NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 CIO BlackBerry News and Tips
 CIO Research and Analysis
 CIO Microsoft
 CIO Insider
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 


Tue, Feb 19, 2008 16:36 EST

Is your hard drive data really gone?

Topic: Enterprise Management

Current Rating: 5 Comments: 10

As the most widely used storage medium today, it is no wonder hard drives represent one of the biggest security challenges. Yet despite stricter government data compliance and security mandates, more needs to be done to safeguard end-of-life data. Ensuring the data on a hard drive is completely eliminated before it is disposed, redeployed or donated should be a top priority for every organization. A clear understanding of these methods and their limitations is essential to ensuring the safety of end-of-life data. To help you better understand your options, I’ve summarized them below for your consideration.

Secure Erase Technology
Caution: Many vendors who sell commercial software products use the term “secure erase” incorrectly. They use the term to describe an “erasure that is secure”. However it is important to distinguish this misused marketing term with Secure Erase technology.

In the late 90’s, the hard drive manufacturers called for a global summit to discuss the rapidly growing challenge of properly sanitizing hard drives. The challenge was to develop a means for certifiably sanitizing hard drives beyond forensic reconstruction while retaining the ability to reuse the hard drive. The hard drive industry collaborated with Center for Magnetic Recording Research (CMRR), under the direction of the US National Security Agency (NSA), to meet this challenge. They developed a sanitization standard called Secure Erase. The Secure Erase standard has been implemented by all hard drive manufacturers since 2002. It is embedded in the firmware of all ATA/IDE and SATA hard drives and is recommended by the National Institute for Standards and Technology (NIST SP 800-88) as a “purge technology”, a step above software overwriting which is characterized as a “clear technology”.

Since it is located in the firmware of the drive, the sanitization procedure is up to 18x faster than commercial software overwrite routines, which have to communicate to the drive through the OS and BIOS. In addition, it is able to purge all sectors of the hard drive as it has direct access to all bad sector tables stored internally on the drive.

Commercial Overwrite Routines
Commercial overwriting tools are designed to write random bits of data on all user accessible sectors of a drive. The software is loaded onto a machine or server to execute the overwrite procedure. Most overwriting tools execute multiple passes for added security. However, even multiple passes does not guarantee complete sanitization. Some overwriting tools are not able to access bad sectors of a hard drive. This leaves recoverable data on these sectors. In addition, software can take an enormous amount of time, usually lacks an automated logging capability for audit purposes and is not a physically secure process. Both public and private sectors have acknowledged the ineffectiveness of software overwriting. One example of this occurred in June of 2007 when the US Defense Security Service disapproved of this methodology as a method for destroying data.

Degaussing Machines
Degaussers produce a strong magnetic field in order to destroy the magnetically recorded data on the hard drive. Degassers have the unfortunate consequence of destroying the read/write head of the hard drive, rendering the hard drive unusable. The original intent of degaussers was for use with non-rigid disks and magnetic tape media. As the sophistication and platter density in most modern hard drives continues to increase so to does the inadequacy of this methodology. Aside from dangers they pose to other nearby electronic equipment there is no way to ensure that the hard drive platter does not contain any

You do not have flash or javascript support.
Average (2 votes)
5
 
 
Wed, Feb 20, 2008 11:44 EST
Anonymous user
Posted by: Anonymous
Rating: 90

The practical matter here is:

How much effort and what kind of a budget would it take to recover the data on the drive?

Short of a federal level budget (CIA, NSA, etc.) for recovery, there are a number of simple techniques that are rather effective in destroying data

Regarding permanent destruction:

For simple old drives which are too small for practical use in new machines, disassembly and removing the platters is quite sufficient. You can cut them up if needed, or bend them into fun shapes for wind chimes. Give them to the kids to play with in the sand box. (Sand does wonders for a platter surface). Or take them on a cruise, and throw them into the sea between islands, far out from land.

