true. Our HDs are all marked if they contain classified data, never leave the building unless they are transported by a cleared courier, and destroyed upon completion. Just not booting isn't the standard, they are totally destroyed, not going to work anymore. As for replacing PCs, it hardly happens, especially in classified environments. We run them until they are so old that the government doesn't use them anymore or they die. Even then, the harddrives stay.

    3. Re:Who is really to blame? by sunking2 · · Score: 1

      Reality is that once a company takes over the infrastructure at a large company it is next to impossible to get rid of them. In the end, the ones who own every single machine that runs your entire business are the ones who have the other by the balls. Oh sure there are slaps on the wrist, but its a marriage with a prenup that neither party would ever be willing to pay. How does a fortune 30 that doesn't own a single desktop/server/infrastructure/help desk dump their provider? They can't.

  12. Probably illegally sold by roger_that · · Score: 5, Interesting

    The drives were probably illegally sold. DoD requires the destruction of classified drives, and contractors are supposed to follow the same rules. If the drive(s) in question held classified data (which they apparently did), they should have been wiped, then physically destroyed. Sounds like someone bypassed the last step, and tried to make a little profit on the side, by selling the "destroyed" drive.

    Disclaimer: I work for a contractor on a US Government contract, working with classified data. (at the five-sided building)

    1. Re:Probably illegally sold by T+Murphy · · Score: 2, Funny

      the five-sided building

      ...most buildings have a roof and 4 walls, so that doesn't exactly narrow it down.

    2. Re:Probably illegally sold by Renraku · · Score: 1

      Sounds like someone has been selling government information. Send them to jail for doing so.

      --
      Job? I don't have time to get a job! Who will sit around and bitch about being broke and unemployed then?
    3. Re:Probably illegally sold by DoofusOfDeath · · Score: 1

      the five-sided building

      ...most buildings have a roof and 4 walls, so that doesn't exactly narrow it down.

      Yes, but let's assume his building also has a floor.

      He works in The Triangle!

    4. Re:Probably illegally sold by chris-chittleborough · · Score: 1

      Yep. Procedures that senior officials spent weeks designing defeated because someone way down the hierarchy saw a chance to make a few hundred bucks.

      There's a lesson in here somewhere.

    5. Re:Probably illegally sold by Ecuador · · Score: 1

      You are forgetting the floor. It is obvious he works at the Luxor.

      --
      Violence is the last refuge of the incompetent. Polar Scope Align for iOS
    6. Re:Probably illegally sold by dysan27 · · Score: 1

      especially when the building he is probably alluding to actualy has 201 sides when you add up the all the rings corridors and the roof.

    7. Re:Probably illegally sold by Elbowgeek · · Score: 1

      That's what happens when you assign the duty of hard drive destruction to the lowest person on the totem pole, no doubt someone only a little better than your average fast food employee.

      The fact is that with many thousands of computer systems being turned over in a large corporation there's bound to be some rogue drives out there whether innocently or not.

      --
      Who is this delectable creature with an insatiable love of the dead?
  13. Is it just me... by s0litaire · · Score: 4, Funny

    Or are these types of stories probably sponsored by E-Bay's PR department..

    Just think of all those people now bidding on old hard drives now... Probably won't be able to pick one up for under £99 by the end of the week :D

    That reminds me... Got a few old ones to sell myself... :D:D

    --
    Laters Sol "Have you found the secrets of the universe? Asked Zebade "I'm sure I left them here somewhere"
    1. Re:Is it just me... by halcyon1234 · · Score: 1

      Just add to the listing "Drives are being liquidated from the assets of bankrupt mortgage company."

  14. Re:Uhh by linzeal · · Score: 3, Interesting

    The problem is when people have a whole bunch of them and 100 40 gig hard drives sold at a flea market can pickup 2000 dollars some weekends. I did a pull once where the guy was savvy enough to wipe the hard disks but did not check all the CD-Rom drives, half of which had CDs in them with corporate information. Looking it over I could of easily sold the info to an unscrupulous competitor but decided to just send them to him COD for cost of postage.

  15. For Highly Classified Data, it's more than a wipe by sirwired · · Score: 3, Informative

    I worked in a highly classified facility once. The wipe "standard" was to hire a lowly intern (such as myself), remove the platters from the case, take them out back, and sandblast them. The agencies scientists had decided degaussing wasn't good enough.

    SirWired

  16. Sounds like gruntwork to me by Anonymous Coward · · Score: 2, Funny

    First part of story. scary that they did not wipe it to Department of Defense standards which I believe is wiping the whole disk and then writing 1010 all over it.

    I just had a mental image of a private being assigned a sharpie and a room full of hard drives, furiously writing 1010 on each one.

  17. DoD standards by konigstein · · Score: 2, Interesting

    Are to overwrite the harddrive 9 times, then degauss (which makes a loud POP and the magnetic information is GONE, and THEN to drill 6 holes through the drive. The DoD policy memo can be found here http://www.drms.dla.mil/turn-in/usable/cpu-memo-jun01.pdf

    --
    This space intentionally left blank
    1. Re:DoD standards by Sancho · · Score: 2, Informative

      Note that document only covers unclassified data.

