NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 


Tue, Feb 19, 2008 16:36 EST

Is your hard drive data really gone?

Topic: Enterprise Management

Current Rating: 5 Comments: 10

As the most widely used storage medium today, it is no wonder hard drives represent one of the biggest security challenges. Yet despite stricter government data compliance and security mandates, more needs to be done to safeguard end-of-life data. Ensuring the data on a hard drive is completely eliminated before it is disposed, redeployed or donated should be a top priority for every organization. A clear understanding of these methods and their limitations is essential to ensuring the safety of end-of-life data. To help you better understand your options, I’ve summarized them below for your consideration.

Secure Erase Technology
Caution: Many vendors who sell commercial software products use the term “secure erase” incorrectly. They use the term to describe an “erasure that is secure”. However it is important to distinguish this misused marketing term with Secure Erase technology.

In the late 90’s, the hard drive manufacturers called for a global summit to discuss the rapidly growing challenge of properly sanitizing hard drives. The challenge was to develop a means for certifiably sanitizing hard drives beyond forensic reconstruction while retaining the ability to reuse the hard drive. The hard drive industry collaborated with Center for Magnetic Recording Research (CMRR), under the direction of the US National Security Agency (NSA), to meet this challenge. They developed a sanitization standard called Secure Erase. The Secure Erase standard has been implemented by all hard drive manufacturers since 2002. It is embedded in the firmware of all ATA/IDE and SATA hard drives and is recommended by the National Institute for Standards and Technology (NIST SP 800-88) as a “purge technology”, a step above software overwriting which is characterized as a “clear technology”.

Since it is located in the firmware of the drive, the sanitization procedure is up to 18x faster than commercial software overwrite routines, which have to communicate to the drive through the OS and BIOS. In addition, it is able to purge all sectors of the hard drive as it has direct access to all bad sector tables stored internally on the drive.

Commercial Overwrite Routines
Commercial overwriting tools are designed to write random bits of data on all user accessible sectors of a drive. The software is loaded onto a machine or server to execute the overwrite procedure. Most overwriting tools execute multiple passes for added security. However, even multiple passes does not guarantee complete sanitization. Some overwriting tools are not able to access bad sectors of a hard drive. This leaves recoverable data on these sectors. In addition, software can take an enormous amount of time, usually lacks an automated logging capability for audit purposes and is not a physically secure process. Both public and private sectors have acknowledged the ineffectiveness of software overwriting. One example of this occurred in June of 2007 when the US Defense Security Service disapproved of this methodology as a method for destroying data.

Degaussing Machines
Degaussers produce a strong magnetic field in order to destroy the magnetically recorded data on the hard drive. Degassers have the unfortunate consequence of destroying the read/write head of the hard drive, rendering the hard drive unusable. The original intent of degaussers was for use with non-rigid disks and magnetic tape media. As the sophistication and platter density in most modern hard drives continues to increase so to does the inadequacy of this methodology. Aside from dangers they pose to other nearby electronic equipment there is no way to ensure that the hard drive platter does not contain any

You do not have flash or javascript support.
Average (2 votes)
5
 
 
Wed, Feb 20, 2008 11:44 EST
Anonymous user
Posted by: Anonymous
Rating: 90

The practical matter here is:

How much effort and what kind of a budget would it take to recover the data on the drive?

Short of a federal level budget (CIA, NSA, etc.) for recovery, there are a number of simple techniques that are rather effective in destroying data

Regarding permanent destruction:

For simple old drives which are too small for practical use in new machines, disassembly and removing the platters is quite sufficient. You can cut them up if needed, or bend them into fun shapes for wind chimes. Give them to the kids to play with in the sand box. (Sand does wonders for a platter surface). Or take them on a cruise, and throw them into the sea between islands, far out from land.

Another simple destructive method is to drill a couple of large holes through the circuit board and the main platters, then let the old drives soak in a bucket of salt water for a month, long enough to ensure a good buildup of corrosion.

These methods are quite effective for anything outside of a governmental budget for recovery purposes.

Erasing with the intent to reuse is somewhat more problematic.

But again, overwriting with random sequences ones or zeroes is quite sufficient before reformatting for use in the new setup.

And drives are inexpensive, so that often it is worth simple replacing the drive and destroying the old

 
Thu, Feb 21, 2008 17:16 EST
Anonymous user
Posted by: Anonymous
Rating: 90

Federal requirements such as HIPAA, Sarbanes-Oxley, etc. require fully documented procedures for disposing of data and a complete chain of custody across a variety of industries; this isn’t limited to just government agencies.

Perhaps it is this simplistic and indifferent attitude that has led to a record year of data security breaches.

 
Mon, Feb 25, 2008 11:25 EST
Anonymous user
Posted by: Anonymous
Rating: 70

I find it quite absurd that you find the methods you listed as satisfactory for non-governmental organizations. The cost to a company who loses sensitive information is astronomical: notifications to customers (letters, email, web and media), legal defense services, criminal investigations, legal audit and accounting fees, call center expenses, public and investor relations and internal investigations just to name a few. In light of this, you can bet that a company is going to spend whatever is necessary to prevent the expenses associated with the above as well the damage that their reputation will suffer from a breach.

Recently, the Poneman Institute released an annual study on the cost of a data breach. They estimated the total cost to be $197 per record lost. Imagine how many millions of records would be on a single hard drive. I don’t think they would be making wind chimes with the platters.

 
Tue, Feb 26, 2008 14:38 EST
Anonymous user
Posted by: Anonymous
Rating: 10

PLEASE!!!!

