Live data from Hacker News

Destroyer.io

destroyer.io

1–10 of 23 posts

Re: Destroyer.io

#3
post #2

Cool idea, but how do we know that destroyer.io itself is not an elaborate phishing front?

It would be great if you could pay an additional $10 and get a video confirmation of the destruction (they could start with a closeup zoom on the serial number).

Re: Destroyer.io

#5
post #2

Cool idea, but how do we know that destroyer.io itself is not an elaborate phishing front?

Yup, you could add "0. Make drive image for NSA" without altering the rest of the process. If you need that amount of security, you should probably destroy your own drives.

Re: Destroyer.io

#7
> Does it comply with HIPPA?

If they can't be arsed to spell-check "HIPAA", I'm not entirely convinced that I should be trusting them to maintain HIPAA compliance if I decide to send them drives that potentially contain patient data.

That is, unless they're instead shouting about complying with sand crabs, though I'm still concerned in either case.

> The easiest way to destroy your hard drive.

You mean other than nuking it with DBAN or shred and then taking a hammer to it and/or burning it in a fire?

> Same methods, machines and processes used by banks and recommended by the NSA

Yeah, because banks and the NSA are obviously bastions of trustworthiness.

> Place the sealed box in any UPS dropbox or schedule a free pick-up.

This seems to be a rather significant point of potential failure. While I certainly like UPS better than the USPS (or - God forbid - FedEx), I'm not inclined to go with this approach rather than take drives to a local data destruction facility and/or destroy them myself.

If you're going to send me a box, it had damn well better be one with a good locking mechanism and some measure of tamper resistance and/or evidence. Even that's not surefire, but it's sure as hell better than "here's a cardboard box; trust us, it's secure enough".

The idea's cute and creative, but when it comes to things like EHRs and such that require absolute confidentiality and security to a degree that would make top-notch military agencies and veteran cryptonerds blush, neither "cute" nor "creative" are good selling points.

Re: Destroyer.io

#8
post #6

The chat with us thing covers my entire phone's screen, I saw pictures of hard drives before that activated.

Hi, hope you're doing well!

What phone are you using? There might be a bug, and I'd like to fix it.

Here's a screenshot of what it looks like on my iPhone 5: http://destroyer.io/chat-screenshot.png

The chat box should be at the bottom right hand side of the screen.

Let me know and I'll get on it. Thanks!

PS: Just noticed there's another HN thread on Destroyer.io, I had posted one, and had been answering questions, here - https://news.ycombinator.com/item?id=8074934

Re: Destroyer.io

#9
post #2

Cool idea, but how do we know that destroyer.io itself is not an elaborate phishing front?

Hi, sorry for the late response. I was just tipped about this HN thread, I had posted one, and had been answering questions, here - https://news.ycombinator.com/item?id=8074934

I've answered your same questions a couple of times today, here's what I've been saying:

Great question. Naturally, most of the inquiries or concerns around this service are going to revolve around trust and security.

The obvious and straight forward answer is that we're not. The more complicated one would be that I'd break a large amount of serious laws if we were doing something like that.

When testing the service out, some users asked for further assurance. The solution that seemed to be liked the most involved a video feed (or pictures), that showed how we opened the package, removed the drive and destroyed it. That's something that we'd build down the road if I get enough requests or feel that it would move the needle in the right direction.

For now, here's what we do: receive the drive, degauss (demagnetize) it, destroy it. The customer is notified when the package arrives and when the drive is destroyed, at which point we send a certificate of destruction.

Also, we'm in the process of getting our NAID AAA, eStewards, R2 and ISO 14001 certifications. The machines and processes that we use follow all of their guidelines, it's just a matter of getting approved (and paying the fees).

Let me know if you have any other ideas on how we could show/proof that we're trustworthy. Interested in listening to any suggestions.

Re: Destroyer.io

#10
post #3
post #2

Cool idea, but how do we know that destroyer.io itself is not an elaborate phishing front?

It would be great if you could pay an additional $10 and get a video confirmation of the destruction (they could start with a closeup zoom on the serial number).

Hi, I'm Alex, founder of Destroyer.io. I was just tipped about this HN thread, I had posted one, and had been answering questions, here - https://news.ycombinator.com/item?id=8074934

Yes, that's a great idea, and it's the next step. We plan on having a live video feed of our facility. We also want to record how each order is destroyed, and show the drive owner see how we destroyed their drive.

The site was just opened up today. As we grow and get feedback, we'll adapt and add more features to our service.

Post reply on HN