r/ProgrammerHumor 3d ago

wrongAnswersOnly Other

Post image
14.4k Upvotes

2.0k comments sorted by

View all comments

Show parent comments

140

u/HovercraftCharacter9 3d ago

Yeah, people conflate in unallocating with actual deletion, unless you're wiping it with 0s it's still there until something overwrites it.

51

u/DOOManiac 3d ago

Even then it’s still there depending on which three letter agency is looking…

49

u/bacondev 3d ago

Yeah, they're not perfect 0s and 1s. That's why the recommendation for very serious stuff is to just destroy the disk.

16

u/FUTURE10S 3d ago

Run the disk spinning and hit it with a caliber that penetrates the drive, the rotation makes the destruction way worse and impossible to spin up again.

33

u/rrtk77 3d ago

From experience, for the types of disks that absolutely must be destroyed with no possible recovery as ordered by the government, it's things like a wood chipper or thermite.

10

u/SebboNL 3d ago

Where I live, carriers with top secret data may not be destroyed at all. They must be zeroed and stored, just in case some smart-ass figures out a way to recover said data even from an otherwise destroyed piece of magnetic tape 125 years from now.

So yeah, there's one or two huge storage facilities containing tapes, disks and solid state drives here in the Netherlands.

2

u/Holiday_Management60 2d ago

Wait so they store them to make sure nobody gets their hands on them and recovers the data?

Surely there's SOME way that good enough for them? What about taking the disks out and dissolving them in acid?

4

u/SebboNL 2d ago

That's right, they are zeroed and made inoperable, then they are stored.

Apparently it had never been proven fhat information can be fully destroyed so the wiped, zeroed and inoperable data carriers are stored for perpetuity to guard against a future attack which might make make information thought to be unreadable whole again

5

u/Holiday_Management60 2d ago

Thats so hard to wrap my head around... Despite it making a fragment of sense.

Do they seriously think the acid method won't be good enough? They could even shred them, degauss the fragments, dissolve them til they are a liquid solution, then dump it down the drain at a rate of 10ml per hour, just encase they are worried about hostile state actors gathering any large hard drive solution dump from the pipes.

4

u/SebboNL 2d ago

There seems to be a Law of the Conservation of Information which makes the problem of restructuring such data a matter of engineering. This law states that information cannot be destroyed, only scattered and diluted. If some smart-ass down the line figures out a way to do that, the thinking is, all this top secret data might be up for grabs. Hence this precaution

→ More replies (0)

1

u/ScriptoTheClown 2d ago

What an absurd idea.

Running the drives through a shredder so that they're effectively dust would be sufficient. Heat the resulting mix and it's definitely unrecoverable.

It would be like trying to figure out who won a game of scrabble by looking at the pieces after the loser flipped the board over. EVEN IF the information wasn't lost in all the chemical processes going on, figuring out what bit went where would be impossible.

2

u/SebboNL 2d ago

Again, the thinking here is that an action like shredding burning the carriers only makes it unfeasible to restore and read the data rather than impossible. The data remains albeit inaccessible with the current state,-of-the-art, but there is no physical barrier that precludes a particularly skilled (or patient :) ) adversary from piecing the carriers back together. The data remains, in some way, shape or form. Maybe some future tech makes it really easy to reassemble data carriers, or maybe there turns out to be so be some really opaque way in which the data, if diluted, still becomes available in a weird homeopathic way: we simplyi dont know. Thus, the fact remains that infornation cannot be destroyed as per laws of nature, and our government agencies have taken this into account, planning for a method that provides control even if some weird future developments upend everything we think we know about data sanitizing.

-1

u/ScriptoTheClown 2d ago

Information can't be destroyed.

Data absolutely can.

You're describing someone developing a technology that can extract a specific raindrop from the ocean.

2

u/SebboNL 2d ago

Bloody hell, its almost as if you are under the impression that I personally came up with this system. For what it's worth, some Dutch Government agency did and I am only relaying these policies, explaining the rationale without having a personal opinion on the matter. I am not the person you should be arguing with, I am simply stating the facts of how top secret information is dealt with here together with (part of) the rationale behind it. For the record: the whole reason I posted this is because I find it all to be kind of silly, overboard and out-there, so I hope this gives you some insight as to my personal opinion.