    2. Re:DoD standards by Nukenbar · · Score: 1

      It think most people simply put hard Drives in industrial shredders that spit out little pieces of the drive the size of a small nail.

  18. The procedureâ(TM)s more than *that*! by kuleiana · · Score: 1

    The procedure is actually to write random bits (01101111010110000 etc) at least seven to 13 times! This doesnâ(TM)t 100% guarantee nonrecovery, but it comes very close. Also, most hard drives are *not* regularly zeroed out (in free space), unless thereâ(TM)s a security policy in place at that particular facility/organization/office that implements a daemon thatâ(TM)s going to handle it for you.

    --
    Thinkingman.com New Media
    1. Re:The procedureâ(TM)s more than *that*! by Sancho · · Score: 1

      [citation needed]

      Not trying to be an ass, but there's a lot of misinformation out there on these "DoD wipe standards." Lots of people are throwing around these things, but I've only seen one person trying to back it up with something from the DoD.

  19. How to dispose of SECRET media by Anonymous Coward · · Score: 1, Informative

    First, everything that is SECRET must be serialized and fully accounted for at all times. Paperwork must be done when it is decommissioned.

    It must be physically destroyed. If it's a CD, then it must be broken or otherwise scratched to the point where reading any data off it becomes not only unlikely, but impossible. Fire is good.

    Hard drives (I had one fail on my in Iraq) must be double packaged, clearly labeled SECRET, and escorted by authorized personnel the entire way to somewhere a lot higher than the infantry battalion I am in to get properly destroyed.

    Since it's got Lockheed Martin employee information on it, it's a Lockheed Martin hard drive, and their accountability is probably not as demanding as the Marine Corps...probably a guy in the tech department wanting to make some extra money.

    1. Re:How to dispose of SECRET media by jtev · · Score: 1

      Ummmm... the procedure for hard drives seems a little overdone to me. Wouldn't a thermite grenade out in the middle of nowhere mean that the drive would be destroyed with less risk of interception than shipping it back to where it can be "properly" destoryed?

      --
      That which is done from love exists beyond good and evil
  20. Re:Uhh by cowbutt · · Score: 1

    The end-users probably aren't (officially) selling their used drives; they're probably selling their three year old machines by the kilo to an authorised disposal agent, who in turn wipes the drives (or is contractually supposed to do so) then either sells the machines as used, or breaks them into components for sale as used.

  21. Re:Uhh by kannibal_klown · · Score: 1

    Why does anyone sell hard drives second hand, anyways? Most organizations and people buy them, and keep using the old disk until it either dies or becomes so obsolete that it's no longer worth using. How much value does some old 60 gig hard drive have on ebay, anyways? New 1 terrabyte drives are a mere $70 at newegg!

    I can imagine that the drives might come from retired PCs. Many companies replace their PCs every X years for various reasons: their lease ran out, the PCs are too underpowered for current software, or upgrading/maintaining the old machines becomes too much of a hastle.

    After disposal/donation/selling those PCs have to go somewhere, so I'd imagine they get broken up into their main components and sold off. Selling a PII-266 might be a tall order but someone might want that 60GB HD.

  22. Re:The procedure's more than *that*! by kuleiana · · Score: 1

    OK, obviously /. has a problem with UTF8, which my browser's inserting by default. sorry

    --
    Thinkingman.com New Media
  23. Say what? by minsk · · Score: 3, Funny

    wiping the whole disk and then writing 1010 all over it.

    Did exactly that. Removed it from a computer. Wiped all over the disk. Then took a marker and wrote all over it. For additional security, wiped it *again* to remove the marker. And you nuts are still claiming there's secrets on it...

    </fiction>

  24. A+++++ Vendor! by xonar · · Score: 5, Funny

    A++++++++++++ service! Quick shipping, and free military secrets included! Would buy from again.

  25. Wiping the whole disk by writing 1010 by Gathers · · Score: 2, Funny

    The problem with writing 1010 all over the disk is that it only covers an extremely tiny fraction of the disk. Most modern drives are much larger than 4 bits.

    It is also highly inefficient since the OS would always have to read a whole sector (typically 512 bytes) and modify it in memory before writing it back again to avoid changing any bits outside of those 4 that are to be wiped!

    So, why not just sell it on eBay and hope the buyer wipes the disk before using it?

    1. Re:Wiping the whole disk by writing 1010 by Gathers · · Score: 1

      Yes, I know that addressing a nibble (4 bits) to a byte is not possible unless you have a 4-bit computer like the Intel 4004, Toshiba TLCS-47 etc. That's the whole reason why you, to get that effect, have to read-modify-write the whole byte.

      It is actually kind of the same as how you must read-modify-write a whole sector to change one byte on a disk.

      Also, and perhaps more importantly; I was only joking/trolling and I have no idea why anyone would want to describe my post as Informative. Perhaps they found "Most modern drives are much larger than 4 bits." to be informative? :P

      Cheers!

  26. Does the IRS do it better or worse? by BenEnglishAtHome · · Score: 2, Informative

    I work for the IRS and we supposedly use the DOD standard. Our wiping software actually has a "/DOD" switch. However, unlike the standard quoted in another post, our software just reinitializes the MBR and then does 7 random overwrites. Is that better or worse than writing patterns? I dunno.