Roger Detzler (CTO) has never believed a thing that he is saying... and as a matter of fact... laughed at the concept of a 'digital shredder" as not having a market... "it's too expensive for the common man" and EDT has yet to sell any quantity of product into the open market, since 2005.

EDT's founders are all non technical people who have never used a computer... never mind run a high tech company.

EDT's founders have screwed their dealer network and it will come back to haunt them. They screwed their original OEM... EDT has no in-house development/programming/support staff...A shell organization.

Buyer's beware... EDT is living off of angel investors seed capital and free rent... The senior management is making all of the wrong moves...the BOARD NEEDS TO WAKE UP!

 
Wed, Feb 27, 2008 8:14 EST
Posted by: Esther Schindler
Rating: 90

You wrote: Roger Detzler (CTO) has never believed a thing that he is saying...

I understand that you disagree fervently with the author of this post. Fine. But there's a difference between "This is how I feel" and "You're wrong | stupid | lying."

This is a professional forum. We're expected to act like grown-ups. If you wouldn't utter your message to Roger's face, under your own identity... then how seriously can a reader here take your opinion?

For more understanding of the guidelines of Advice & Opinion, see A Note from Your BlogMom.

Start a Conversation
Click to post

Got something to say? We want to hear it! Click the Post button to get started. GO»

EXPERT ADVICE
See our roster of experts.

Advice & Opinion from more than 108 of IT's most insightful thinkers.

  PARTNERS       WEBCASTS    
 

Preparing for the Next Cyber Attack

Ensure you are up-to-speed on the latest security technologies available to keep your network safe in this Executive Guide. Get a thorough assessment of the corporate security threat landscape. Protect your network with data leakage protection, NAC and other technologies explained in this report.

Sponsored by Qwest  Read this Executive Guide »

 

Cloud Building: 8 Ingredients for Internal Clouds

Cloud computing: a fundamentally new way to deploy IT services and functions cost-effectively and quickly. Learn how the VMware vCloud initiative dramatically improves how consumers access their information and experience applications as well as the 8 ingredients to get you going.

Sponsored by VMWare  Read this White Paper »

 

Investing in Business Analytics Technology

You're thinking now is the time to take the plunge into business analytics, but you still have some unanswered questions. This research summary addresses the most common questions and concerns surrounding the successful launch of a business analytics initiative. It also includes real-world examples of organizations already getting return on their investment.

Sponsored by SAS  Read this White Paper »

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

Improving Transparency and Accuracy in IT Cross Charging

During this Webcast you'll learn how KBC Group implemented SAP BusinessObjects Profitability and Cost Management and realized many benefits.   View Now »

 

Cost Savings and Risk Reduction with Effective Systems Management

Join us and see how Novell can help you respond to today's economic challenges by increasing productivity, reducing costs and aligning IT initiatives with overall business goals.  View Now »

 

Capitalize on Your SAP Content

Learn ways to improve your content management by viewing these Open Text webinars today.  View Now »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

 
NEWSLETTER

Sign-up for the Blogs & Discussion Newsletter

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Introducing the new HP ProLiant G6 server family

Accenture: Outsourcing for Competitive Advantage. More...

Better spam protection with Postini for just $1/user/mo

Introducing the new HP ProLiant G6 server family

infoBOOM! - The Mid-Sized Company CIO's Exclusive Community

Accenture IT Consulting: Logical meets technological. More . . .

The Fraudster Economy Model: Operating a Business in the Underground

Trade in your old laser printer and get up to $1000 back!

Taking the Service Desk to the Next Level

Revolutionizing Enterprise Application Deployment

Why Data Loss is Increasing--and What You Can Do About It

Data Loss Prevention: A Better Way to Approach Security

Learn how to managing client systems in the enterprise.

Build a High-Performance Open Web Platform

Mid-Sized Company CIO Community: infoBOOM!

Enterprise PBX Comparison Guide

Getting Value from Outdated Networking Equipment

Losing Ground: 2009 TMT Global Security Survey

Stop Application Fraud at the Source with Device Reputation

Learn about the VMware vSphere (TM) & Intel (R) Xeon (R) Processor 5500 Series

Learn how a virtualized enterprise can help your company reduce costs

Why Isn't Server Virtualization Saving Us More?

Learn how to save 30% through project & portfolio management.

How Open Source is Changing the Face of Enterprise Software

8 Key Ingredients to Building an Internal Cloud

Accenture IT Consulting: Enabling high performance. More...

Top Five CIO Challenges

Insight makes it easy to spend your Microsoft subsidy check.

Five minute business analytics assessment. Immediate results.

Dangerous Collaboration Practices: 5 Ways IT Can Minimize Risk

Accenture: Outsourcing for uncertain times. Click to learn more.

The Case for Investing in Business Analytics Technology. Read white paper.

Live Webinar: Applying Business Analytics. Click here to learn more

Seven Ways ITIL Can Help You in an Economic Downturn

Developing A Dynamic, Real-Time IT Infrastructure

Maximizing the Business Value of the PC Infrastructure

Communications and Collaboration Needs at Business Organizations

Using Open Source to Deploy Web Applications

Cloud Computing: Read about VMware's compelling vision & set of products

Enterprise PBX Buyer's Guide

Secondary Market Primer: Your Network at Half Price

How Interactive Viewer Reduces the Effort to Meet Visualization Requirements

Top-line Performance that's Bottom-line Efficient

White Paper: 8 Key Ingredients to Building an Internal Cloud

Read about virtualization and consolidation effort best practices

Building the Virtualized Enterprise with VMware Infrastructure

The Global Marketplace Today: Strategies for Tough Times

Top 10 Business and IT Drivers for the Wealth Management Sector

5 Steps to Automating Accounts Payable

Bottom-Line Benefits of Virtualization