WhiteCanyon.com

 

Erase Files: Hard Drive Data Fall

How to Effectively Erase Files

US CERT
Cyber Security Tip ST05-011
by Mindi McDowell and Matt Lytle

Before selling or discarding an old computer, or throwing away a disk or CD, you naturally make sure that you've copied all of the files you need. You've probably also attempted to erase files so that other people aren't able to access personal information. However, unless you have taken the proper steps to make sure the hard drive, disk, or CD is erased, people may still be able to resurrect those files.

Where Do Erased Files Go?

erase files completely When you erase files, depending on your operating system and your settings, it may be transferred to your trash or recycle bin instead of actually erasing files. This "holding area" essentially protects you from yourself—if you accidentally erase files, you can easily restore them.

However, you may have experienced the panic that results from emptying the trash bin prematurely or having a file seem to disappear on its own.

The good news is that even though it may be difficult to locate, the file is probably still somewhere on your machine. The bad news is that even though you think you've erased files, a computer hacker or other unauthorized person may be able to retrieve it.

What Are The Risks?

Think of the information you have saved on your computer. Is there banking or credit card account information? Tax returns? Passwords? Medical or other personal data? Personal photos? Sensitive corporate information? How much would someone be able to find out about you or your company by looking through your computer files?

Depending on what kind of information an attacker can find, he or she may be able to use it maliciously. You may become a victim of identity theft. Another possibility is that the information could be used in a social engineering attack. Attackers may use information they find about you or an organization you're affiliated with to appear to be legitimate and gain access to sensitive data (see Avoiding Social Engineering and Phishing Attacks for more information).

Can You Erase Files By Reformatting?

Reformatting your hard drive or CD may superficially erase files, but the information is still buried somewhere. Unless those areas of the disk are effectively overwritten with new content, it is still possible that knowledgeable attackers may be able to access the information.

How Can You Be Sure to Completely Erase Files?

Some people use extreme measures to erase files, but these measures can be dangerous and may not be completely successful. Your best option is to investigate software programs and hardware devices that claim to erase files on a hard drive or CD. Even so, these programs and devices have varying levels of effectiveness for erasing files. When choosing a software program to perform this task, look for the following characteristics:

Erase files permanently
  • Data is Overwritten Multiple Times - It is important to make sure that not does it erase files, but new data is written over it. By adding multiple layers of data, the program makes it difficult for an attacker to "peel away" the new layer and get to your erased files. Three to seven passes is standard and sufficient.

  • Use of Random Data - Using random data instead of easily identifiable patterns makes it harder for attackers to determine the pattern and discover the original information underneath.

  • Use of Zeros in the Final Layer - Regardless of how many times the program overwrites the data, look for programs that use all zeros in the last layer. This adds an additional level of security to erase files.

While many of these programs assume that you want to erase an entire disk, there are programs that give you the option to erase and overwrite individual files.

An effective way to ruin a CD or DVD is to wrap it in a paper towel and shatter it. However, there are also hardware devices that erase CDs or DVDs by destroying their surface. Some of these devices actually shred the media itself, while others puncture the writable surface with a pattern of holes. If you decide to use one of these devices, compare the various features and prices to determine which option best suits your needs.

WipeDrive

WipeDrive

$39.95

Completely Eliminate Hard Drive Data

  • Use before getting rid of your PC to prevent identity theft
  • Restore hard drive to "like-new" condition
Learn More Add to Cart