<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: How many times to erase hard drive</title>
	<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive/</link>
	<description>Comments on Ask MetaFilter post How many times to erase hard drive</description>
	<pubDate>Mon, 08 Jan 2007 18:58:37 -0800</pubDate>
	<lastBuildDate>Mon, 08 Jan 2007 18:58:37 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: How many times to erase hard drive</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive</link>	
		<description>How many times should I zero the hard drive of a laptop I am going to sell? &lt;br /&gt;&lt;br /&gt; I have an old iBook (the display fritzed) that I am planning to sell on Ebay. I had the hard disk zeroed in a single pass. This took two and  a half hours. Because the display is not working, I had to take it to a Mac repair shop and wait. Now I am wondering about security. Should I have the hard disk zeroed again, seven times, thirty-five times?&lt;br&gt;
&lt;br&gt;
There was no financial information on the computer (Quicken, tax programs, etc.). I prefer to contemplate my dismal finances on scribbled scraps of paper. My net-surf patterns would show that I sometimes visit websites with encrypted pages for buying on-line; I have an Ebay account, etc. &lt;br&gt;
&lt;br&gt;
I hope that nobody is interested in my journal, fanfic, or academic papers and manuscripts.</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2007:site.54639</guid>
		<pubDate>Mon, 08 Jan 2007 18:51:16 -0800</pubDate>
		<dc:creator>bad grammar</dc:creator>
		
			<category>iBook</category>
		
			<category>hard</category>
		
			<category>drive</category>
		
			<category>disk</category>
		
			<category>erase</category>
		
			<category>zero</category>
		
	</item> <item>
		<title>By: IndigoRain</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822689</link>	
		<description>Well, it depends on who gets hold of your old hard drive.  I&apos;d say the average user these days wouldn&apos;t know how to get your old data since you overwrote it once (you did overwrite it, and not just erased it, right?)  I think the Eraser program recommends 7 times.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822689</guid>
		<pubDate>Mon, 08 Jan 2007 18:58:37 -0800</pubDate>
		<dc:creator>IndigoRain</dc:creator>
	</item><item>
		<title>By: cschneid</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822691</link>	
		<description>Zeroing is a good first step, but deletion patterns are better.  I&apos;d imagine that what you&apos;ve done is probably fine.  The question is if you have anything worth stealing on it.  If you do, you should go for another erasure, if not, what do you care.&lt;br&gt;
&lt;br&gt;
It&apos;s all about risk, and based on what you said was on it, I would say don&apos;t worry about it.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822691</guid>
		<pubDate>Mon, 08 Jan 2007 18:59:50 -0800</pubDate>
		<dc:creator>cschneid</dc:creator>
	</item><item>
		<title>By: saraswati</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822698</link>	
		<description>I think the DoD or NSA (or both?) used to recommend 7 passes as well. However, I third the idea that your data probably isn&apos;t worth the kind of effort it would take to retrieve it after a single pass.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822698</guid>
		<pubDate>Mon, 08 Jan 2007 19:07:17 -0800</pubDate>
		<dc:creator>saraswati</dc:creator>
	</item><item>
		<title>By: Zed_Lopez</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822703</link>	
		<description>&quot;In the time since this paper was published, some people have treated the 35-pass overwrite technique described in it more as a kind of voodoo incantation to banish evil spirits than the result of a technical analysis of drive encoding techniques. As a result, they advocate applying the voodoo to PRML and EPRML drives even though it will have no more effect than a simple scrubbing with random data... &lt;a href=&quot;http://dban.sourceforge.net/faq/index.html&quot;&gt;For any modern PRML/EPRML drive, a few passes of random scrubbing is the best you can do.&lt;/a&gt;&quot;&lt;br&gt;
&lt;br&gt;
Do another pass of all 1&apos;s and another pass of 0 or 1 at random and call it a day.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822703</guid>
		<pubDate>Mon, 08 Jan 2007 19:12:57 -0800</pubDate>
		<dc:creator>Zed_Lopez</dc:creator>
	</item><item>
		<title>By: polyglot</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822704</link>	
		<description>Repeated zeroing has little additional benefit over a single zeroing since it introduces no additional noise.  A low-level zeroing is good for pretty much anything short of someone disassembling the disc and applying a couple hundred $k of machinery to analysing the fields on it, so I wouldn&apos;t worry unless there is classified material on it.&lt;br&gt;
&lt;br&gt;
If you want a higher security erasure without physical destruction, you want to overwrite it with high-quality random data.  A couple passes of pseudo-random is still very good.  Repeated writing with random data makes it more difficult to analyse the content even after disassembling the drive and inspecting the fields at the sides of the tracks, which is the only approach I (an eleceng who doesn&apos;t work for NSA) knows of for dirty-tricks data recovery.&lt;br&gt;
&lt;br&gt;
If it only contains what you list on it, I wouldn&apos;t bother any further at all - assuming the computer store did the erasure correctly.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822704</guid>
		<pubDate>Mon, 08 Jan 2007 19:13:26 -0800</pubDate>
		<dc:creator>polyglot</dc:creator>
	</item><item>
		<title>By: Khalad</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822717</link>	
		<description>You&apos;re fine. Nobody&apos;s going to be going after your data with a scanning electron microscope.&lt;br&gt;
&lt;br&gt;
One of the things I work on is wiping software that declassifies servers onboard U.S. Navy submarines. And hell, we still just do one-pass wipes, which is good enough up until the time the hard drives are chucked into the incinerator, or however it is they physically destroy the drives.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822717</guid>
		<pubDate>Mon, 08 Jan 2007 19:33:04 -0800</pubDate>
		<dc:creator>Khalad</dc:creator>
	</item><item>
		<title>By: ericb</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822734</link>	
		<description>&lt;em&gt;I think the DoD or NSA (or both?) used to recommend 7 passes as well.&lt;/em&gt;&lt;br&gt;
&lt;br&gt;
Yes -- NSA is 7 passes; DOD (52202.22-M) is 3 with Guttman at 35 passes.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822734</guid>
		<pubDate>Mon, 08 Jan 2007 19:56:59 -0800</pubDate>
		<dc:creator>ericb</dc:creator>
	</item><item>
		<title>By: Osmanthus</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822749</link>	
		<description>Filesystem author here. One pass is good enough.   All that stuff about 7 passes is crazed hooey.  Promoted by semantec to sell wipe software.    Only a handful people in the whole world have the technology to recover an erased drive and they aren&apos;t going to be trying to steal some random person&apos;s drive.  The only way a theif would be able to steal your data is to pay those people thousands of dollars to do it for them and even then, they would probably get nothing.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822749</guid>
		<pubDate>Mon, 08 Jan 2007 20:25:31 -0800</pubDate>
		<dc:creator>Osmanthus</dc:creator>
	</item><item>
		<title>By: cribcage</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822768</link>	
		<description>For your circumstances, you&apos;re already beyond fine. But if you feel super-paranoid, try &lt;a href=&quot;http://freshsqueeze.com/products/iwipe/&quot;&gt;iWipe&lt;/a&gt; on its (wait for it...) &quot;Super Paranoid&quot; setting, which uses the aforementioned 35-pass Guttman method. It&apos;s shareware, but the free version will wipe free space on any setting.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822768</guid>
