Data erasure (sometimes referred to as data clearing, data wiping, or data destruction) is a software-based method of data sanitization that aims to completely destroy all electronic data residing on a hard disk drive or other digital media by overwriting data onto all sectors of the device in an irreversible process. By overwriting the data on the storage device, the data is rendered irrecoverable.
Ideally, software designed for data erasure should:
Allow for selection of a specific standard, based on unique needs, and
Verify the overwriting method has been successful and removed data across the entire device.
Permanent data erasure goes beyond basic file deletion commands, which only remove direct pointers to the data disk sectors and make the data recovery possible with common software tools. Unlike degaussing and physical destruction, which render the storage media unusable, data erasure removes all information while leaving the disk operable. New flash memory-based media implementations, such as solid-state drives or USB flash drives, can cause data erasure techniques to fail allowing remnant data to be recoverable.[1]
Software-based overwriting uses a software application to write a stream of zeros, ones or meaningless pseudorandom data onto all sectors of a hard disk drive. There are key differentiators between data erasure and other overwriting methods, which can leave data intact and raise the risk of data breach, identity theft or failure to achieve regulatory compliance. Many data eradication programs also provide multiple overwrites so that they support recognized government and industry standards, though a single-pass overwrite is widely considered to be sufficient for modern hard disk drives. Good software should provide verification of data removal, which is necessary for meeting certain standards.
To protect the data on lost or stolen media, some data erasure applications remotely destroy the data if the password is incorrectly entered. Data erasure tools can also target specific data on a disk for routine erasure, providing a hacking protection method that is less time-consuming than software encryption. Hardware/firmware encryption built into the drive itself or integrated controllers is a popular solution with no degradation in performance at all.
Encryption
When encryption is in place, data erasure acts as a complement to crypto-shredding, or the practice of 'deleting' data by (only) deleting or overwriting the encryption keys.[2]
Presently, dedicated hardware/firmware encryption solutions can perform a 256-bit full AES encryption faster than the drive electronics can write the data. Drives with this capability are known as self-encrypting drives (SEDs); they are present on most modern enterprise-level laptops and are increasingly used in the enterprise to protect the data. Changing the encryption key renders inaccessible all data stored on a SED, which is an easy and very fast method for achieving a 100% data erasure. Theft of an SED results in a physical asset loss, but the stored data is inaccessible without the decryption key that is not stored on a SED, assuming there are no effective attacks against AES or its implementation in the drive hardware.[citation needed]
Importance
Information technology assets commonly hold large volumes of confidential data. Social security numbers, credit card numbers, bank details, medical history and classified information are often stored on computer hard drives or servers. These can inadvertently or intentionally make their way onto other media such as printers, USB, flash, Zip, Jaz, and REV drives.
Data breach
Increased storage of sensitive data, combined with rapid technological change and the shorter lifespan of IT assets, has driven the need for permanent data erasure of electronic devices as they are retired or refurbished. Also, compromised networks and laptop theft and loss, as well as that of other portable media, are increasingly common sources of data breaches.
