Federal Charges Against Stanford University Researcher Expanded
11–20 of 97 posts
Re: Federal Charges Against Stanford University Researcher Expanded
#12The superseding indictment alleges that she then attempted to delete a digital folder of documents on an external hard drive that she possessed containing records relating to her military service and visa fraud, including: - A digital version of a letter from Song, written in Chinese and addressed to the People’s Republic of China consulate in New York, in which Song explained that her stated employer, “Beijing Xi Di…
Follow up question, as someone who knows even less about forensics, what kind of traces stay on a hard drive if you just delete a file?
Re: Federal Charges Against Stanford University Researcher Expanded
#13The superseding indictment alleges that she then attempted to delete a digital folder of documents on an external hard drive that she possessed containing records relating to her military service and visa fraud, including: - A digital version of a letter from Song, written in Chinese and addressed to the People’s Republic of China consulate in New York, in which Song explained that her stated employer, “Beijing Xi Di…
Follow up question, as someone who knows even less about forensics, what kind of traces stay on a hard drive if you just delete a file?
Re: Federal Charges Against Stanford University Researcher Expanded
#14How widespread are cases like this? I'm not an expert on this topic but from reading this it feels like such an investigation is expensive and time consuming. I imagine for every person identified there must be many more whose secret affiliations with the foreign powers won't be uncovered.
I recently read somewhere that secret angencies likely watch suspects and see when they turn off their phones or when they turn them back on for example when they have a meeting. This is a good way to narrow in on other people connected to the suspect by watching their patterns.
Re: Federal Charges Against Stanford University Researcher Expanded
#15Earlier quoted context omitted.
Follow up question, as someone who knows even less about forensics, what kind of traces stay on a hard drive if you just delete a file?
A lot. You need to write a drive with zeros(minimum)/random data(preferably) at least once to make forensic recovery difficult. I know all about the "5 times" rule, but I've never heard of anyone recovering a drive after even a single overwrite. Personally, I just hammer a screwdriver through the platter. It generally converts it into glass shards--the drive sounds like a maraca afterward. Flash, of course, is differ…
Re: Federal Charges Against Stanford University Researcher Expanded
#16Seems a bit racist. Israel/Finland/Germany all have universal conscription so they don't get harassed like the Chinese.
Re: Federal Charges Against Stanford University Researcher Expanded
#17Earlier quoted context omitted.
Follow up question, as someone who knows even less about forensics, what kind of traces stay on a hard drive if you just delete a file?
The file is still there. A regular delete just tells the disk that the segments of memory are available to be overwritten. Zeroing out (or /dev/urandom) the memory is an option, but even that is not 100% safe, especially when it comes to forensic labs with the ability to read and analyze platters removed from a complete, sealed disk. Really safe deleters will overwrite the segments of memory multiple times to scrambl…
You can’t transplant a platter into another reader, the old days of Guttman method don’t really apply anymore, density is so high that outside of research settings it’s just not practical.
That said I still put a drill through mine before disposing of them, because close to zero isn’t zero.
Re: Federal Charges Against Stanford University Researcher Expanded
#18Earlier quoted context omitted.
Follow up question, as someone who knows even less about forensics, what kind of traces stay on a hard drive if you just delete a file?
The file is still there. A regular delete just tells the disk that the segments of memory are available to be overwritten. Zeroing out (or /dev/urandom) the memory is an option, but even that is not 100% safe, especially when it comes to forensic labs with the ability to read and analyze platters removed from a complete, sealed disk. Really safe deleters will overwrite the segments of memory multiple times to scrambl…
No, this is completely impossible and noone has ever done it. (An exception would be HDDs with bad block mapping because they might not actually erase some sector.)
SSDs don't even have platters and you could probably recover things from the flash, but you can avoid this with disk encryption by simply losing the keys.
> Really safe deleters will overwrite the segments of memory multiple times to scramble magnetic signatures
Deletion programs do this because it looks cool. It's not necessary - literally noone has ever recovered anything from a zeroed out HD sector.
Re: Federal Charges Against Stanford University Researcher Expanded
#19Earlier quoted context omitted.
A lot. You need to write a drive with zeros(minimum)/random data(preferably) at least once to make forensic recovery difficult. I know all about the "5 times" rule, but I've never heard of anyone recovering a drive after even a single overwrite. Personally, I just hammer a screwdriver through the platter. It generally converts it into glass shards--the drive sounds like a maraca afterward. Flash, of course, is differ…
I have a few HDs with bullet holes in them, and the platters are still intact. I've messed around with a lot of drives and never shattered a disk like glass. I've heard that there's labs that specialize in reading disks without even needing to spin them, but information seems to be tightly guarded about the processes.
Re: Federal Charges Against Stanford University Researcher Expanded
#20Seems a bit racist. Israel/Finland/Germany all have universal conscription so they don't get harassed like the Chinese.