• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

hdd wipe n security

tra77

n00b
Joined
Sep 17, 2005
Messages
12
have a quick question maybe u guys can help

Im looking for a program like this if there is one....

ok I turn pc on and have to enter password, if i enter wrong password so many times a hdd wipe accours.....

I had a program like this a few years ago but it did not do the hdd wipe,

so is there any new programs that can do this?
 
ne1 or is there nothing out there,


is there any other forums that might have the answer?
 
This would need to be a BIOS-level thing, or as part of your MBR (master boot record). Either way, it seems like a very un-common feature (outside of the FBI/CIA/NSA).
 
Let me guess, you saw that TV show about that FBI criminoligist dude where the suspect guy had this program called "Deadbolt" or something? I seem to recall there being DOS batch scripts that would do something like this back in the day, but haven't researched it since then. I'd imagine you could find something. Now you've piqued my curiosity.. Maybe I'll report back here if I find something.
 
Programs like this are essentially useless now anyway - when you delete something or even format a disk it still leaves traces that are often recoverable even after multiple passes. The most effective destoyer of disks is a utility called Gdisk which comes with the Symantec Ghost application. It is dos based and can be launched via a batch file from a bootable floppy.

Even with a "dod wipe" using gdisk, which writes a pattern across the disk seven times over a period of about a day (depending on the size of the disk) and is very hard to recover data from; It is still possible, just more difficult.

But honestly if you're doing something that you're that afraid about being found out or leaving evidence, you really should stop and think about what it is you're actually doing and whether it is worth the risk.
 
Orinthical said:
But honestly if you're doing something that you're that afraid about being found out or leaving evidence, you really should stop and think about what it is you're actually doing and whether it is worth the risk.

Also echoing what Orinthical said and by the the time someone is sitting in front of your computer and trying to type in a password, you have already lost the game. Ownership of the physical media is ownship of the data. Only way to prevent (slow down) the reading of the data is to encypt it.
 
Since you are so paranoid, perhaps you could rig some thermite up to a trigger to slag your whole PC when the Feds come knocking; that'd be the quickest (and likely most effective) way to erase all your kiddie porn/0-day warez/downloaded movies.
 
Flint,

I like your 'no-bs' approach to the subject. You dared to speak what I could only think to myself :)
 
Flint,
What I think you are reffering to is low level formatting the drive. It's not done on modern systems/drives, many people confuse 0-filling a drive=low level formatting it, they are wrong.

Orinthical, useless? Ever hear of sensitive data? Don't need to be a criminal to have that, every public company has sensitive data on many-many-many PCs.

I'll agree that even multiple wiped (DOD method) isn't 100%, but it keeps even the more dedicated data theifs away. Why rob a bank w/ a nice security system, when you can get the same out of the trash bin, literally.

Don't think so? I'll ship you a drive, and you tell me the last uesr to log on. If you can easily read the data you will have piqued my curiosity. I'd be very interested to know how easy it is to read a drive that has been wiped with random data 7+ times.

I would suggest using DBAN, Darik's boot and nuke on the ultimate boot CD, link in sig.
 
I don't think Flint was suggesting that secure deletion of de-comissioned hard disk drives was a 'useless' task. However, what the original poster was asking for was a virtual 'hard disk booby trap', like the one I saw on TV the other day. I think Flint summed up very well what kind of person needs that sort of thing, outside of the national security/intelligence/terrorism/counter-terrorism communities.

Secure deletion of decomissioned or discarded magnetic media is an important thing to do, especially if you work with sensitive information. I'm certainly not debating this. It should be part of every organizations information security policies regarding confidentiality of data and some privacy legislation, depending on where you reside and what industry you operate in, require this.
 
Well I don't think what the OP is asking for exists. You might be able to create something based on the utility I mentioned, but if I have disk in hand I could bypass that.

The best alternate is EFS, don't have the key+user/pass=screwed. Sure it *can* be cracked, but in reality, the data is pretty secure, even when physical security has been compromised.
 
Phoenix86 said:
Orinthical, useless? Ever hear of sensitive data? Don't need to be a criminal to have that, every public company has sensitive data on many-many-many PCs.

I'll agree that even multiple wiped (DOD method) isn't 100%, but it keeps even the more dedicated data theifs away. Why rob a bank w/ a nice security system, when you can get the same out of the trash bin, literally.

Don't think so? I'll ship you a drive, and you tell me the last uesr to log on. If you can easily read the data you will have piqued my curiosity. I'd be very interested to know how easy it is to read a drive that has been wiped with random data 7+ times.

I would suggest using DBAN, Darik's boot and nuke on the ultimate boot CD, link in sig.

Hey Phoenix, I deal with sensitive information all of the time - but by reading the OP's message do you really think that was the concern? That is beside the point really, thankfully the organization I work for/with knows that the only way to 'secure' data is to run the hard drive through a metal shredder.

As for how easy it is, why the e-penis competition? But to answer your question it is about as simpe as putting the drive in a working windows (or linux) machine and running one of several good data recovery programs. The data may never be whole again and in some cases the data you get back after seven wipes may not even be coherent enough to be usable - but we have restored data from DoD wipe disks in the past. Hence the need for a metal shredder. =)

Let's not compare how big our e-schwartz's are, frankly I don't care.

The OP's best bet would be to look for an encryption device - I've seen some that can plug into the IDE chain and use a simple hardware engine to encrypt the contents of the drive. If the key/passphrase/etc isn't entered correctly then you cannot access the drive. It doesn't wipe the drive, it simply won't let you in. Is it defeatable? Most definately... but it's about as close as I think the OP will find to what he/she is seeking.

There is of course PGP disk encryption or various other software based disk encryption programs, like SafeHouse, as well.

------------------------------------
Edit: Here are some links to so-called hardware-based hard drive encryption systems. I have not used any of these personally but they look pretty nifty. Sucks if that little USB key ever dies on you though. =/

http://www.firewiremax.com/fire-wire-1394-ilink/securedisk.html
http://www.firewiremax.com/fire-wire-1394-ilink/hahadienidem.html
http://www.cooldrives.com/encrypted-ide-hard-drive-mobile-rack.html

Of course this tech from Seagate sounds pretty nifty as well:

http://www.seagate.com/cda/newsinfo/newsroom/releases/article/0,,2732,00.html
 
Orinthical said:
Hey Phoenix, I deal with sensitive information all of the time - but by reading the OP's message do you really think that was the concern? That is beside the point really, thankfully the organization I work for/with knows that the only way to 'secure' data is to run the hard drive through a metal shredder.

As for how easy it is, why the e-penis competition? But to answer your question it is about as simpe as putting the drive in a working windows (or linux) machine and running one of several good data recovery programs. The data may never be whole again and in some cases the data you get back after seven wipes may not even be coherent enough to be usable - but we have restored data from DoD wipe disks in the past. Hence the need for a metal shredder. =)

Let's not compare how big our e-schwartz's are, frankly I don't care.
It's OK, you don't know me, I'm not that kind of poster. You shouldn't assume either.

I think we both know where the OP is coming from with that kind of question. ;)

I'm curious for my companies data protection, no need to compare e-peni for that, right? :)

Currently I use DBANs DOD wipe 7 times. I want to know if that's recoverable, or how easy it is to recover the data. Heck, I might recommend shredding the platters, it's much faster anyways.

I haven't been able to recover anything with standard recovery utilities, what do you suggest? Have you actually recovered data on a drive that's been wiped multiple times?

I agree encryption is the solution, whatever the method. That seagate link is interesting. :)
 
Back
Top