If data erasure does not occur when a disk is retired or lost, an organization or user faces a possibility that the data will be stolen and compromised, leading to identity theft, loss of corporate reputation, threats to regulatory compliance and financial impacts. Companies spend large amounts of money to make sure their data is erased when they discard disks.[3][dubious – discuss] High-profile incidents of data theft include:
CardSystems Solutions (2005-06-19): Credit card breach exposes 40 million accounts.[4]
Lifeblood (2008-02-13): Missing laptops contain personal information including dates of birth and some Social Security numbers of 321,000.[5]
Hannaford (2008-03-17): Breach exposes 4.2 million credit, debit cards.[6]
Compass Bank (2008-03-21): Stolen hard drive contains 1,000,000 customer records.[7]
University of Florida College of Medicine, Jacksonville (2008-05-20): Photographs and identifying information of 1,900 on improperly disposed computer.[8]
Oklahoma Corporation Commission (2008-05-21): Server sold at auction compromises more than 5,000 Social Security numbers.[9]
Department of Finance, the Australian Electoral Commission and National Disability Insurance Agency (2017-11-02) - 50,000 Australians and 5000 Federal Public servant records.[citation needed]
Regulatory compliance
Strict industry standards and government regulations are in place that force organizations to mitigate the risk of unauthorized exposure of confidential corporate and government data. Regulations in the United States include HIPAA (Health Insurance Portability and Accountability Act); FACTA (The Fair and Accurate Credit Transactions Act of 2003); GLB (Gramm-Leach Bliley); Sarbanes-Oxley Act (SOx); and Payment Card Industry Data Security Standards (PCI DSS) and the Data Protection Act in the United Kingdom. Failure to comply can result in fines and damage to company reputation, as well as civil and criminal liability.[citation needed]
Preserving assets and the environment
Data erasure offers an alternative to physical destruction and degaussing for secure removal of all the disk data. Physical destruction and degaussing destroy the digital media, requiring disposal and contributing to electronic waste while negatively impacting the carbon footprint of individuals and companies.[10] Hard drives are nearly 100% recyclable and can be collected at no charge from a variety of hard drive recyclers after they have been sanitized.[11]
Limitations
Data erasure may not work completely on flash based media, such as Solid State Drives and USB Flash Drives, as these devices can store remnant data which is inaccessible to the erasure technique, and data can be retrieved from the individual flash memory chips inside the device.[1]
Data erasure through overwriting only works on hard drives that are functioning and writing to all sectors. Bad sectors cannot usually be overwritten, but may contain recoverable information. Bad sectors, however, may be invisible to the host system and thus to the erasing software. Disk encryption before use prevents this problem. Software-driven data erasure could also be compromised by malicious code.[12]
Differentiators
Software-based data erasure uses a disk accessible application to write a combination of ones, zeroes and any other alpha numeric character also known as the "mask" onto each hard disk drive sector. The level of security when using software data destruction tools is increased dramatically by pre-testing hard drives for sector abnormalities and ensuring that the drive is 100% in working order. The number of wipes has become obsolete with the more recent inclusion of a "verify pass" which scans all sectors of the disk and checks against what character should be there, i.e., one pass of AA has to fill every writable sector of the hard disk. This makes any more than one pass an unnecessary and certainly a more damaging act, especially in the case of large multi-terabyte drives.
Full disk overwriting
While there are many overwriting programs, only those capable of complete data erasure offer full security by destroying the data on all areas of a hard drive. Disk overwriting programs that cannot access the entire hard drive, including hidden/locked areas like the host protected area (HPA), device configuration overlay (DCO), and remapped sectors, perform an incomplete erasure, leaving some of the data intact. By accessing the entire hard drive, data erasure eliminates the risk of data remanence.
Data erasure can also bypass the Operating System (OS). Overwriting programs that operate through the OS will not always perform a complete erasure because they cannot modify the contents of the hard drive that are actively in use by that OS. Because of this, many data erasure programs are provided in a bootable format, where you run off a live CD that has all of the necessary software to erase the disk.[citation needed]
Hardware support
Data erasure can be deployed over a network to target multiple PCs rather than having to erase each one sequentially. In contrast with DOS-based overwriting programs that may not detect all network hardware, Linux-based data erasure software supports high-end server and storage area network (SAN) environments with hardware support for Serial ATA, Serial Attached SCSI (SAS) and Fibre Channel disks and remapped sectors. It operates directly with sector sizes such as 520, 524, and 528, removing the need to first reformat back to 512 sector size. WinPE has now overtaken Linux as the environment of choice since drivers can be added with little effort. This also helps with data destruction of tablets and other handheld devices that require pure UEFI environments without hardware NIC's installed and/or are lacking UEFI network stack support.
Standards
Many government and industry standards exist for software-based overwriting that removes the data. A key factor in meeting these standards is the number of times the data is overwritten. Also, some standards require a method to verify that all the data have been removed from the entire hard drive and to view the overwrite pattern. Complete data erasure should account for hidden areas, typically DCO, HPA and remapped sectors.
The 1995 edition of the National Industrial Security Program Operating Manual (DoD 5220.22-M) permitted the use of overwriting techniques to sanitize some types of media by writing all addressable locations with a character, its complement, and then a random character. This provision was removed in a 2001 change to the manual and was never permitted for Top Secret media, but it is still listed as a technique by many providers of the data erasure software.[13]
Data erasure software should provide the user with a validation certificate indicating that the overwriting procedure was completed properly. Data erasure software should[citation needed] also comply with requirements to erase hidden areas, provide a defects log list and list bad sectors that could not be overwritten.