    I do know, however, that we never let a drive out of our inventory without a wipe. If the drive has failed completely, we have a big magnetic blanker we use. (Local option - in my office, we then take those drives apart, abuse the platters, and one of our techs makes sculptures from them. Neat stuff.)

    As an aside, we never RMA drives, either. If a drive in our possession fails, we call for a warranty replacement and send back in the return box a signed statement swearing that we destroyed the old drive. If a laptop has a failure that requires a contractor tech to replace parts, we make them come on-site then have someone stand over them the whole time to make sure they don't try to actually read anything off the drive.

    I would expect the military to do at least as well. Am I wrong?

    1. Re:Does the IRS do it better or worse? by querist · · Score: 1

      The patterns are better because you KNOW what is happening. I do computer forensics work as part of my day job.

      While the chances are very, very slim, it is possible that a "random" wipe could write the exact same 1111 1111 or 0000 0000 every time to the same area. Also, how random is your random source?

      Recovering anything from a drive wiped with

            dd if=/dev/zero of=/dev/sda

      requires highly specialized hardware and training - not what your average criminal will have handy (especially the hardware).

      Governments, OTOH, may indeed have that hardware, though the "official" story is that modern hard drives have such high data density on the platters that doing a /dev/zero wipe as shown above would render the disk completely unreadable. Keep in mind that those DOD standards were created back when drives had MUCH lower data densities.

      Personally, I like the sandblasting suggestion that someone else posted. That should do it - that or a vat of acid.

      However, if you want to be able to use the drive again, /dev/zero should do the trick.

    2. Re:Does the IRS do it better or worse? by inject_hotmail.com · · Score: 1

      Nope...I would say you are right. I recommend something like this to everyone that asks me about getting rid of their old computer(s) (and hence: hard drives). I usually can't believe it when seemingly intelligent human beings maintain a cavalier or the "well, it's going back to the factory, what could go wrong?" attitude.

      Very few people have been interested in paying for such a data protection service.

      I don't like to RMA drives I can't properly wipe...does the sworn statement actually work?

      I wish more people were security minded...

    3. Re:Does the IRS do it better or worse? by BenEnglishAtHome · · Score: 1

      Yes, the sworn statement works, but only because it's part of our contract negotiation from the beginning. We set it up as a part of each acquisition that we won't be returning any drives. Since we buy more that 30,000 computers a year, the people who sell them to us (currently, mostly HP) are OK with it. Occasionally there's some tension when a particular run of drives fails at a high rate; the contracts can be unprofitable if things go badly enough. But that's rare.

      Such arrangements are far more common than most people realize.

    4. Re:Does the IRS do it better or worse? by WarlockD · · Score: 1

      Yea, Nokia does the same thing too. Hell, they have a BONDED guy come by to shred the damn things once we fill up the bucket. Thats after the DOD wipe too.

      Did I mention all laptop drives there are encrypted as well? Even if you could recover from a DOD wipe, you got an encrypted drive.

      It REALLY irks me. This just shows they have no overall security policy and let everyone do what they want. I am just glad the IRS has precautions.

  27. SInce When by cfkboyz · · Score: 2, Interesting

    I just got out of the Military and was in there for 6 years. Not one time did we ever wipe a hard drive, not because we did not care nor to lazy. We never sold the hard drives or gave them away. We either reused the drive or we smashed it and then recycled it. The Army is so paranoid that we even had to take RAM out of old computers that processed classified information just because it MIGHT have information left...

  28. Perhaps we should find new ways to motivate them by AnalPerfume · · Score: 2, Insightful

    Every time a piece of hardware which wasn't properly cleaned to the recommended levels, the individual responsible for letting it leave the premises should be held accountable....personally. How about sharing state secrets with the enemy? You can't know who it was destined for so there's every possibility it will go overseas. To my knowledge this carries a harsh sentence, but we can allow a prison sentence if they co-operate with the authorities and ensure the command level personnel are also charged.

    My guess is that most of this stuff happens through employee laziness, and contractor unaccountability. If you have lobbyists lairing in government to ensure that you keep the contracts no matter what and are able to hide anything under the "national security" red herring then why bother enforcing rules like wiping stuff properly? The idea of being held PERSONALLY responsible, with potential jail time will make people stop and think, specially if the command level have no loophole to blame their underlings for anything the press find out about.

  29. Contractor drive, not military by gatkinso · · Score: 1

    For all anyone knows it could have been stolen.

    --
    I am very small, utmostly microscopic.
    1. Re:Contractor drive, not military by coolsnowmen · · Score: 1

      I'm almost positive they are. Any security clearance room I've worked in, you can't take anything out of the room, let alone selling them on ebay.

      So I definitely think someone stole these for the cash, because defense contractors who work on classified projects don't sell hard drives on ebay (wiped or otherwise).

  30. wipe? destroy! by anonieuweling · · Score: 1

    Why wipe a disk?
    Media is cheap nowadays. Just destroy the disk.

    1. Re:wipe? destroy! by butlerm · · Score: 1

      I take a hammer to all my old drives...who wants a five year old drive anyways?

  31. Re:Uhh by ShooterNeo · · Score: 1

    100 * 40 gigs = 4 terrabytes. Or 4 $70 drives off of newegg.com, shipped to you brand new. With warranty. Who is dumb enough to pay anything for a crummy worn 40 gig drive? I shudder to think of the power draw of 100 drives grinding away.