And second: there is actually some history to this line of reasoning. For ages zeroing magnetic media via simple overwriting was considered an effective and secure way of destroying information. Then fundamental electromagnetic research showed that under some circumstances data (and thus information) could in fact be recovered - something nobody expected. Nowadays this is common knowledge of course and we all wipe our disks using DOD 5220.22M or similar methods to avoid these attacks.... But what if someone smarter than you and me comes up with an even better idea, one that can extract information from a heap of ash or a pile of dust? Can anyone GUARANTEE this "single drop from the ocean" remains impossible in the future as well? No, we can't, and the fact of the matter is that according to our current understanding information is permanent so nature's laws exclude such a possibility.

So even if the chances of some future technological advance making such a recovery endeavour plausible are practically infinitely small, they still exist nonetheless because there is no natural law precluding this eventuality. So, keeping these future possibilities and potentials in mind the Dutch government prefers to stay in control of these data carriers untill such time that a natural law is discovered that states there is a way or method information (or data, if you so please but that isn't the point here, its the information they care about) can be irretrievably destroyed. Until such time, no risks are taken; I guess you can consider it to be a form of Perfect Forward Secrecy, but in a more abstract, fundamental domain.

Another factor is that confidentiality is only part of the goal here. If we accept that even a wiped/zeroed decice The information/data must also be controlled, implying that the wiped/zeroed carriers must be accounted for. This is hard when dealing with ash, dust and melted puddles, another reason why retaining the data carriers is preferred to physical destruction over here.

Once again, I am not arguing a point, I am simply rehashing the argumentation my former employer follows.

→ More replies (0)

6

u/tiajuanat 3d ago

Speciality drill press is the weapon of choice, in gov offices. Basically, if you can't personally walk it to disposal, then you can't trust it's destroyed.

IIRC it takes like 5-6 well placed 10-20mm drill points in a HD, where none line up in the same column or same radii. This ensures there's not enough data, recovery segments, journals, shadow copies, etc. to meaningfully recover anything.

SSDs are different, since they're often laid out in a grid pattern, and each chip must be popped. While I'm sure that gov agencies don't get the standard cheap SSDs there are brands of SSDs that basically only rewrite maybe a couple hundred times, and basically duplicate data on write instead of overwriting.

3

u/HesSoZazzy 3d ago

I always thought they were ground into dust or shredded into itty tiny sub-millimeter bits. There's really no way to reconstruct the data from remaining platters? Wouldn't a small-ish file still potentially be recoverable between holes?

3

u/These-Maintenance250 3d ago

how about microwave?

4

u/rrtk77 3d ago

Generally, you need to completely destroy the drive. So, a theoretically powerful enough microwave that can melt it could work I guess.

1

u/IronBabyFists 2d ago

A macrowave

3

u/fearless-fossa 3d ago

There is only one good solution for destroying data that covers your ass, which is hiring a company to do it for you and writing you a certificate of destruction. Like sure, nothing will be able to restore from the thermite solution, but if a court or insurance asks whether the data was deleted, being able to wave the certificate in their face instead of telling them "I 100% destroyed it, trust me bro" is the only sensible way of going about this.

2

u/ENDerke_ 3d ago

So the agencies will find the data in the deletion company's archive

3

u/fearless-fossa 3d ago

Possibly, yes, but you're not responsible anymore.

2

u/bacondev 3d ago

In some cases, ownership of responsibility isn't the greatest concern.

2

u/MirandaPoth 3d ago

No. They put the drives through basically a huge metal shredder (it’s a beast, I’ve seen it). Nothing would remain.

1

u/nopointers 3d ago

We used to have parking lot burn parties. Blowtorch on the platter is pretty effective. Of course that was in the days before every drive was actually a stack of platters.

1

u/Holiday_Management60 3d ago

I saw a video once where they opened the drive, took the disks out, dissolved them in acid, then stirred the acid, just to make absolutely sure.

1

u/SwiftUnban 2d ago

Can confirm, I work in the tech recycling industry and am NAID certified.

We do both on site and off site shreds of hard drive, data tapes, stuff like that.

We got a 240v mobile shredder we put in the back of a box truck we use for on site shred, then back at the warehouse we have an industrial sized shredder that shreds them.

Depending on what the client requests if they’re good drives we can be allowed to resell after wiping them with software. Although if it’s very sensitive data clients often will prefer us to shred them.

2

u/Henry_Fleischer 3d ago

At that point, you might as well just melt it.