Another simple destructive method is to drill a couple of large holes through the circuit board and the main platters, then let the old drives soak in a bucket of salt water for a month, long enough to ensure a good buildup of corrosion.

These methods are quite effective for anything outside of a governmental budget for recovery purposes.

Erasing with the intent to reuse is somewhat more problematic.

But again, overwriting with random sequences ones or zeroes is quite sufficient before reformatting for use in the new setup.

And drives are inexpensive, so that often it is worth simple replacing the drive and destroying the old

 
Thu, Feb 21, 2008 17:16 EST
Anonymous user
Posted by: Anonymous
Rating: 90

Federal requirements such as HIPAA, Sarbanes-Oxley, etc. require fully documented procedures for disposing of data and a complete chain of custody across a variety of industries; this isn’t limited to just government agencies.

Perhaps it is this simplistic and indifferent attitude that has led to a record year of data security breaches.

 
Mon, Feb 25, 2008 11:25 EST
Anonymous user
Posted by: Anonymous
Rating: 70

I find it quite absurd that you find the methods you listed as satisfactory for non-governmental organizations. The cost to a company who loses sensitive information is astronomical: notifications to customers (letters, email, web and media), legal defense services, criminal investigations, legal audit and accounting fees, call center expenses, public and investor relations and internal investigations just to name a few. In light of this, you can bet that a company is going to spend whatever is necessary to prevent the expenses associated with the above as well the damage that their reputation will suffer from a breach.

Recently, the Poneman Institute released an annual study on the cost of a data breach. They estimated the total cost to be $197 per record lost. Imagine how many millions of records would be on a single hard drive. I don’t think they would be making wind chimes with the platters.

 
Tue, Feb 26, 2008 14:38 EST
Anonymous user
Posted by: Anonymous
Rating: 10

PLEASE!!!!

Roger Detzler (CTO) has never believed a thing that he is saying... and as a matter of fact... laughed at the concept of a 'digital shredder" as not having a market... "it's too expensive for the common man" and EDT has yet to sell any quantity of product into the open market, since 2005.

EDT's founders are all non technical people who have never used a computer... never mind run a high tech company.

EDT's founders have screwed their dealer network and it will come back to haunt them. They screwed their original OEM... EDT has no in-house development/programming/support staff...A shell organization.

Buyer's beware... EDT is living off of angel investors seed capital and free rent... The senior management is making all of the wrong moves...the BOARD NEEDS TO WAKE UP!

 
Wed, Feb 27, 2008 8:14 EST
Posted by: Esther Schindler
Rating: 90

You wrote: Roger Detzler (CTO) has never believed a thing that he is saying...

I understand that you disagree fervently with the author of this post. Fine. But there's a difference between "This is how I feel" and "You're wrong | stupid | lying."

This is a professional forum. We're expected to act like grown-ups. If you wouldn't utter your message to Roger's face, under your own identity... then how seriously can a reader here take your opinion?

For more understanding of the guidelines of Advice & Opinion, see A Note from Your BlogMom.

Post new comment

* Subject:
* Username:
* E-mail:
The content of this field is kept private and will not be shown publicly.
Homepage:
* Body:
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <img> <blockquote> <strike> <p> <br>
  • Lines and paragraphs break automatically.
More information about formatting options

* Denotes required field.

Start a Conversation
Click to post

Got something to say? We want to hear it! Click the Post button to get started. GO»

EXPERT ADVICE
See our roster of experts.

Advice & Opinion from more than 113 of IT's most insightful thinkers.

  PARTNERS       WEBCASTS    
 

Windows 7 Webcast Series

There's a lot of buzz about Windows 7 out there. Each month in our webcast series, listen to analysts and customers discuss how Windows 7 and the Windows Optimized Desktop is impacting large companies around the world. Learn how they evaluated Windows 7, including the cost of deployment, deployment strategies, and tangible benefits.

Sponsored by Microsoft  Listen to on-demand Recordings »

 

Service Level Management Best Practices Life Cycle Overview - Improve Service Levels

Best practices for Service Level Management (SLM) is a process for consistently meeting customer requirements and delivering on IT's promises. See the steps required to ensure high-quality SLM.