  32. Mandatory by lufo · · Score: 1

    Wiping hard drives is no rocket science. It's HARDER than rocket science, indeed.

  33. Great Quote by clickclickdrone · · Score: 1

    One of the researchers, Professor Andrew Blyth said: "It's not rocket science..."

    --
    I want a list of atrocities done in your name - Recoil
  34. Induction Cooker by Sponge+Bath · · Score: 1

    Has anyone here ever used an induction cooker to wipe/destroy a hard drive?
    It seems that should be effective and entertaining.

  35. Re:Uhh by iccaros · · Score: 1

    for my Alesis HD24 http://www.alesis.com/hd24 old IDE drives is what this multi-track recorder users.. a 500 or even a 100 gig drive is a waste in the machine as you are limited in number of songs and audio tracks. Plus I have had issues with the machines undo features and modern drives. and sadly the newest version still expects the same old IDE drives.. which are hard enough to find. now to hard drives containing classified information.. agency's are only allowed to reuse drives on systems of the same classification or higher.. so if the data was on a secret system, once wiped can only be used on other Secret or higher systems. other wise must be destroyed. a lot of this supposed classified information is sensitive but unclass. which is not a classification but a handling instruction. The unclass part is a classification, and the lowest protection level, so things slip, solders send computers to DRMO with out following procedure as its only unclass, but they forget the handling as procedure as SBU, and news stories like this get out. also most of this looks like corporate design information or even some engineers stored information on projects he is working on and all may be SBU or even fouo, but most companies do not have a requirement to wipe drives before reselling them or returning them from a lease, and if he did work on his home computer all bets are off.

  36. Disks full of porn "sold to military" by David+Gerard · · Score: 1

    [probably to post tomorrow]

    Gigabytes and gigabytes of pornography and highly sensitive login details for gentleman's art sites were bought by a US military missile air defence base second-hand on eBay.

    The artistic pamphlets were found on a hard disk for the SPLORT (Super-Powered Less Obviously Retronymed Thing) ground to air missile defence system, used to shoot down Scum missiles in Iraq.

    Dr Andy Jones, a researcher at the base, said "This is the fourth time we have carried out this research and it is clear that records left on hard disks are the twenty-first century equivalent of random pornographic magazines found in bushes and parks by masturbation-crazed eleven year old boys. PHWOAR, LOOK AT THE TITS ON THAT ONE! I'm sorry, I'm just reviewing a birdwatching site. Fabulous display of Cyanistes caeruleus.

    "Of significant concern is the number of large organisations that are still not disposing of confidential information in a secure manner. Thank fuck."

    The disk also contained login details, credit card numbers and 18 USC 2257 information on ... "prospective military contractors," said Dr Jones. "Really. Prospective contractors. We're getting in touch right away."

    --
    http://rocknerd.co.uk
  37. These assertions clearly false by Timwit · · Score: 1

    A hard drive contained records from human resources *and* classified THAAD information? No way that's true. Classified information would be on its own network, and there would never be any reason to copy it to HR. Even if a contractor neglected to destroy or wipe a disk, only one type of information would be found on it, and not both.

    1. Re:These assertions clearly false by Culture20 · · Score: 1

      Could be a spy's drive.

  38. This doesn't make sense... by LoneAdmin · · Score: 2, Informative

    I worked for a government contractor at Tinker AFB in Oklahoma back in 2005-2006. I was on a contract doing server/desktop support for a wing on the base. Whenever we had a failed drive in a desktop, laptop or server there were certain protocols that we had to follow to make sure the data was compromised. We had to remove the drive and then take it apart completely. Once it was dismantled we had to scratch the platters to make sure they couldn't be reassembled in a different drive. I was also in on a server upgrade and they were going to sell the old server in a surplus auction. We were told to run a wipe of the drives and then REMOVE THEM because DOD regulations stated that the drives couldn't be sold at all. Then we had to destroy the drives in the same way I described above. Obviously this situation is someone not doing their job or just taking drives to make money.

    1. Re:This doesn't make sense... by clickclickdrone · · Score: 1

      >there were certain protocols that we had to follow to make sure the data was compromised
      There's your leak right there!

      --
      I want a list of atrocities done in your name - Recoil
  39. Re:For Highly Classified Data, it's more than a wi by jandoedel · · Score: 5, Funny

    ?? why would sandblasting an intern help in wiping the disk?

  40. Erase and 0 7 times by olddotter · · Score: 1

    Last time I read the military specs for harddrive disposal, moderately sensitive data disks should be deleted and zero'ed 7 times. (That options is on the Mac Disk Utility, BTW.)

  41. What a joke by TheLink · · Score: 1

    That challenge is a joke.

    1) If I could recover data from a zeroed drive, I'd charge a lot more than USD500 to do it. Why? Because there will be people who would pay.
    2) I'd charge a LOT more to show you how to do it with NDA etc.
    3) I'd charge even more to publicly disclose to everyone how to do it.

    Secondly this from the website is even funnier: "Yes, if your company is an established, professional data recovery company (see below). Send a self-addressed, postage-paid box with packaging material to the address listed below and we will mail the drive to you."

