Live data from Hacker News

Hard drive, SSD puncher of physical media with 12 tons of pressure

tomshardware.com

51–60 of 61 posts

Re: Hard drive, SSD puncher of physical media with 12 tons of pressure

#51
post #37

Earlier quoted context omitted.

Most standards (e.g. ISO 27001, NIST 800-88) do allow for physical destruction without cryptographic erasure if the device is being shredded or incinerated (to the applicable shredding/incineration standard of particulate size/temperature). Especially because cryptographic erasure is effectively pointless (at high data-sensitivity levels) if the device wasn't encrypted immediately and prior to data being written. Not…

Right, but nobody's arguing that there are cases where you'd physically destroy a device, while cryptographic erasure of the data is not required as well. I didn't explicitly say this in my original comment since it seemed implicit given the context.

>nobody's arguing that there are cases where you'd physically destroy a device, while cryptographic erasure of the data is not required as well.

I am very explicitly saying cryptographic erasure is not required if you are following physical destruction standards (in ISO 27001 and NIST 800-88, at least).

Re: Hard drive, SSD puncher of physical media with 12 tons of pressure

#52

An awful lot of the destruction can be done with a torx screwdriver: Step 1: take the screwdriver, dismantle the drive, and remove the platter(s). Step 2: take the screwdriver and gouge the platters. Step 3: take the screwdriver, lay each platter across it on the floor and stamp your foot down, hard. Destroying the metal casing is fun but it doesn’t really do an awful lot in terms of making your bits harder to read.

Destroying the metal casing means the whole disk takes about 10 seconds to destroy, and doesn't require a "stomp on a screwdriver" step that OSHA may not approve of.

Your procedure absolutely makes sense if you have a single-digit number of drives to destroy once in a while at home, not if you have to destroy dozens regularly.

Re: Hard drive, SSD puncher of physical media with 12 tons of pressure

#53
post #2

Wouldn't a standard drill press accomplish the same thing, and be a lot cheaper?

A drill press is more dangerous (rotating tools can get clothes/gloves/hair caught in them), and less effective.

Bending the platters is, in practice, irrecoverable due to the sheer amount of data that's impossible to read in any reasonable amount of time unless the platter can be rotated while keeping the reading tool aligned.

With a cleanly drilled hole, and some preparation (carefully machining out the area around the hole with precision tools), the platters would be a lot more suitable for partial data recovery.

Re: Hard drive, SSD puncher of physical media with 12 tons of pressure

#54
post #7

This reads like a press release.

Yes, I'm surprised why an advertising article for a random disk crusher (with nothing special about it as far as I can tell) is on HN.

I expected this to be an hobbyist implementation, not an ad.

Re: Hard drive, SSD puncher of physical media with 12 tons of pressure

#55
post #28

Earlier quoted context omitted.

Some orgs crush entire computers, so crushing just the drives is at least better than that.

Never heard or seen this. Who? And why?

Because it's very very hard to ensure modern computers dont have storage integrated into some unexpected part. UEFI on board can have a pretty significant amount of storage. All kinds of other devices can have storage in them too. Rather than ensure everything has been erased, they grind up the whole thing.

Re: Hard drive, SSD puncher of physical media with 12 tons of pressure

#56
post #12
post #4

Earlier quoted context omitted.

Depending on your threat model, a drill isn't even the right tool. This will significantly complicate data recovery and render data where the drill impacts it destroyed, but it will in theory still be possible to decap/analyse platters or nand with a SEM microscope and reconstruct data off the surviving parts of the storage medium. The cost may not be worth it even to some state actors, but such a cost is peanuts to…

Would thermite be enough?

Some number of years ago there was someone that built a smelter and melted down the drives. Not sure everything melted but getting anything glowing hot demagnitizes it.

Re: Hard drive, SSD puncher of physical media with 12 tons of pressure

#57
post #45

I hate to imagine how much ewaste is produced from destroying these drives, rather than simply wiping them and reselling them as refurbs.

If there's even theoretical possiblity to recover even a piece of customer data you're risking your entire existence. Serious companies don't wanna do that

The feasability is the same whether you crush a drive or erase it normally. A serious company would worry about the people who are inside your network reading the live drives, not campfire scare stories about drives magically remembering previous values.

Drives are extremely dense. If there were any way to store a value and still have any remnants of the old one, we would have slapped an error-correcting code on it and used that effect to double drive density.

Companies who believe in this magical spare capacity to read values that have been overwritten suffer from an entirely irrational fear. A paranoia that there is always a possibility.

The actual, non-theoretical possibility of recovering customer data is those companies being hacked by bored teenagers or everyday ransomware. Not empty drives.

Re: Hard drive, SSD puncher of physical media with 12 tons of pressure

#58
post #17

Earlier quoted context omitted.

I don't know, personally, I would be very unhappy if someone stole my server and then starts blackmailing me to reveal private information somewhere (unless I pay a certain sum). I don't have anything to hide, but I still don't want my private information public. I don't need to mind about this with encrypted data.

> I don't need to mind about this with encrypted data. I'm not sure if I wasn't clear or if you didn't read my comment correctly. Encrypting is not enough to prevent data recovery if data was written to disk prior to encrypting it. In other words, if you want to be 100% sure about your data being safe, you must encrypt first (when the drive is brand new), or you must physically destroy the drive.

Yes, I understood - but this has nothing to do with encryption. Data that is encrypted is save. Any data that is not encrypted (or was not encrypted) would offer an attack surface. Since I use ZFS for all my data, all my data is encrypted from Minute 1 of a new hard drive.

Re: Hard drive, SSD puncher of physical media with 12 tons of pressure

#59
post #57
post #45

Earlier quoted context omitted.

If there's even theoretical possiblity to recover even a piece of customer data you're risking your entire existence. Serious companies don't wanna do that

The feasability is the same whether you crush a drive or erase it normally. A serious company would worry about the people who are inside your network reading the live drives, not campfire scare stories about drives magically remembering previous values. Drives are extremely dense. If there were any way to store a value and still have any remnants of the old one, we would have slapped an error-correcting code on it a…

Its not the feasibility of reading previously erased data.

The much more simple issue, is that drives that have not been erased look exactly like drives that have been erased. Does the drive contain data? Who knows until you hook it up to a computer.

Meanwhile It's very easy to distinguish a drive that has been crushed and can be e-wasted, from a drive that has not been crushed, and can't be e-wasted.

Post reply on HN