<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>EPC's Computer Recyling Blog &#187; hard drive data destruction</title>
	<atom:link href="http://blog.epcusa.com/tag/hard-drive-data-destruction/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.epcusa.com</link>
	<description>A blog about EPC, computer recycling, data security, and other IT related mess</description>
	<lastBuildDate>Thu, 22 Jul 2010 15:49:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Data Destruction: Is One Pass Overwriting Enough?</title>
		<link>http://blog.epcusa.com/2009/03/data-destruction-is-one-pass-overwriting-enough/</link>
		<comments>http://blog.epcusa.com/2009/03/data-destruction-is-one-pass-overwriting-enough/#comments</comments>
		<pubDate>Fri, 13 Mar 2009 19:15:23 +0000</pubDate>
		<dc:creator>Brian Wahoff</dc:creator>
				<category><![CDATA[Data Security]]></category>
		<category><![CDATA[data destruction]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[hard drive data destruction]]></category>
		<category><![CDATA[hard drive wiping]]></category>
		<category><![CDATA[NIST]]></category>

		<guid isPermaLink="false">http://blog.epcusa.com/?p=10</guid>
		<description><![CDATA[There is some controversy regarding data destruction in the IT industry, some vendors claim that no software writing solution is secure, and only firmware level erasing, like Secure Erase, is certifiable. Others go further and say that only physical destruction is enough. The DoD spec calls for either a 3 pass or a 7 pass [...]


Related posts:<ol><li><a href='http://blog.epcusa.com/2010/01/5-questions-to-ask-your-data-destruction-company/' rel='bookmark' title='Permanent Link: 5 Questions to ask your Data Destruction Company'>5 Questions to ask your Data Destruction Company</a> <small>When you replace your computers, what happens to the data...</small></li>
<li><a href='http://blog.epcusa.com/2009/05/buy-a-used-hard-drive-on-ebay-get-government-secrets-for-free/' rel='bookmark' title='Permanent Link: Buy a used hard drive on eBay, get government secrets for free!'>Buy a used hard drive on eBay, get government secrets for free!</a> <small>Imagine it, you purchased a computer on eBay, plug it...</small></li>
<li><a href='http://blog.epcusa.com/2009/03/stimulus-bill-significantly-modifies-hipaa-regulations/' rel='bookmark' title='Permanent Link: Stimulus Bill significantly modifies HIPAA regulations'>Stimulus Bill significantly modifies HIPAA regulations</a> <small>Buried within the huge American Recovery and Reinvestment Act (a.k.a,...</small></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>There is some controversy regarding data destruction in the IT industry, some vendors claim that no software writing solution is secure, and only firmware level erasing, like <a href="http://advosys.ca/viewpoints/2006/07/hard-drive-secure-erase/">Secure Erase</a>, is certifiable. Others go further and say that only physical destruction is enough. The DoD spec calls for either a 3 pass or a 7 pass wipe, and NIST <a href="http://csrc.nist.gov/publications/nistpubs/800-88/NISTSP800-88_rev1.pdf">has stated</a>:</p>
<blockquote><p>Studies have shown that most of today&#8217;s media can be effectively cleared by one overwrite.</p></blockquote>
<p>Popular TV shows like Numb3rs show scientists able to recover data from drives even after they have been wiped. There are probably as many standards to wipe data from hard drives as there are companies providing solutions. When is it enough? EPC as a company has standardized on the 3 pass DoD wipe as it is well recognized in the IT industry and it is a relatively fast process.<span id="more-10"></span></p>
<p>Back in January, <a href="http://sansforensics.wordpress.com/">SANS Forensics blog</a> published an article entitled <em><a href="http://sansforensics.wordpress.com/2009/01/15/overwriting-hard-drive-data/">&#8220;Overwriting Hard Drive Data&#8221;</a></em>. SANS paper is noteworthy because it concludes that a single pass of zeros is enough to make the drive forensically unrecoverable:</p>
<blockquote><p>Although there is a good chance of recovery for any individual bit from a drive, the chances of recovery of any amount of data from a drive using an electron microscope are negligible..</p></blockquote>
<h3>What does this mean?</h3>
<p>Basically the SANS study said that unless you could guarantee where on the drive a particular set of data was stored, it was virtually impossible to rebuild that data from a wiped drive. Even if you could recover an individual bit, you would not have enough information to make usable data.</p>
<p>This study, filled with probability charts and bayesian confidence scores, probably won&#8217;t change your mind if you are really paranoid. However for those people, I recommend a certified drive shredding program like EPC&#8217;s <a href="http://www.epcusa.com/news/2009/03/your-company-data-risk/">DDRV</a>.</p>


<p>Related posts:<ol><li><a href='http://blog.epcusa.com/2010/01/5-questions-to-ask-your-data-destruction-company/' rel='bookmark' title='Permanent Link: 5 Questions to ask your Data Destruction Company'>5 Questions to ask your Data Destruction Company</a> <small>When you replace your computers, what happens to the data...</small></li>
<li><a href='http://blog.epcusa.com/2009/05/buy-a-used-hard-drive-on-ebay-get-government-secrets-for-free/' rel='bookmark' title='Permanent Link: Buy a used hard drive on eBay, get government secrets for free!'>Buy a used hard drive on eBay, get government secrets for free!</a> <small>Imagine it, you purchased a computer on eBay, plug it...</small></li>
<li><a href='http://blog.epcusa.com/2009/03/stimulus-bill-significantly-modifies-hipaa-regulations/' rel='bookmark' title='Permanent Link: Stimulus Bill significantly modifies HIPAA regulations'>Stimulus Bill significantly modifies HIPAA regulations</a> <small>Buried within the huge American Recovery and Reinvestment Act (a.k.a,...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://blog.epcusa.com/2009/03/data-destruction-is-one-pass-overwriting-enough/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