Sponsored by Compuware  Read this White Paper »

 

Keeping Your Members Safe from Online Scams and Predators

In order to keep fraudsters out, romance sites must deploy effective solutions that look at information independent of what is supplied by users. A device fingerprinting solution such as iovation ReputationManager™ provides unique insight into the computers being used to create multiple accounts and exposes hidden device-account relationships that identity-based fraud solutions often miss.

Sponsored by iovation  Read this White Paper »

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

Defend Against Blended Threats: What You Need to Know

Blended Web and email threats are becoming increasingly complex and represent a huge...  View Now »

 

Prescriptive Actions to Reduce Risk

In this Webcast, learn best practices for effective systems management in a heterogeneous environment and keep client systems cost under control.   View Now »

 

Webcast- Vantage 11: Redefining Application Performance Management

Compuware's latest release, Vantage 11, is a major advance in end-to-end application performance management--bringing together proactive issue identification, quantification of business impact and problem resolution into a single solution. Tune in to learn how Vantage 11's top-down approach helps you make better decisions and dramatically lower operations costs.  View Now »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

 
NEWSLETTER

Sign-up for the Blogs & Discussion Newsletter

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Return on Information: Google Enterprise Search pays you back. Get the facts.

VMware. The source for Business Infrastructure Virtualization.

ShoreTel tells businesses to untangle from competitors' complexity and turn to its brilliantly simple UC solution

See how AT&T can help protect your network.

Streamline IT Costs. Boost Performance with WAN Optimization.

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

The rules of infrastructure management just changed.

A Clear View Toward Virtualization

Interactive Q&A helps you discover key ways to maximize IT assets.

Ready to virtualize tier one applications? Check your virtualization maturity.

Think you can't afford a Cisco Switch? Cisco Catalyst Switches are now more affordable.

Five minute business analytics assessment. Immediate results.

The Case for Investing in Business Analytics Technology. Read white paper.

Upgrading to VMware vSphere with vWire

Top 10 Lessons Learned for Corporate 3G Mobile Broadband Deployments

CRM Built for IT: The Executive Guide to Selecting CRM that Meets IT Needs

Return on Information: Google Enterprise Search pays you back

ROI of Application Delivery Controllers

Making Consumer Two-Factor Authentication Simple and Cost-Effective

Mining the Cloud to Ease the Enterprise Compliance Burden

Solve Five Key IT Security Challenges with Cloud-Based Authentication

White Paper: Right-Sizing Your Power Infrastructure

AT&T Synaptic Storage as a Service. Expand on demand

Trend Micro ranked #1 against real-world malware. Read more.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Top Five CIO Challenges

Read the RSA report: Security for Business Innovation

64-page prescriptive guide to security, compliance, and IT operations.

Increase UPS efficiency without sacrificing protection.

eZine: A Roadmap to Reducing IT Complexity

Reduce risk, gain agility. See how Progress can help your business.

Virtualization Technology as a Business Solution

eZine: A Roadmap to Reducing IT Complexity

World-class trading technology solutions from NYSE Technologies.

If You're Paying for Telecom, You're Paying Too Much. Contact Asentinel Today.

Trade-In your old printer and save up to $1,000 plus free recycling!

infoBOOM! - The Mid-Sized Company CIO's Exclusive Community

Live Webinar: Applying Business Analytics. Click here to learn more

Removing Barriers To Better Server Virtualization Efficiency

4G Revisited. The Continued Evolution of Wireless Mobility.

What's Next for Enterprise Resource Planning?

Maximizing website Return on Information with high-quality search

Gartner Magic Quadrant, Application Delivery Controllers 2009

Authentication as a Service by Forrester Research

Cloud-Based Authentication for Next-Generation Extranets

Cut Costs & Green Your IT Operations with PC Power Management

White Paper: 4 Customer Service Myths