    Go look at Pwn2Own as an example of a competition that gets some serious entrants. The last I checked, USD10000 plus a Macbook is worth more than USD500.

    I'd say hacking OSX is easier than recovering zeroed drive - especially since involves using far more expensive hardware.

    --
  42. Re:Uhh by bleh-of-the-huns · · Score: 1

    Same reason you can still buy new technology 40g drives... because 100 striped 40 gig drives will absolutely destroy 4 1tb drives in performance and redundancy....

    Atleast when it comes to SAN infrastructure..

    --
    I came, I conquered, I coredumped
  43. DBAN! by LanMan04 · · Score: 1

    DBAN to the rescue!

    http://www.dban.org/

    --
    With the first link, the chain is forged.
  44. Truely poor standards. by TheMightyFuzzball · · Score: 1

    When last I checked the military's policy on wiping hard drives was to wipe it, write 1s and 0s and then cut the drive in half and send each part to separate locations to be destroyed. Maybe they wanted to make a little money from selling them on Ebay instead of just destroying them. See what this economy is doing to people!

  45. From the cash cow department by dbIII · · Score: 1

    I doubt they were illegally sold - it's more likely to be a breach of procedure due to incompetance considering where it was from and what was on it. Also does it really matter in this case? Where is the real SCUD missile that the system managed to shoot down? That's right - there wasn't one and there has been press about that. Leaked plans for Starwars snakeoil are unlikely to do much damage but it's now a good excuse to get rid of projects that show incompetance at all levels. Lysenkoism drove funding for a lot of things that just sounded cool and never had to actually work, and once a company is aware of that it just becomes a cash cow tended by those without the ability to succeed elsewhere in the company or those that lose hope when they become aware that they are working on a sham project.

  46. Why risk it? by Godskitchen · · Score: 1

    The data is much more valuable than the $20 or $30 bucks they can recoup from selling the drives on Ebay; I don't know why a government agency would risk doing this.

  47. Re:For Highly Classified Data, it's more than a wi by silver007 · · Score: 2, Funny

    link please

  48. Re:Uhh by Barny · · Score: 1

    striped drives ... redundancy

    Oh, you did not just say that striped drives are redundant did you? :)

    --
    ...
    /me sighs
  49. No more disks in workstations by jhfry · · Score: 1

    With PXE network boot, remote desktop, virtualization ect. There is little reason that any information higher than "sensitive" would ever need to be stored on a disk that is outside a secure data center. I would like to see the governemnt do away with desktop computers completely in favor of thin clients or something similar.

    --
    Sometimes the best solution is to stop wasting time looking for an easy solution.
  50. Re:No such thing as a "DOD standard" for classifie by CannedTurkey · · Score: 1

    Where I work we purchased a plasma cutter for the sole purpose of destroying platters.

    --
    Ingredients: Turkey, Mechanically Separated Turkey, Water, Salt, Flavour.
  51. Unclean Military Hard Drives? by clone53421 · · Score: 1

    Doubleplus ungood!

    --
    Alexander Peter Kristopeit bought his basement from his mommy for one dollar.
  52. DoD policy by JTsyo · · Score: 1

    Scary that they did not wipe it to Department of Defense standards which I believe is wiping the whole disk and then writing 1010 all over it.
    You would think the policy is to destroy them not sell them on e-bay,

    1. Re:DoD policy by Bobfrankly1 · · Score: 1

      You would think the policy is to destroy them not sell them on e-bay,

      Yeah, but the government is throwing money at GM and Chrysler...they gotta raise that money somehow, oh wait, they just print it, my bad...

  53. Consider the source by soniCron88 · · Score: 1

    Everyone's so caught up debating the possibilities of recovering data from discarded hard drives that nobody seemed to notice this "article" is from the UK's finest tabloid, Daily Mail.

    Wake me when we have a legitimate source.

    1. Re:Consider the source by Bobfrankly1 · · Score: 1

      Point made. When the sidebar is entitled "FEMAIL TODAY" and features Lindsay Lohan, you have to question their journalistic ability.

    2. Re:Consider the source by JustNiz · · Score: 1

      You have no exceuse. Everyone knows that for professional journalism you should read The Sun.

  54. Hmmm... by Bobfrankly1 · · Score: 1

    Unclean Military Hard Drives Sold On eBay

    *Starts yelling from the distance* UNCLEAN!!!! UNCLEAN!!!

    Seriously though, somehow I picture this ending up on a Red vs Blue joke...bow chika wow wow!

  55. Re:Uhh by jtev · · Score: 1

    100*40 gigs=100 drives each of which is capable of holding the operating system for a workstation. Also since he mentioned CD drives, maybe he is selling the entire used system. Also depending on drive technology, you may be able to work them into a RAID array, or the buyer might just want to slag them anyway for the component material.

    --
    That which is done from love exists beyond good and evil
  56. GET A MAGNET! by TheLeopardsAreComing · · Score: 1

    It's amazing to me in this day and age that highly sensitive information is leaked via old hard drives. My understanding is this: a.) you have highly sensitive information on a hard drive b.) you thoroughly destroy the disk( magneto, powerful magnet, baseball bat) c.) you check to see if the information was destroyed d.) ? e.) PROFITS If this is not done, some sneaky cheeser is going to find a way to get your info. -- this does not include intentional leaking of info

  57. Does it matter by Jeez01 · · Score: 1

    Considering IT work is more or less outsourced to Bangalore even among Pentagon contractors, i doubt companies like Wipro, TCS do much in terms of keeping their client's work secret.

