Re: Interesting One

From: ATD (simon@snosoft.com)
Date: 10/31/02


From: ATD <simon@snosoft.com>
To: Carol Stone <carol@carolstone.com>
Date: 30 Oct 2002 18:08:05 -0500


I have heard similar claims from "agencies" about the ability to recover
data after multiple re-writes. I also happen to know that several of
these "agencies" when doing drive disposal, literally drill holes in
their drives then incinerate them. That is after they wipe the drive
clean several times. I'd assume that there is a reason for such
paranoia, wouldn't you? Or do you think they are just playing it super
safe?

On Tue, 2002-10-29 at 15:57, Carol Stone wrote:
> I don't know much about this, but yesterday I read in one of the later
> chapters of Bruce Schneier's book, "Secrets and Lies," (link to amazon
> follows) that over-writing data on a disk does *not* completely
> obliterate it, it just makes it a lot more difficult to recover with
> each over-write. I believe he said just how many re-writes were still
> recoverable was a secret one of our governmental organizations wasn't
> about to give up. I'll look at my book later when I have it in my
> hands and see if I can't find part and post a pointer to *his*
> reference.
>
> -carol
>
> http://www.amazon.com/exec/obidos/tg/detail/-
> /0471253111/qid=1035924654/sr=8-3/ref=sr_8_3/104-4454644-5987143?
> v=glance&n=507846
>
> > Greetings Folks,
> >
> > I had an interesting conversation today with someone from FAST
> > (Federation
> > Against Software Theft) They pretend not to be a snitch wing of the
> BSA.
> > Anyway, to get to the point, the guy that came to see me said that
> their
> > forensics guys could read data off a hard drive that had been written
> > over
> > up to thirty times. I find this very hard to believe and told him I
> > thought
> > he was mistaken but the guy was adamant that it could be done. My
> > question
> > is, does anyone have any views on this, or, can anyone point me to a
> > source
> > of information where I can get the facts on exactly how much data can
> be
> > retrieved off a hard drive and under what conditions etc etc.
> >
> > Thanks
> >
> > Dave Adams
> >
> >
> >
> > This message (and any associated files) is intended only for the
> > use of the individual or entity to which it is addressed and may
> > contain information that is confidential, subject to copyright or
> > constitutes a trade secret. If you are not the intended recipient
> > you are hereby notified that any dissemination, copying or
> > distribution of this message, or files associated with this message,
> > is strictly prohibited. If you have received this message in error,
> > please notify us immediately by replying to the message and deleting
> > it from your computer. Messages sent to and from
> > John Crowley (Maidstone) Ltd may be monitored.
> >
> > Internet communications cannot be guaranteed to be secure or error-
> free
> > as information could be intercepted, corrupted, lost, destroyed,
> arrive
> > late or incomplete, or contain viruses. Therefore, we do not accept
> > responsibility for any errors or omissions that are present in this
> > message, or any attachment, that have arisen as a result of e-mail
> > transmission. If verification is required, please request a hard-copy
> > version. Any views or opinions presented are solely those of the
> author
> > and do not necessarily represent those of John Crowley (Maidstone)
> Ltd.
> >
> >
>
> --
> Real people for the virtual world.
> http://www.elirion.net

-- 

-ATD-

------------------------------------------------------------- Secure Network Operations | Strategic Reconnaissance Team http://www.snosoft.com | recon@snosoft.com Cerebrum Project | cerebrum@snosoft.com -------------------------------------------------------------




Relevant Pages

  • Re: Hmm...
    ... US Government could recover the data from the drives. ... you worry about destroying it to ...
    (comp.security.misc)
  • Re: USB 1 to USB 2 corruption
    ... The problem is the slave drive,it has become corrupt to the point that it cannot be read.This has occured several times in the past with different comp.I have a theory how it got corrupt....It is not a virus or malware,I know this for a fact,my system is clean.My theory involves the USB Interface.Especially with going from USB 1 to USB 2 or vice versa.I have a external box that I have the drive in,it is a USB 2 devise,and as long as I keep it attached to a comp.that has USB 2,no problems.The problems start to occur when the external is attached to a comp. ... wants to do a check disk operation at startup,then finally the drive itself cannot be read.This does not happen over few hours, rather a few months.This last time it happened,the drive was fine till I plugged it up to another comp.When I realized that it was a USB 1 port I unplugged it,that was 7 weeks ago,now as of this morning the drive cannot be read.I almost have the 1T drive full,I really don't want to loose 3 years of work.Oh I also might add that the drive cannot be formatted by any XP means,or by any tools that I had,the last time this happened I had to send the drive off to be formatted.Even my computer guru had a very hard time formatting the drive.As I mentioned both drives are sata...but it has also happened with IDE drives.Like I said before main drive still boots normally .I know this is a bit long winded, but maybe something here will help.This is not only limited to XP,it has also happened on '98,me.,2000,and also vista. ... To recover the data, you need enough space to put the recovered files. ...
    (microsoft.public.windowsxp.general)
  • Re: Newly created NTFS files deleted during System Hive restore
    ... Have you visited Windows Update regularly? ... mobo maker to be sure you have a BIOS that supports the "big drives", ... Were you able to recover the file names and directories or ... Chkdsk was running on a 25 ...
    (microsoft.public.win2000.file_system)
  • RE: Digital Evidence Question - What is an effective Windows hard -disk search tool?
    ... If you overwrote your drive with a new install of the O/S you just overwrote ... Ontrack who MIGHT be able to recover it but it would cost you some $$$. ... analyze your drives using tools gnerally used for forensics (NTI, ... Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ...
    (Security-Basics)
  • RE: Interesting One
    ... I have heard similar claims from "agencies" about the ability to recover ... their drives then incinerate them. ... What is the point of taking the time to wipe ... to the incinerator. ...
    (Security-Basics)