A joint project of Law Technology News and Law.com Legal Technology

LTN Law.com

« Rule 502, where are you? | Main | Don't Forget the iPhone »

January 17, 2009

Told Ya So!

Smug2 Back in April of 2008, I wrote here that a single overwriting pass was sufficient to obliterate hard drive data, and that the stories of post-wipe data recovery were preposterous--the stuff of urban legend.  I put my money where my mouth was and offered a new iPod to anyone who could prove me wrong.  No one ever did, but maybe no one cared enough to try.

Well, I'm happy to report that my friend, Dave Kleiman, and colleagues, Craig Wright and Shyaam Sundhar, definitively proved that multipass erasure is a waste of time, and that one good pass is more than sufficient to protect data from recovery despite heroic efforts.

I'd scoffed at the notion of using magnetic force microscopy (MFM) to achieve practical recovery of single-pass overwritten data, and so I'm pretty pleased that some smart folks have tried to to use MFM to do just that and proven that it's a dead end. 

The outcome in their words: "In many instances, using a MFM to determine the prior value written to the hard drive was less successful than a simple coin toss," concluding, "The fallacy that data can be forensically recovered using an electron microscope or related means needs to be put to rest." 

I couldn't have said it better myself--oh, wait, wait, that's exactly what I DID say a year ago!  Please forgive the smug "I told you so," but when a blind hog stumbles upon an acorn, it's only right to wallow around a bit!

You can read more here.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8345280a669e2010536d0dae7970b

Listed below are links to weblogs that reference Told Ya So!:

Comments

Ralph Losey

Interesting article. Looks like you made a great call.

But how do you explain DOD requirements? Plus all those experts that go around saying a ledge hammer is the only way to be sure data is gone. Popular delusions, yes? But DOD delusions too? You would think our military would know something, but perhaps that is why military intelligence is considered an oxymoron.

Craig Ball

Hi Ralph:

By "DOD Requirements," I assume you're referring to the matrix set out in the National Industrial Security Program's Operating Manual (DoD 5220.22-M) which used to dictate that hard drives be sanitized by, inter alia, overwriting all addressable locations with a character, its complement and a random value?

I could say that 5220.22-M is correct for the same reason that 3 oz. of toothpaste poses no threat to aviation security whereas 4oz. requires seizure and suspicion. Fear is ignorance's greatest ally. Or, as Bertrand Russell said, "Neither a man nor a crowd nor a nation can be trusted to act humanely or to think sanely under the influence of a great fear."

Instead, I'll note that the 5520.22-M matrix emerged at a time in the early 1990's when data remanence was a more plausible concern. You'll recall that the areal density of early 90's hard drives was vastly different than today. Further, we hadn't completed the jump from stepper motors to servos so ghost track remanence was a more plausible concern. And remember, in the early 1990's, magnetoresistive heads were not in wide use, so the capacities of consumer drives were still being measured in megabytes. Explosive growth in areal density and ubiquitous use of servo tracking by voice coil actuators changes everything. 5520.22-M still has to deal with old equipment. But just because the government takes away your toothpaste doesn't make it dangerous.

Post a comment

If you have a TypeKey or TypePad account, please Sign In.





An Affiliate of the Law.com Network

From the Law.com Newswire

Sign up to receive Legal Blog Watch by email
View a Sample


Subscribe to this blog's feed

PODCAST: Law Technology Now

Monica Bay

In this new monthly podcast, editor-in-chief of Law Technology News Monica Bay interviews key experts of the legal technology community on top issues confronting the legal profession.

Go to Podcast

RSS Feed: LTN Podcast

Monica Bay's Law Technology Now Podcasts are also available as an RSS feed.

Go to RSS Subscribe page




August 2010

Sun Mon Tue Wed Thu Fri Sat
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30 31        

Blog Directory - Blogged