  58. Re:Plasma Furnace by cayenne8 · · Score: 1
    "These drives primarily come from defense contractors which are the biggest source of information leaks. Hell, H1B's just walked off the job with it."

    H1B's can't work on classified systems. If you're not a US citizen, you aren't even considered for those positions.

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  59. Good Indicator by Jaysyn · · Score: 1

    Just another indicator that any screams of "terrorists!" coming from our military-industrial complex are nothing more than a dog & pony show.

    --
    There is a war going on for your mind.
  60. EPIC FAIL by kheldan · · Score: 1

    Why the hell is the military selling used hard drives in the first place? If there is ANY chance of there being ANY sensitive data on a drive, even in deleted files, they should physically destroy the drive or at least completely degauss it to the point of it being scrap. Even the private sector knows better that this! When I worked as a contractor for Intel, they would run ALL used drives through a conveyor belt driven degaussing machine that would render the drives unusable scrap because they did NOT want any I.P. recovered by third parties. Doesn't our own military know better than this?

    --
    Are YOU using the TOOL, or is the TOOL using YOU? Think about it!
  61. Re:Obligatory oxymoron -- See parent by oDDmON+oUT · · Score: 1

    Truth hurts doesn't it?

    --
    Some days it's just not worth
    chewing through my restraints.
  62. Re:For Highly Classified Data, it's more than a wi by tippe · · Score: 2, Interesting

    I prefer the muriatic acid formatting approach myself. You know, just in case there are any confidential bits or bytes left in the drive's PCB traces or ICs, or sticking to the side walls of the platter enclosure. You can never be too careful....

  63. Poor CmdrTaco by samjam · · Score: 1

    Hats off to CmdrTaco who was arrested at home a few moments ago as a terrorists dangerous to national security, through publishing information likely to give comfort to and support the cause of terrorists, and disseminating information likely to aid terrorists and other enemies of the state.

  64. That cuts both ways by kaladorn · · Score: 2, Interesting

    It is possible that the people who want to sell you a product don't want to announce the capability they wish to sell you is not necessary.

    Besides, if the government is after you, they have such a variety of options to figure out what goes on (pin cameras, laser mics, various other forms of mics, analysis programs that can guess what you are typing, installation of keyloggers, and just simple acquisition with legal means like a warrant) that worrying about whether they may, beyond all known capabilities of industry, be able to recover data off your drive is absolutely hilarious.

    If you're that paranoid, just never, ever do or say anything the government will pay attention to. In the maxima, this means never doing or saying anything. Ever.

    --
    -- Mal: "Well they tell you: never hit a man with a closed fist. But it is, on occasion, hilarious."
  65. THAAD was not used in Iraq by Thagg · · Score: 1

    The THAAD system has never been deployed. It's always been a sore point for me -- typical headlines in Aviation Week are "THAAD fails tests for the third time in a row", or "THAAD deployment delayed yet again", or "THAAD does not live up to promises."

    Kinda pisses me off.

    Thad [just one A!] Beier

    --
    I love Mondays. On a Monday, anything is possible.
  66. mod parent up! by someone1234 · · Score: 1

    This was the first thing that came in my mind too!
    They blame P2P when they put sensitive data on computers accessible on the net, or just sell it outright.
    This latter could happen even if the internet wouldn't exist at all.

    --
    Patents Drive Free Software as Hurricanes Drive Construction Industry
  67. Even easier: BIOS wipe utilities by davidwr · · Score: 1

    Some major vendors include "wipe hard drive" as one of the functions built into the BIOS.

    It would be way cool if drives had a jumpers that if set on drive-power-on, would cause the drive to not connect to the bus but rather start writing random data to wipe the drive. Add a status LED that blinked a pattern based on the pass number in progress: "flash pause" for "in the middle of pass 1," "flash flash pause" for "in the middle of pass 2," etc., with a special blink sequence if any pass failed to write to all sectors including previously-marked-bad sectors. Store the results in the drive's nonvolitile RAM for read-back later and you have the means to certify that the drive was wiped.

    Since on modern drives all but the most sensitive data is safe after a 1-pass wipe, this would make recycling computers much easier.

    --
    Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
  68. IF they wipe 'em and write 1010 all over them... by Mucky+Pup · · Score: 1

    They'd be easy to spot: just look for shiny hard drives (wiped) with the numbers 1010 written (hopefully using a sharpie) all over it!

  69. All that data on one hard drive? by novalis112 · · Score: 1

    Am I the only one that finds it peculiar that all that wildly different data was found on one hard drive? Security policies, social security numbers, facility blueprints, ...etc.? I mean, of course it's *possible*, but it seems a bit odd to me that such disparate kinds of data would all be on one server, let alone one hard drive.

  70. Use shred on the disk device, like dd. by emil · · Score: 1

    This is addressed in the shred man page:

    "The default is not to remove the (original) files because it is common to operate on device files like /dev/hda, and those files usually should not be removed."

