Bugtraq mailing list archives

Peter Gutmann data deletion theaory?


From: "Jared Johnson" <jaredsjazz () Yahoo com>
Date: Wed, 20 Jul 2005 19:48:44 -0400

All,

Do you all agree with Peter Gutman's conclusion on his theory that data can
never really be erased, as noted in his quote below:

"Data overwritten once or twice may be recovered by subtracting what is
expected to be read from a storage location from what is actually read. Data
which is overwritten an arbitrarily large number of times can still be
recovered provided that the new data isn't written to the same location as
the original data (for magnetic media), or that the recovery attempt is
carried out fairly soon after the new data was written (for RAM). For this
reason it is effectively impossible to sanitise storage locations by simple
overwriting them, no matter how many overwrite passes are made or what data
patterns are written. However by using the relatively simple methods
presented in this paper the task of an attacker can be made significantly
more difficult, if not prohibitively expensive."

It seems that the perhaps the only real way to rid your Hard Drives of data
is to burn them. 

I'd love to hear some thoughts on this from security and data experts out
there.




Current thread: