Peter Gutmann data deletion theaory?

From: Jared Johnson (jaredsjazz_at_Yahoo.com)
Date: 07/21/05

  • Next message: Dirk Mueller: "[KDE Security Advisory] Multiple libgadu vulnerabilities"
    To: <focus-ms@securityfocus.com>
    Date: Wed, 20 Jul 2005 19:48:44 -0400
    
    

    All,

    Do you all agree with Peter Gutman's conclusion on his theory that data can
    never really be erased, as noted in his quote below:

    "Data overwritten once or twice may be recovered by subtracting what is
    expected to be read from a storage location from what is actually read. Data
    which is overwritten an arbitrarily large number of times can still be
    recovered provided that the new data isn't written to the same location as
    the original data (for magnetic media), or that the recovery attempt is
    carried out fairly soon after the new data was written (for RAM). For this
    reason it is effectively impossible to sanitise storage locations by simple
    overwriting them, no matter how many overwrite passes are made or what data
    patterns are written. However by using the relatively simple methods
    presented in this paper the task of an attacker can be made significantly
    more difficult, if not prohibitively expensive."

    It seems that the perhaps the only real way to rid your Hard Drives of data
    is to burn them.

    I'd love to hear some thoughts on this from security and data experts out
    there.


  • Next message: Dirk Mueller: "[KDE Security Advisory] Multiple libgadu vulnerabilities"

    Relevant Pages

    • Re: Peter Gutmann data deletion theaory?
      ... The NSA disagree and have conducted laboratory tests. ... erase disks (that can be written to; drives that won't spin up or can't be ... > expected to be read from a storage location from what is actually read. ... > overwriting them, no matter how many overwrite passes are made or what data ...
      (Bugtraq)
    • RE: Peter Gutmann data deletion theaory?
      ... This is a well known fact of data forensic science and why this science ... Overwriting data hardly obscures the data. ... expected to be read from a storage location from what is actually read. ... the original data, or that the recovery attempt is ...
      (Bugtraq)
    • RE: Peter Gutmann data deletion theaory?
      ... If you have, for example, a modern tape and just zero it (write eofs at the ... it'll cost to get the data back, and whether all recovery shops might ask embarrassing ... expected to be read from a storage location from what is actually read. ... overwriting them, no matter how many overwrite passes are made or what data ...
      (Bugtraq)
    • bugtraq@planetcobalt.net
      ... "Overwriting Hard Drive Data: The Great Wiping Controversy". ... modern ePRML drives. ... of a few regarding data recovery after a file has been 'zeroed' and ...
      (Security-Basics)
    • Re: FileCopy overwrites the existing file
      ... overwriting large file is quite expensive and if I had to do it, ... I've seen a software that allows a user to overwrite the sectors up ... overwritten once with zeros. ... I wouldn't assume such recovery is a regular offer. ...
      (microsoft.public.win32.programmer.kernel)