		<pubDate>Mon, 08 Jan 2007 20:50:01 -0800</pubDate>
		<dc:creator>cribcage</dc:creator>
	</item><item>
		<title>By: b1tr0t</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822803</link>	
		<description>Download an archive of R-rated bikini photos, and drop them on the drive. If the new owner wants to go looking for stuff, they will find the photos and be happy.&lt;br&gt;
&lt;br&gt;
All this talk of zeroing is absurd. You didn&apos;t have anything of value on your computer. Nothing about your computer would lead anyone to believe that recovering your old data is worth their time and effort.&lt;br&gt;
&lt;br&gt;
If you paid for the disk zeroing process, you got scammed. If you do it again, doubly so.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822803</guid>
		<pubDate>Mon, 08 Jan 2007 21:28:13 -0800</pubDate>
		<dc:creator>b1tr0t</dc:creator>
	</item><item>
		<title>By: i_am_joe&apos;s_spleen</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822806</link>	
		<description>To expand on Zed Lopez&apos; answer, here is &lt;a href=&quot;http://www.cs.auckland.ac.nz/~pgut001/pubs/secure_del.html&quot;&gt;Peter Gutmann&apos;s original paper&lt;/a&gt;. (Note spelling). And Zed Lopez&apos; quote is from Peter himself, who is well aware of the current state of the art.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822806</guid>
		<pubDate>Mon, 08 Jan 2007 21:31:36 -0800</pubDate>
		<dc:creator>i_am_joe&apos;s_spleen</dc:creator>
	</item><item>
		<title>By: Rhomboid</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822840</link>	
		<description>Everyone, please read Zed_Lopez&apos;s and Osmanthus&apos; comments again and stop spreading the false notion that this 35 pass baloney does anything on modern hardware.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822840</guid>
		<pubDate>Mon, 08 Jan 2007 22:25:52 -0800</pubDate>
		<dc:creator>Rhomboid</dc:creator>
	</item><item>
		<title>By: i_am_joe&apos;s_spleen</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822879</link>	
		<description>I do hope that wasn&apos;t aimed at me. I just wanted to point people at the source.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822879</guid>
		<pubDate>Mon, 08 Jan 2007 23:48:19 -0800</pubDate>
		<dc:creator>i_am_joe&apos;s_spleen</dc:creator>
	</item><item>
		<title>By: Zed_Lopez</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#822896</link>	
		<description>I counseled doing a couple of more passes just because you were concerned, and it couldn&apos;t hurt.... so I thought. On first reading, I missed that you&apos;d had it done at a repair shop, and presumably paid for it.&lt;br&gt;
&lt;br&gt;
I think this was worth doing, in case you had something sensitive you forgot about on the drive (in previous questions, I&apos;ve jumped up and down insisting upon the relevance of running DBAN instead of just formatting.) &lt;br&gt;
&lt;br&gt;
But I&apos;ve got to agree with everyone who&apos;s said you shouldn&apos;t feel like you need to do more. It would take someone fantastically interested in your data in particular, and willing to go to ludicrous expense, to attempt to recover anything. No one&apos;s going to do that with a random hard drive.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-822896</guid>
		<pubDate>Tue, 09 Jan 2007 00:28:55 -0800</pubDate>
		<dc:creator>Zed_Lopez</dc:creator>
	</item><item>
		<title>By: damn dirty ape</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#823095</link>	
		<description>First off, zeroing the drive once will mean it will be impossible for a software-based reader to get -any- data off of that drive. Anything more than that is purely extra credit which probably has no real world use.  A lot of people do the DoD 3-pass just for kicks and for CYA. &lt;br&gt;
&lt;br&gt;
Secondly, Gutmann is usually a little misunderstood. I dont believe he recommends 35 passes. What he has done is gather 26 or so patterns which coincide with the patterns drive manufacturers use to write data on their drive.  For instance, pattern number three would coincide with old Maxtors or somesuch.  Gutmann&apos;s implementation is 35 passes because no one really knows what encoding method is on their disk, so why not do them all to be extra-super safe.  &lt;br&gt;
&lt;br&gt;
The downside to doing anything but  a zero-ing out is the time.  On a slightly older machine you may wait 45 minutes to a couple hours just to do the DoD 3-pass. Especially laptops with slow drives.  Typically you can zero a drive in well under 30 mins.&lt;br&gt;
&lt;br&gt;
Zeroing drives is easy.  Some people might benefit from using sdelete from sysinternals to wipe the free space on the drive or to securely delete a file at a time.  This is handy if youre planning on giving your computer to someone without wiping it first.  You could delete your profile and other files and just do a sdelete -z to wipe all that free space.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-823095</guid>
		<pubDate>Tue, 09 Jan 2007 07:02:09 -0800</pubDate>
		<dc:creator>damn dirty ape</dc:creator>
	</item><item>
		<title>By: damn dirty ape</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#823096</link>	
		<description>Seconding &lt;a href=&quot;http://dban.sourceforge.net/&quot;&gt;dban&lt;/a&gt;. Its free. Burn the image to a CD and off you go.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-823096</guid>
		<pubDate>Tue, 09 Jan 2007 07:03:11 -0800</pubDate>
		<dc:creator>damn dirty ape</dc:creator>
	</item><item>
		<title>By: Tacos Are Pretty Great</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#823115</link>	
		<description>Unless you are a covert agent of some sort, you are good to go.&lt;br&gt;
&lt;br&gt;
And if you &lt;em&gt;are&lt;/em&gt; a covert agent, don&apos;t sell the hard drive.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-823115</guid>
		<pubDate>Tue, 09 Jan 2007 07:26:52 -0800</pubDate>
		<dc:creator>Tacos Are Pretty Great</dc:creator>
	</item><item>
		<title>By: bad grammar</title>
		<link>http://ask.metafilter.com/54639/How-many-times-to-erase-hard-drive#823161</link>	
		<description>Thanks for the advice, people. I agree that it probably isn&apos;t worth it to repeat the zeroing. I still feel a little worried, but I must have paranoid tendencies. I should be more worried that meth addicts will steal my snail mail bills out of my mailbox.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.54639-823161</guid>
		<pubDate>Tue, 09 Jan 2007 08:16:22 -0800</pubDate>
		<dc:creator>bad grammar</dc:creator>
	</item>
	</channel>
</rss>