    If you shred the disk device, rather than individual partitions or filesystem entries on the disk device, you will get the swap areas and other relevant metadata. In the above example, /dev/hda1 may be your swap, and /dev/hda2 may be your filesystem. If you shred /dev/hda, both will be overwritten. If you shred only /dev/hda2, the swap will be preserved (which is not what you want). Under no account would you mount /dev/hda2 and shred files within it and expect secure erasure.

    The shred manpage has specific warnings about journaling filesystems and other cases where your erasure will not be as secure as you would like.

  71. Re:Plasma Furnace by muridae · · Score: 1

    You don't necessarily need to be working on the classified system to have access to the computer. Someone has to clean up the computer labs.

  72. The Hard Drive That Never Was by ses114 · · Score: 1

    Hang on....let me adjust my tin foil hat.....ok..... This hard drive might have been deliberately put on ebay with the hope it would fall into the "wrong" hands.

  73. MCI standards by HTH+NE1 · · Score: 1

    Scary that they did not wipe it to Department of Defense standards, which I believe is wiping the whole disk and then writing 1010 all over it.

    I've been using MCI's standard: writing 1010220 all over it, then taking the sale of the drive as a tax deduction for advertising expenses.

    --
    Oh, say does that Star-Spangled Banner entwine / The myrtle of Venus with Bacchus's vine?
  74. A novel invention for that in the Netherlands... by thrill12 · · Score: 1

    ...is the hard drive shredder, a machine that simply shreds complete hard drives to pieces. Apparently some large defense institutions showed interest at the time this invention was presented at "Dragon's Den" (a TV-show where people can request money from private investors).

    --
    Slashdot: stuff for news, nerds that matter, matter for news, stuff that nerd
  75. Re:Plasma Furnace by cayenne8 · · Score: 1
    "You don't necessarily need to be working on the classified system to have access to the computer. Someone has to clean up the computer labs."

    They don't let just anybody into any area that contains either classified materials, or classified machines. You have to be cleared to even enter those areas much less access information. An unclassified person would not even be able to enter the room, much less touch anything in it. You're not going to be classified if you are not a US citizen...at least not normally.

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  76. DBAN by GodfatherofSoul · · Score: 1

    Mindlessly easy to use, you can burn it onto floppies or CDs as a boot image, and effective.

    --
    I swear to God...I swear to God! That is NOT how you treat your human!
  77. Exactlly what is the news here? by lorg · · Score: 1

    They do this "experiment" several times a year and they all come to the same conclusion; OHH WE FOUND THE SECRET DATA!

    So is it really even news anymore? Shouldn't the new really be "We learned nothing since last time!".

  78. Re:Uhh by Zakabog · · Score: 1

    I sold a 386 just a few years ago for $175.

    How did I get so much for a computer you could find in a dumpster? Easy, the customers 286 was fried in a lightning storm. He used the thing with some very very old DOS based software that ran his embroidery machine. I happened to have a 386 lying around that ran everything just fine. Even installed Windows 3.1 on the thing.

    Sometimes a 40 gig drive is a lot more valuable than a 1TB drive. Especially when it's the difference in replacing one old broken component vs buying all new hardware/software that you're not even sure will work with what you've got.

  79. room full of them by slashdime · · Score: 1

    A friend of mine who worked IT for a firm that provided processing for insurance companies told me that he constantly took hard drives home and had ready access to lots more. Why? Because there was a storeroom, completely filled with hard drives ranging back to 10gig ones. The company has a policy that formatting the hard drives aren't enough, they have to be put through a machine where the entire hard drive is basically ripped apart and turned into screw sized scrap metal. The cost of this is roughly $20 per hard drive (iirc). At some point, it became cheaper just to warehouse them then actually destroy them. New hard drives that were to be destroyed then didn't have such a priority to be wiped. "Oh, just leave it there for now, we'll throw it in the room later." If it went missing, no one really cared.

  80. harddrive obviously stolen by societyofrobots · · Score: 1

    The DoD does not sell harddrives on EBay, however gov't contractors that steal harddrives do (fact).

    What I've been told is that all old harddrives are sent to specialists who wipe all data, then incinerate the drive.

    I occasionally work for the Navy as a contractor.

  81. Hamma Time by PalmKiller · · Score: 1

    I whack my old drives several good licks with a heavy hard-faced ball-peen hammer, then dispose of them. Much more secure than any DoD standard way of wiping the drive, especially if you peen the disk platters into a nice curved and sometimes cracked surface.

  82. This needs to be a TV show by Twyst3d · · Score: 1

    At least a mini series. Kinda like Mythbusters except they destroy hard drives each week a different way and then see what kind of information can be salvaged off them by real experts.

    --
    And this has been another installament of Captain Obvious! /whoosh
  83. DoD 5220.22-M; other DoD standards by DragonHawk · · Score: 1

    "Taken from DoD 5220.22-M Wipe Standard:"

    GAH!! Not this again. DoD 5220.22-M, full title "National Industrial Security Program Operating Manual", more commonly called NISPOM, is not and never was a wipe standard. It is a 150 page document that covers all aspects of the National Industrial Security Program (NISP). NISP is the jurisdiction for most commercial contractors doing classified work. Sanitization is about two paragraphs in this document. In every edition published within the past 15 years or so, I've never seen seen it get into specifics about methods -- it just says the CSA (Cognizant Security Authority) gets to set them. I've seen one document of uncertain origin, dated 1995, which did provide a list of methods, but there were several options depending on the nature of the medium and the data.

