Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Peter Gutmann data deletion theaory? |
|---|---|
| Date: | Thu, 21 Jul 2005 14:07:12 -0500 |
On Wednesday 20 July 2005 18:48, Jared Johnson wrote:
Data overwritten once or twice
<snip> The quote is from 1996. I spoke with Guttman about this at AusCERT a few years ago and even *he* doesn't believe it anymore. Drive technology has changed substantially since then. The main areas where criminals get caught with bad stuff on their drives by forensics people is from 1) not knowing where the data is being written to (browser cache, swap file, etc) 2) not doing any overwrite of the data as a part of deletion, and 3) not taking into consideration such items as file slack. Drives that do caching and file systems that do journaling also may be a factor. That being said, 3 wipes are "good enough for government work". DoD 5220.22-M chapter 8 subsection 306 in the Cleaing and Sanitization Matrix shows under the Magentic Disk section that to properly sanitize a non-removable rigid drive, that the choices of degaussing, destruction of the drive, or a 3 pass wipe are acceptible methods for disk sanitation. Note that the 3 pass wipe method is NOT acceptable for drives that contained Top Secret information - so unless the drive contained Top Secret material, you're covered. It should be noted that this issue has been done to death on bugtraq several times. -- # Simple Nomad, C²ISSP -- thegnome@nmrc.org # # C1B1 E749 25DF 867C 36D4 1E14 247A A4BD 6838 F11D # # http://www.nmrc.org/~thegnome/ #
pgpnzMB8tquEc.pgp
Description: PGP signature
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] [ GLSA 200507-20 ] Shorewall: Security policy bypass, Sune Kloppenborg Jeppesen |
|---|---|
| Next by Date: | Re: Re: [HSC Security Group] Invision PowerBoard 1.3.x - 2-x Exploit and Patch, [at] |
| Previous by Thread: | Re: Peter Gutmann data deletion theaory?, Thor (Hammer of God) |
| Next by Thread: | Re: Peter Gutmann data deletion theaory?, Volker Tanger |
| Indexes: | [Date] [Thread] [Top] [All Lists] |