More

Featuring fresh takes and real-time analysis from HuffPost's signature lineup of contributors
HuffPost Social Reading
Robert Siciliano

GET UPDATES FROM Robert Siciliano
 

I Found Your Data on That Used Device You Sold

Posted: 03/ 1/2012 9:46 am

Over the past 15 years, the increasingly rapid evolution of technology has resulted in new computers or mobile phones becoming outdated in a matter of one or two years. Chances are, you've gone through no less than ten digital devices in the past decade, if not more. It has become standard practice to upgrade to a newer device and often sell, donate, or discard the old one. Or you've received a new computer or mobile phone for a holiday gift and need to get rid of the old one.

What did you do with all of your old devices? Some may be in your basement, others were given away, and you might have hocked a few on eBay or Craigslist. Did you know it is very likely that you inadvertently put all of your digital data in someone else's hands if you no longer have the device?

I recently bought 20 laptops, desktops, netbooks, notebooks, tablets, Macs, and mobiles through Craigslist, all from sellers located within 90 minutes of my home. Of the 20, three of them had never been wiped, meaning that I bought the devices exactly as they once sat on someone's desk. The original owners had made no effort to clean out the data, which meant that I was able to access the records of their entire digital lives. Seventeen of the devices had been wiped, meaning that the seller took the time to reformat or reinstall the operating system. Of the 17 wiped drives, seven contained remnants of the previous users' digital lives. Despite the effort made to reformat or reinstall the operating systems, there were partitions and leftover data on the drives.

After having spent the past few months working with a forensics expert, I've come to the conclusion that even if you wipe and reformat a hard drive, you may still miss something. IT professionals tasked with data destruction use "wiping" software, and you can too. But after what I've seen, more needs to be done. This means external and internal drives, thumb drives, SD cards, and anything else that stores data really should be destroyed.

So whether you destroy an unwanted drive with a sledgehammer, or use a drill press to turn it into Swiss cheese, or use a hack saw to chop it into pieces, and then drop those pieces into a bucket of salt water for, oh, say a year, just to be safe, for your own good, don't sell it on eBay or Craigslist.

Robert Siciliano is an Online Security Evangelist to McAfee. See him discussing identity theft on YouTube. (Disclosures)

 

Follow Robert Siciliano on Twitter: www.twitter.com/RobertSiciliano

 
 
  • Comments
  • 9
  • Pending Comments
  • 0
  • View FAQ
Comments are closed for this entry
View All
Favorites
Recency  | 
Popularity
photo
PenguinLinux
got root ?
03:52 PM on 03/02/2012
Just use dd and urandom the hard drive.
photo
PenguinLinux
got root ?
03:38 PM on 03/02/2012
This is your friend:

root@machine:-name:# dd if=/dev/zero of=/dev/sda bs=16M

( You could also throw urandom in there for extra measure. )

I personally physically destroy the hard drives by tossing them into a drive shredder. End of story. No one gets my drives.
photo
DRaymond
Network administrator, voiceovers
01:15 PM on 03/05/2012
Presuming of course that you have installed Linux on the machine.   That is where something like Darik's Boot and Nuke work so well, because it boots a Linux kernel strictly off the optical drive the disk itself can have any OS and is fully available for wiping.  Why physically destroy a perfectly good hard disk unnecessarily?
photo
DRaymond
Network administrator, voiceovers
03:27 AM on 03/02/2012
Speaking as a forensic examiner and court approved expert witness your terminology is mistaken. A wipe is different than a reformat. A wipe puts new data over the entire drive. A reformat does not. The following article describes the technique to use: http://betweenthenumbers.net/2011/03/how-to-properly-prepare-a-computer-for-sale-or-donation/
HUFFPOST SUPER USER
Draekia
Open-minded thinker and traveller
08:57 PM on 03/01/2012
I love when people post things like this as if it were one thing new.

Here's a secret: computers have been getting outdated in under a year since forever. Phones have, too.

The only difference is that the features are now out of the solely "early adopter" or "geek" realm (to a large extent) so people can get away with lazy writing like this.
01:51 PM on 03/01/2012
If you don't wipe your HD with DBAN, you're likely to get into trouble. I always wipe drives before doing an OS reinstall.

You should also routinely encrypt all your drives. TrueCrypt is free and works well.
photo
PenguinLinux
got root ?
03:40 PM on 03/02/2012
Truecrypt is great for Windows, agreed... however if you're a Linux user, no need for that since encryption is built into the OS. You just need to enable / use it. That's all.
photo
DRaymond
Network administrator, voiceovers
04:13 PM on 03/02/2012
In the same manner you can also use Bitlocker with Windows.
11:33 AM on 03/05/2012
I am not much of a home Linux guy, but when I read the install instructions for Debian it said you can't encrypt the root filesystem. Whereas TrueCrypt on Windows does allow you to encrypt the bootable C: partition.