    You can download the NISPOM from the official source here: https://www.dss.mil/GW/ShowBinary/DSS/isp/fac_clear/download_nispom.html Sanitization is Section 8-301(b) on page 8-3-1 (ordinal page 75).

    Most NISP jurisdictions have to follow the DSS Clearing and Sanitization Matrix. As of ISL 2007-01 (Oct 2007), the C&SM does not permit overwriting for destruction. Only degaussing or physical destruction is acceptable.

    Further, the degaussing standards require one to remove and degauss each individual platter. As someone else noted, degaussing a modern hard drive erases the factory formatting and renders it unusable.

    For physical destruction, it's not enough to drill a hole through the platter, either. Every bit (pardon the pun) of surface area must be obliterated. Grinding, sandblasting, incineration, liquidation, vaporization, pulverization, etc.

    --

    dragonhawk@iname.microsoft.com
    I do not like Microsoft. Remove them from my email address.
  84. NIST 800-88 by DragonHawk · · Score: 1

    "These have been superceded by NIST Special Publication 800-88:"

    NIST does not have jurisdiction over DoD. NIST 800-88 doesn't supersede 5220.22-M. 5220.22-M is still in effect; the most current edition is 2006. (See my post here for where to get it.) It doesn't specify methods, though; as far as I can tell, it never did.

    Most DoD and NISP jurisdictions are under DSS authority; the DSS publishes their own Clearing and Sanitization Matrix for this sort of thing. I discuss that in that post, too.

    --

    dragonhawk@iname.microsoft.com
    I do not like Microsoft. Remove them from my email address.
  85. NSA degaussing by DragonHawk · · Score: 1

    "While you're having fun, note that there is a good chance that the degausser just fries the electronics (by inducing strong currents where they don't belong) but leaves the data on the platters intact"

    Any degausser being used to sanitize a hard disk which contained classified information must be purchased from the NSA's Evaluated Products List, and used in accordance with NSA standards. Those typically include removing the platters from the drive enclosure and degaussing them individually. I'm pretty sure it's more than just the electronics. Mission objectives aside, the NSA knows what they are doing.

    --

    dragonhawk@iname.microsoft.com
    I do not like Microsoft. Remove them from my email address.
  86. Damn Jarheads...:-) by rts008 · · Score: 1

    Man, you Marines...
    This should get added to the USMC mission planning. Have all branches/departments of the Fed. Gov't. turn over their HDD's to the USMC for destruction.
    Use it as a 'punishment detail' for minor infractions.

    Sounds like a perfect solution:
    HDD's need destroyed
    Marines needing punishment for that brawl in the bar
    Marines are Masters of Destruction

    Note:see 'subject', as I was 'smiling when I said that!'[former US Army dogface here]

    --
    Down With Slashdot BETA!!! I've been around the corner and seen the oliphant; you can only abuse me from your perspecti
  87. Tremble before the mighyty Vulcan, HDD!! by rts008 · · Score: 1

    I'll bet that results in some interesting 'pattern welded' trinkets!

    --
    Down With Slashdot BETA!!! I've been around the corner and seen the oliphant; you can only abuse me from your perspecti
    1. Re:Tremble before the mighyty Vulcan, HDD!! by BrokenHalo · · Score: 1

      I'll bet that results in some interesting 'pattern welded' trinkets!

      Unfortunately, the heterogeneous mixture of stuff in those things ends up as an amorphous mixture of very, very thin flakes. :-)

  88. Degaussing without disassembling drives by DragonHawk · · Score: 1

    "I don't think disassembling the drives is part of their procedure."

    I remembered that being permitted, provided certain requirements were met by the degaussing equipment. I just double-checked, the EPL and it seems there is more such equipment than I remembered. Perhaps things have improved since I last looked, or perhaps my memory was just faulty. I know we were only interested in the cheaper hand wands, which do require disassembly, so perhaps my memory magnified that part of the document.

    You can find the NSA Evaluated Products List online:

    http://www.nsa.gov/ia/_files/Government/MDG/NSA_CSS-EPL-9-12.PDF

    --

    dragonhawk@iname.microsoft.com
    I do not like Microsoft. Remove them from my email address.
  89. Waterboarding Time by Moe1975 · · Score: 1

    Good Lord, and to think that the unfortunate soul who ended up with the drive is probably being waterboarded already for his/her troubles, as I write this.

    Ok, back to work, this is too depressing.

    MOE

    --
    SARAVA!
  90. Re:Hint by noundi · · Score: 1

    I'd like to see you try. Hell I'd even pay to watch.

    --
    I am the lawn!
  91. Encryption by Neoro · · Score: 1

    Why don't they have the entire hard drive encrypted anyway so if one leaks through their deletion protocol, it isn't quite so bad?

  92. Standard Procedure by Demonantis · · Score: 1

    Aren't those drives supposed to be degaussed. I think the procedure the author is talking about is dated. The company that sold the drive is probably kicking themselves since the sale of that hard drive is probably not going to cover the penalties and lost contracts the military will punish them with.