Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security FullDisclosure
[Top] [All Lists]

Re: [Full-disclosure] Secure Delete for Windows

Subject: Re: [Full-disclosure] Secure Delete for Windows
Date: Tue, 17 Jan 2006 17:15:55 -0500
On Tue, 17 Jan 2006 22:12:38 +0100, GroundZero Security said:

Our application has not only the DOD wiping standard, but also peter gutmanns 
algorythm 
with 38 random overwrites, which is the most secure wiping methode we know of.

Or as Peter Gutmann says himself:

  "In the time since this paper was published, some people have treated the
  35-pass overwrite technique described in it more as a kind of voodoo
  incantation to banish evil spirits than the result of a technical analysis of
  drive encoding techniques. As a result, they advocate applying the voodoo to
  PRML and EPRML drives even though it will have no more effect than a simple
  scrubbing with random data. In fact performing the full 35-pass overwrite is
  pointless for any drive since it targets a blend of scenarios involving all
  types of (normally-used) encoding technology, which covers everything back to
  30+-year-old MFM methods (if you don't understand that statement, re-read the
  paper). If you're using a drive which uses encoding technology X, you only 
need
  to perform the passes specific to X, and you never need to perform all 35
  passes. For any modern PRML/EPRML drive, a few passes of random scrubbing is
  the best you can do. As the paper says, "A good scrubbing with random data 
will
  do about as well as can be expected". This was true in 1996, and is still true
  now."

http://www.cs.auckland.ac.nz/~pgut001/pubs/secure_del.html

Attachment: pgpBf3gEPGda0.pgp
Description: PGP signature

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
<Prev in Thread] Current Thread [Next in Thread>