Overwriting Standard
Date
Overwriting Rounds
Pattern
Notes
U.S. Navy Staff Office Publication NAVSO P-5239-26[14]
Data can sometimes be recovered from a broken hard drive. However, if the platters on a hard drive are damaged, such as by drilling a hole through the drive (and the platters inside), then the data can only theoretically be recovered by bit-by-bit analysis of each platter with advanced forensic technology.
Number of overwrites needed
Data on floppy disks can sometimes be recovered by forensic analysis even after the disks have been overwritten once with zeros (or random zeros and ones).[27]
This is not the case with modern hard drives:
According to the 2014 NIST Special Publication 800-88 Rev. 1, Section 2.4 (p. 7): "For storage devices containing magnetic media, a single overwrite pass with a fixed pattern such as binary zeros typically hinders recovery of data even if state of the art laboratory techniques are applied to attempt to retrieve the data."[24] It recommends cryptographic erase as a more general mechanism.
According to the University of California, San Diego Center for Magnetic Recording Research's (now its Center for Memory and Recording Research) "Tutorial on Disk Drive Data Sanitization" (p. 8): "Secure erase does a single on-track erasure of the data on the disk drive. The U.S. National Security Agency published an Information Assurance Approval of single-pass overwrite, after technical testing at CMRR showed that multiple on-track overwrite passes gave no additional erasure."[28]Secure erase is a feature built into modern hard drives and solid-state drives that overwrites all data on a disk, including remapped (error) sectors.[29]
Further analysis by Wright et al. seems to also indicate that one overwrite is all that is generally required.[30]
Even the possibility of recovering floppy disk data after overwrite is disputed. Gutmann's famous article cites a non-existent source and sources that do not actually demonstrate recovery, only partially-successful observations. Gutmann's article also contains many assumptions that indicate his insufficient understanding of how hard drives work, especially the data processing and encoding process.[31] The definition of "random" is also quite different from the usual one used: Gutmann expects the use of pseudorandom data with sequences known to the recovering side, not an unpredictable one such as a cryptographically secure pseudorandom number generator.[32]
E-waste and information security
E-waste presents a potential security threat to individuals and exporting countries. Hard drives that are not properly erased before the computer is disposed of can be reopened, exposing sensitive information. Credit card numbers, private financial data, account information and records of online transactions can be accessed by most willing individuals. Organized criminals in Ghana commonly search the drives for information to use in local scams.[33]
^ abMichael Wei; Laura M. Grupp; Frederick E. Spada; Steven Swanson (15 February 2011). "Reliably Erasing Data From Flash-Based Solid State Drives"(PDF). FAST '11: 9th USENIX Conference on File and Storage Technologies. Retrieved 17 August 2024. For sanitizing entire disks, built-in sanitize commands are effective when implemented correctly, and software techniques work most, but not all, of the time. We found that none of the available software techniques for sanitizing individual files were effective.
^"Securely erase a solid-state drive". University Information Technology Services. Retrieved 7 February 2022. you may be able to quickly sanitize the device by deleting the encryption key, which renders the data on the drive irretrievable.
^Kissel, Richard; Regenscheid, Andrew; Scholl, Matthew; Stine, Kevin (December 2014). "SP800-88 Rev. 1 Guidelines for Media Sanitization"(PDF). Computer Security Division, Information Technology Laboratory. NIST. pp. 27–40. Retrieved 18 January 2018.
КоммунаСенван-ЛеарSenven-Léhart 48°25′33″ с. ш. 3°04′05″ з. д.HGЯO Страна Франция Регион Бретань Департамент Кот-д’Армор Кантон Каллак Мэр Жильбер Бюрло(2014—2020) История и география Площадь 12,50 км² Высота центра 120–266 м Часовой пояс UTC+1:00, летом UTC+2:00 Население Население 2...
У Вікіпедії є статті про інші географічні об’єкти з назвою Плімут. Місто Плімутангл. Plymouth Координати 35°51′35″ пн. ш. 76°44′52″ зх. д. / 35.85972222224977202° пн. ш. 76.74777777780577992° зх. д. / 35.85972222224977202; -76.74777777780577992Координати: 35°51′35″ пн. ш. 76°44′52″ зх....
Waffle House Inc. Tipo PrivadaIndustria RestaurantesFundación 1955 en Avondale Estates, GeorgiaSede central Condado de Gwinnett, GA, Estados UnidosProductos Comida rápidaIngresos 1.1 billones de USD (2012)Sitio web wafflehouse.com[editar datos en Wikidata] Waffle House (en español Casa de Gofres) es una cadena de restaurantes de comida rápida estadounidense. Se encuentran en el sur de los Estados Unidos, y en total hay en más de 1700 localidades en 25 estados. La sede de ...
دادلي مور معلومات شخصية اسم الولادة (بالإنجليزية: Dudley Stuart John Moore) الميلاد 19 أبريل 1935[1][2][3] هامرسميث الوفاة 27 مارس 2002 (66 سنة) [1][2][3] بلينفيلد[4] سبب الوفاة الشلل فوق النوى المترقي، وذات الرئة الإقامة لندن مواطنة الممل�...
George Stephenson Lokomotive „Blücher“ von George Stephenson, 1814 Lokomotive „The Rocket“ von George und Robert Stephenson von 1829 im Londoner Science Museum Zeichnung einer „Locomotivmaschine des Hrn. R. Stephenson“ von 1836[1] George Stephenson (* 9. Juni 1781 in Wylam bei Newcastle upon Tyne, Northumberland; † 12. August 1848 in Tapton House bei Chesterfield) war ein englischer Ingenieur und Hauptbegründer des Eisenbahnwesens. Er war Autodidakt und erwarb sich umf...
بولوتري الإحداثيات 42°08′00″N 14°36′00″E / 42.133333333333°N 14.6°E / 42.133333333333; 14.6 [1] تقسيم إداري البلد إيطاليا[2] التقسيم الأعلى مقاطعة كييتي خصائص جغرافية المساحة 26.17 كيلومتر مربع (9 أكتوبر 2011)[3] ارتفاع 180 متر عدد السكان عدد السكان 2188 (1
University of New Brunswick Motto Sapere Aude(dt.: Wage es, weise zu sein) Gründung 1785 Trägerschaft staatlich Ort Fredericton und Saint John, Kanada KanadaAußenstellen:Bathurst, Moncton Kanzler (chancellor) Allison D. McCain (seit 2013, McCain Foods)[1] Präsident und Vizekanzler Paul Mazerolle (seit 2019)[2] Studierende > 10.000[3] (Herbst 2020: 8.307 FTE)[4] Mitarbeiter >3000[3] Jahresetat 190 Mio. $ (CAD) (2016/2017)[5] Netzwe...
Kōraku-en, taman bergaya kaiyū di Okayama. Taman batu Jepang di Ryōan-ji, Kyoto. Taman Jepang (日本庭園code: ja is deprecated , Nihon teien) adalah taman yang dibangun dengan gaya tradisional Jepang. Prinsip dasar taman Jepang adalah miniaturisasi dari lanskap atau pemandangan alam empat musim di Jepang. Elemen dasar seperti batu-batu dan kolam dipakai untuk melambangkan lanskap alam berukuran besar. Selain taman Jepang yang dibuka untuk umum, taman Jepang dibangun di hotel, kuil Buddh...
Maribel Guédez Diputada a la Asamblea Nacional de Venezuelapor circuito 1 del estado Barinas 5 de enero de 2016-5 de enero de 2021 Información personalNacimiento 7 de febrero de 1962Nacionalidad VenezolanaEducaciónEducada en Universidad de los LlanosInformación profesionalOcupación PolíticaPartido político Un Nuevo Tiempo (hasta 2018) Prociudadanos (desde 2018)[editar datos en Wikidata] Maribel Guédez (7 de febrero de 1962) es una política venezolana que sirvió como diputa...
