Discoveries Blog Horizons Blog

Read this before you sell or recycle your computer!

Even rocket scientists forget to wipe their hard drives. Here’s how to do it.

By Gregory M. Lamb  |  Staff Writer for The Christian Science Monitor/ June 11, 2009 edition

Rich Clabaugh/Staff


Last month, researchers in Britain decided to find out if people left anything behind when they sold or donated their old computer. They bought 300 used machines in several countries and from a number of sources, including eBay.

What did they find? About one-third still contained personal data on the hard drives, data that was located with just a little digging. Among the items rooted out: the test-launch information for THAAD ground-to-air defense missiles; medical records from hospitals; Social Security numbers; and proprietary commercial documents, such as business plans.

The disturbing conclusion: Even large organizations, which have legal obligations to protect their data, are sometimes lax about removing them thoroughly from discarded computers.

What about average home users?

The biggest mistake they make, experts say, is to assume that files are gone from the hard drive once they’ve been placed in the trash bin and deleted. “The actual data remains intact on the hard drive. There are programs available designed to find this data and easily re-create the original information,” explains Michael Helander, a spokesman for Lavasoft, a Swedish software security firm, in an e-mail.

To really erase all personal data from a hard drive, users have two choices: The first involves software; the second, elbow grease.

A number of free programs will do a good job of thoroughly erasing a hard drive, says Ben Rothke, a senior security consultant in the professional services division of BT (British Telecom), and the author of “Computer Security: 20 Things Every Employee Should Know.”

Mr. Rothke likes the popular open-source program Darik’s Boot and Nuke (DBAN), found at www.dban
.org. Among the commercial data-erasing products is iolo technologies’ DriveScrubber (a one-year service plan is $20.97) which you can find here.

Those who want to remove data selectively – say, keep the operating system and a few programs – could use a product such as Lavasoft File Shredder (one-year license: $29.95). “This program lets the user shred all free disc space in one easy step,” Mr. Helander writes. The user can select what data he wants deleted. Afterward, “no personal information will remain on the hard drive and the user will be able to securely sell or give the computer away.”

Two things that don’t work, experts say: formatting or partitioning the hard drive. The data may get pushed around a bit, but it remains, even if Windows warns you that all data will be erased.

What’s the elbow-grease method? Open up the computer, take out the hard drive, and smash it several times vigorously with a hammer, Rothke says. (Goggles and gloves are a good idea.) Make sure you hear some satisfying crunching sounds from the interior.

Opening up a machine and removing the hard drive isn’t too difficult, Rothke says. Just keep in mind that CD-ROM drives can look like hard drives. “You have to make sure you’re destroying the right thing,” he says.

( More stories )

Comments

1. Alan Ross | 06.12.09

You can also use a hard drive shredder to physically shred the drive into scrap metal for the ultimate in data security

http://www.rossmach.com

2. Sonia Schenker | 06.15.09

Mr. Rothke’s hammer method will render the drive useless, but doesn’t answer the question - what do I do with the drive now? Hard drives are made from recyclable material. If you don’t need to use it as a doorstop, you can recycle it for free with Back Thru The Future Technology Disposal in Ogdensburg, NJ. Free hard drive reycling is not a secure service (which is available for a fee), but it offers a free green solution to disposing hard drives that have no security issues.

3. Ted Caliouette | 06.19.09

You can always send me your hard drive(s) or entire computer. I will destroy it for you by putting a hole through the platters. If requested, I will mail you a certificate of destruction. No charge for the service.

4. Margaret | 06.23.09

You can also use this as a learning exercise. I extracted the hard drive, took it to pieces (really to see how it worked and to see how far into the drive I could get)… I now have a unique “sculpture” made up of the very strong magnets inside the drive, a scultpure which can be changed at whim. The grandchildren are fascinated!

5. Andy Hoffman | 06.27.09

A much simpler and commonly used method by most tech savvy IT pro’s, is to simply drill a hole through the drive itself rendering it useless to most people. Of course there are data recovery specialists who may be able to retrieve some of it’s data after it had been drilled, but that would require an expensive operation where the platters would need to be removed. The new solid state drives could also be rendered useless in this manner. Most people are not aware that as you use a solid state drive over time it becomes more and more prone to data errors, even more so than current sputtered platter technology. The only advantage to a solid state drive is the resistance it has to shock.

Trackbacks/Pingbacks

Leave a Comment

  By clicking "Submit Comment", you agree to our Terms of Service.

We do not publish all comments, and we do not publish comments immediately. The comments feature is a forum to discuss the ideas in our stories. Constructive debate - even pointed disagreement - is welcome, but personal attacks on other commenters are not, and will not be published.

Tip: Do not write a novel. Keep it short. We will not publish lengthy comments. Come up with your own statements. This is not a place to cut and paste an email you received. If we recognize it as such, we won't post it.

Please do not post any comments that are commercial in nature or that violate copyrights.

Finally, we will not publish any comments that we regard as obscene, defamatory, or intended to incite violence.