Live data from Hacker News

Millions of usable hard drives are being destroyed

bbc.com

141–150 of 153 posts

Re: Millions of usable hard drives are being destroyed

#141
post #125

Earlier quoted context omitted.

If I can store drive encryption keys on a HSM in my old, consumer grade laptop, I would hope that large storage systems have at least the same degree of protection.

But if that HSM module or machine suddenly dies, the system would lose all the customer's files. Not good.

[deleted]

Re: Millions of usable hard drives are being destroyed

#142

Earlier quoted context omitted.

Ah, you have never been on the IT side of any shop have you? The risks to keep running said hardware, or performance, or storage space, or power consumption or whatever are too high so you aren't going to be using it. So you decom it and do what, stick it in a closet? Decommissioned hardware that is put in storage inevitably walks home with an enterprising employee to whom the risks from the business perspective are…

>hardware, or performance, or storage space, or power consumption or whatever are too high I just upgraded my 10 year old laptop because I wanted to do AI Art locally. I ran video games, CAD, cellphone emulators, my programs, etc... on this computer and it still works. Heck, I still use it in a different room now. Its not the 2000s anymore, we don't need tons of processing power to open web browsers and M$ Office. De…

you... haven't actually seen what an average employee does to a computer have you? Yes there are ones that treat their hardware nice, but yeah, no.

Also it's not the useability it's the manufacturing warranty that goes with it. Personal use is a very different thing from business risk.

Re: Millions of usable hard drives are being destroyed

#143

We recently had to destroy over 700 harddisks (10TB) because the customer didn't trust that a secure erase and full overwrite ways enough to make sure no data could be recovered. It was really painful to watch....

I was looking at cleaning up some of my old drive, and I was basing my decisions on outdated information. At some point in the past it used to be necessary to do many overwrites to truly erase the data, and I was just stuck on that. Took me a bunch of research on modern drives and latest best practices before I was able to convince myself what I "knew" was no longer valid, and things have changed. I imagine that is w…

> At some point in the past it used to be necessary to do many overwrites

Even that has almost always been just a cargo cult. Some people (mainly from the hacker community) claimed that US government agencies can still read data from harddrives that have been erased. It has never been proven by any independent data recovery company.

It might have been somewhat true for MFM or RLL drives (these were before my time in IT), but at least since IDE drives, it was no longer true. However, the cult around "multiple erase cycles" still held, mainly because of companies like Norton etc. who sold snakeoil tools to "securely" erase your data

Re: Millions of usable hard drives are being destroyed

#144

We recently had to destroy over 700 harddisks (10TB) because the customer didn't trust that a secure erase and full overwrite ways enough to make sure no data could be recovered. It was really painful to watch....

Did the customer not use encryption? I guess I would have trust issues with the services the customer offered.

They were a provider for other customers with high security requirements (this is Europe, so the GDPR is very much in effect here) and they apparently had contracts with those customers that the drives were not to be re-introduced into the market in any way.

Re: Millions of usable hard drives are being destroyed

#146

I've had this argument til I'm blue in the face. 1. Nuke the key and an encrypted drive is indistinguishable from noise. 1a. When SAN sizes get STUPIDLY LARGE, miltiple writes are cost and energy prohibitive, crushing is cheap, cert revocation is cheaper and leaves a device with residual value. 2. In the datacenter, data at rest is not a target, the attack happens higher up the stack where the OS/SQL/App can read the…

How do you "nuke" the key? It may still be on the drive (or other drives, or magnetic tape backups).

I'm going to trust the storage manufacturers when they offer a secure erase function that it whole disk encrypts, and secure erase removed the decrypt keys everywhere they exist. It's a conversation you have when you establish the vendor, and they're the ones that own the risk (fiancial, reputational, etc) if it turns out the key is stored in plain text on ring 0, sector 0, disk 0 and someone talks about it at Defcon.

The point is: I'm tired of 'well what if?'...that comes up EVERY time there's a question about data destruction....'we should shred it "just to be sure"' is stupid.

Re: Millions of usable hard drives are being destroyed

#147
post #125

Earlier quoted context omitted.

If I can store drive encryption keys on a HSM in my old, consumer grade laptop, I would hope that large storage systems have at least the same degree of protection.

But if that HSM module or machine suddenly dies, the system would lose all the customer's files. Not good.

That's when you fall back to your backup processes....you HAVE backup processes, don't you? (They're resilient against ransomware, aren't they?)

Re: Millions of usable hard drives are being destroyed

#149
post #82

Earlier quoted context omitted.

A read/write head does not follow precisely the same path every time. It has a positioning error that makes subsequent reads/writes take place slightly offset from earlier ones. With the proper equipment and expertise (and helped out by the error correction mechanisms), you can recover a substantial amount of data that has been "overwritten" on an existing track. This is why "data shredding" applications erase the ol…

That's theoretical only. Nobody has ever demonstrated that since the theory started and now hdd complexity and density has increased dramatically.

I had to check with some experts on this that I know, to make sure that I wasn't talking nonsense.

I wasn't, exactly, but I also wasn't correct in the modern day. Retrieving erased information from hard drives like this was certainly a thing (a thing that I myself have seen done, so I know first-hand).

However, after hard drives moved beyond MFM it stopped really being possible.

So what I was saying isn't wrong, exactly, but certainly isn't relevant to today's hardware.

Re: Millions of usable hard drives are being destroyed

#150

Earlier quoted context omitted.

But if that HSM module or machine suddenly dies, the system would lose all the customer's files. Not good.

That's when you fall back to your backup processes....you HAVE backup processes, don't you? (They're resilient against ransomware, aren't they?)

But parent said to "nuke" the encryption key. :shrug:
Post reply on HN