Umdat al-Salik wa Uddat al-Nasik Reliance of the Traveller, diterjemahkan oleh Nuh Ha Mim KellerPengarangAhmad ibn Naqib al-MisriPenerjemahNuh Ha Mim KellerBahasaBahasa ArabSubjekFikih Syafi'iPenerbitAmana publicationsHalaman1232ISBNISBN 978-0-915957-72-9 Umdat as-Salik wa 'Uddat an-Nasik (Reliance of the Traveller and Tools of the Worshipper, juga umum dikenal dengan judul pendek Reliance of the Traveller)[1][2] adalah sebuah panduan klasik fikih untuk aliran Syafi'i. Penulis...
10th episode of the 6th season of Aqua Teen Hunger Force Last Last One Forever and EverAqua Teen Hunger Force episodeA promotional set photoEpisode no.Season 6Episode 10Directed byMatt MaiellaroDave WillisWritten byMatt MaiellaroDave WillisProduction code610[1]Original air dateMay 31, 2009 (2009-05-31)Running time11:40 minutesGuest appearances David Long, Jr. as Carl Brutananadilewski (live action) Jon Benjamin as Don Shake (live action) T-Pain as Frylock (live act...
Николай Сыченков Имя при рождении Николай Максимович Сыченков Дата рождения 19 декабря 1925(1925-12-19) Место рождения Москва, РСФСР, СССР Дата смерти 18 октября 2012(2012-10-18) (86 лет) Место смерти Махачкала, Дагестан, Россия Гражданство СССР→ Россия Профессия актёр Годы активно�...
2022 windstorm over northwestern Europe For the 2015 cyclone, see Cyclone Eunice. For the 1948 tropical storm sometimes known as Eunice, see Typhoon Dolores–Eunice. Storm Eunice Storm Eunice on 17 February 2022Meteorological historyFormed17 February 2022Dissipated19 February 2022Extratropical cycloneHighest gusts196 km/h (122 mph; 106 kn) at The Needles, Isle of WightOverall effectsFatalities 17 Netherlands: 4 Poland: 4 Germany: 3 United Kingdom: 3 Belgium: 2 Ireland: 1 ...
This article does not cite any sources. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: List of mosques in Lahore – news · newspapers · books · scholar · JSTOR (December 2009) (Learn how and when to remove this template message) This is a list of mosques in the city of Lahore, Pakistan. This city has remained capital of Delhi Sultanate and Mughal Empire at various ...
Final Piala Liga Inggris 2001TurnamenPiala Liga Inggris 2000–2001 Liverpool Birmingham City 1 1 setelah perpanjangan waktuLiverpool menang 5–4 pada adu penaltiTanggal25 Februari 2001StadionStadion Millennium, CardiffWasitDavid Elleray (Harrow)[1]Penonton73.500← 2000 2002 → Final Piala Liga Inggris 2001 adalah pertandingan final ke-41 dari turnamen sepak bola Piala Liga Inggris untuk menentukan juara musim 2000–2001. Pertandingan ini diselenggarakan pada 25 Februari 2...
Bi-annual South African event that is to be held for the first time in 2008 This article includes a list of general references, but it lacks sufficient corresponding inline citations. Please help to improve this article by introducing more precise citations. (July 2022) (Learn how and when to remove this template message) South African Solar ChallengeVenuePublic roadsLocationSouth AfricaCorporate sponsorSasolFirst race2008Last race2022Distance~2500kmMost wins (team)Nuna The Sasol Solar Challe...
For modernist reform movements in Islam, see Islamic Modernism. Part of a series onIslam Beliefs Oneness of God Prophets Revealed Books Angels Day of Resurrection Predestination Practices Profession of Faith Prayer Almsgiving Fasting Pilgrimage TextsFoundations Quran Sunnah (Hadith, Sirah) Tafsir (exegesis) Aqidah (creed) Qisas al-Anbiya (Stories of the Prophets) Mathnawi (Poems) Fiqh (jurisprudence) Sharia (law) History Timeline Muhammad Ahl al-Bayt Sahabah Rashidun Caliphate Imamate Medieva...
『この人を見よ』作者アンドレア・マンテーニャ製作年1500年以前寸法72 cm × 54 cm (28 in × 21 in)所蔵ジャックマール=アンドレ美術館, パリ, フランス 『この人を見よ』(このひとをみよ、伊: Ecce Homo)は、イタリアのルネサンス期の画家アンドレア・マンテーニャの絵画である[1]。パリのジャックマール=アンドレ美術館に所蔵されて...