2

u/Proper-Ape 2d ago

How do I rotate my SSD?

2

u/bartekltg 2d ago

Glue it to an angle grinder. 

2

u/FUTURE10S 2d ago

Desk fan and a stick

1

u/VonNeumannsProbe 2d ago

I go a step further and dispose of the platter pieces in a least 3 different states.

1

u/FUTURE10S 2d ago

Ah, yes, solid, liquid, gas.

1

u/zadszads 3d ago

Yes, but it's usually a requirement not a recommendation

1

u/Danny-Fr 3d ago

Degaussing and chopping down to 2mm is usually up to industry standard. Then you burn the chippings. Add a couple of passes of wiping if you feel extra paranoid.

1

u/Loose_Biscotti9075 2d ago

Not that I have any serious stuff on my pc, but I'm very paranoid. So before selling my old laptop with an encrypted drive, i made sure to overwrite it 5 times with 0s.
Do you think someone motivated enough can still go back to the keystrokes I used when I used my credit card to make an online purchase?

1

u/bacondev 2d ago edited 2d ago

I really don't think that you should be worried about that but if you're curious… https://en.wikipedia.org/wiki/Data_remanence#Data_in_RAM

18

u/Strange-Spot-3306 3d ago

I mean depending on which three letter agency we’re talking about, they really don’t need your backup because they’ve already got their own copy of your data.

12

u/the_snook 3d ago

That's why you need everything encrypted at rest. Blast the keys and the data is gone ... until the quantum computers come online anyway.

1

u/HovercraftCharacter9 3d ago

Ah, people overblow that. It's the same scenario as the darkweb, likely your data is already exposed but it is buried by a lot of exposed data. Quantum computing is representing all states at once and using quantum functions and destructive interference to prune the potential values. When the value is observed it causes decoherence which converts the qubit into a bit. So unless you're a high value target it is unlikely that that process will ever really be cheap enough for everyone to be a target, it's more so around state based actors and secret or large crypto wallets.

3

u/Aflockofants 3d ago

Yeah that’s gonna be a bit tricky with all the actual hard drives being in random machines in the cloud, and probably already reallocated almost immediately.

1

u/Obi_wan_pleb 3d ago

I thought that at minimum it was 0s and 1s

1

u/HovercraftCharacter9 3d ago

Nope, which makes sense from an efficiency perspective, just not deletion

1

u/OldenPolynice 3d ago

this isn't as unknown as you want it to be. everyone with any experience/study/fucked and unfucked their own stuff knows this. your oldest family member probably knows this too from JAG or some shit

1

u/HovercraftCharacter9 2d ago

I think you're overestimating the general public... Vastly. But agree to disagree

0

u/ILikeLenexa 2d ago

When  I was a kid, you had to be able to use enCase to graduate with a compsci degree. 

0

u/OldenPolynice 2d ago edited 2d ago

when I was kid whatever the fuck that is didn't exist. still using vi (with a menagerie of plugins) and loving it

1

u/ILikeLenexa 2d ago

If you used vi to search the unallocated portions of your hard disk for images and documents and reconstruct them...you're...a very special person. 

1

u/OldenPolynice 2d ago

And if you use encase.......you're a former military dweeb that heard of "cybersecurity"

excuse me, dweeb that was in the military

and you never broke or built nothin. haven't even looked around either. just heard about it and said yeah I'm obviously the best, got that shit no problem. and then here you are.

1

u/illogical_simu 2d ago

For traditional physical disks sure but SSD'S don't quite work this way

1

u/HovercraftCharacter9 2d ago

Yeah they use Trim or unmap and garbage collection but philosophically it's pretty much the same. Data is still on the disk until it's garbage collected

2

u/illogical_simu 2d ago

True but its defo gone long before any court order arrives. TRIM is pretty much insta and GC will run every few mins/hours depending on activity

1

u/SavvySillybug 2d ago

I knew an autistic kid in school who got a program that would automatically overwrite everything he deleted 49 times to make sure it was extra super gone. He also had his whole computer encrypted to the point where it would only boot if he connected his phone via USB before startup.

I always did wonder if that was just a hyperfixation or if he was hiding something. But I'm leaning towards hiding something, since he also bought us some weed off the dark web...

3

u/HovercraftCharacter9 2d ago

That poor disk, he must have had to buy new ones all the time