Why do we need to crush the harddisk? ◦ To protect information security for corporate, customer and personal data so that when we dispose the harddisk (from system upgrade, harddisk failure, etc), there will be no one can retrieve or recover any data from the old harddisk ◦ From one of the key data earsing marketleader 2. “Socially responsible and regulatory compliant companies are concerned about protecting confidential data and reducing their environmental footprint and seek a secure, ethical and cost effective solution to erase data. Can’t we use the software disk shredder or harddisk eraser program in the market? ◦ There are many software available in the market as freeware, shareware and licensed software, most of them only reformat, and overwriting the data by 00 or FF, and some hidden area of the harddisk which the manufacturer used to store disc information cannot be accessed by such software ◦ To completely format and overwriting the hardisc based on industrial data security regulation, for 64GB volume, the time it takes is around 10-30 hours (including earsing data and reformat, then overwriting the same area by different methods repeatedly, and reformat again) ◦ From ◦ Overwriting software that are unable to erase data on the locked/hidden sectors perform an incomplete erasure compromising data security. Overwriting software that operate through the BIOS/OS perform an incomplete erasure leaving some of the data still intact Data can still be recovered by some companies (at high cost in most case) at around us$100k 3. Can we use Degausser to erase the harddisk using strong magnetic field? ◦ Yes but… ◦ Degausser is usually create very loud noise depends on the charge up power (12000 gauss/ 15000 gauss) which cause hearing safety problem for operator performing degaussing ◦ It is stated clearly in the instruction that it may cause hazardous to health, especially not suitable for person who is pregnant, with heart problem, kids, people sensitive to magnetic field; even though the people in charge may not be in this listed category, certain precaution is to be taken care of ◦ For nowadays harddisk, the writing method by magnetic field is using a vertical recording method, degausser is effective for horizontal recording in most cases ◦ CD/DVD/SSD (flash memory)/HDD with Flash cannot be erased by Degausser ◦ No physical evidence or proof that the harddisk is totally erased. Who can proof each degaussing is successful? How? ◦ If one believed degausser can erase the harddisk, the best combination will be using degausser to erase the harddisk followed by a physcial destruction ◦ Harddisk manufacturer, e.g. Segate, Hitachi, etc. didn’t disclose their trade secret that what is the required strength of Anti-Magnetic power in order the information can be completely erased ◦ Harddisk casing is getting stronger. From the point of view of harddisk manufacturer, it make sense to create such a strong anti-magentic housing in order to protect the data stored. Some harddisk can stand high gauss to ensure data securely preserved and anti magnetic ◦ Some companies can recover harddisk (even not total recovery) even they are treated by degausser: Segate Technology OnTrack DriveSaver PCKit Japan (also being nominated by APPLE Inc. as their iPhone data recovery service provider) 5. 6. Why physical destruction / crusher is necessary? ◦ Most NSA, Military is revising the guideline for digital media disposal to include physical destruction is required before disposing the harddisk ◦ Crusher provide evidence the harddisk is being destroyed and cannot be read ◦ It is fast and effective way (roughly 10sec) to destroy a harddisk/digital media for continue operation and large volume of harddisk to be destroyed when compare to software and degausser What is the advantage of iCrusher over other crusher? ◦ Some crusher completely shred the harddisk/media; again from a pile of scraped residual, it is hard to tell if it is from the same harddisk, or from one’s harddisk ◦ Some crusher create holes in the harddisk disc area, there is still doubt that the remaining part of the disc can still be read / recover by some companies even the disc cannot be rotated anymore ◦ iCrusher does not create holes in harddisk disc area: It create a kind of humps on the disc making the disc unevenly bended in the kind of wave form that no reading head will be able to land on the surface to read from the surface It is very compact in size, and for companies to carry out onsite and portable service Rare metal (the raw material of the PCB) can be recycled and due to export control of most countries such as China, countries are tend to recycle the PCB part (that control the motor action but no user data) seperately (refer to the news clip from Japan in last page of slide), iCrusher does not crush the PCB part (not completely penetrating the whole harddisk) so that removing the PCB part can be easily achieved. ◦ ◦ ◦ ◦ Shall one wish to also crush the PCB part, one can simply perform one more crush by reversing the harddisk and having the PCB side facing the needle iCrusher can create 3ton of pressure to crush any harddisk housing in such a compact unit thanks to the patented design of the high power hydraulic pump The special designed PIN is highly resistance to damage. The strongest part of the harddisk is the high power magnet inside the harddisk which cannot be crushed; most crusher’s PIN will be bended when direct landed on this hard metal; a repair and replacement will be required whereas the unique designed PIN head of iCrusher can avoid any damange to the PIN Software overwrite Degauss Physical Destruction Description Involves using a special application to write patterns of meaningless data onto each of the drive’s sectors. This process works by overwriting the data with a combination of 1´s and 0’s. The level of security depends on the number of times the entire hard drive is written over. It is best to use certified software that provides detailed reporting of the erasure process such as Blancco software. Involves using a machine that produces a strong electromagnetic field to destroy the data on the hard drive. Can be accomplished using a variety of methods, including disintegration, incineration, pulverization, shredding, melting, sanding, and chemical treatment. This method does not actually destroy data but makes the drive inoperable preventing data recovery. It should be carried out at an approved facility by trained and authorized personnel. Advantages •Drives can be reused •Increases the remarketing value of the computer •Can be deployed over the network to target specific PCs. Erasure reports can be sent to a central database offering centralized management. •Software tools that provide detailed reporting of the erasure process are able to validate the erasure of every PC erased. •Convenient way to erase data •Can be performed in-house eliminating the risk of media being stolen during storage or transit to a third party. •Capable of destroying all the data on the hard drive •Can be used to destroy data on a variety of magnetic hard drives irrespective of the drive interface •Fast and simple process •One time investment •It is an effective way of destroying data if carried out correctly •Large amounts of media can be destroyed at once Disadvantages •Cannot be used if the media is damaged or is not writeable. •Overwriting software that are unable to erase data on the locked/hidden sectors perform an incomplete erasure compromising data security. •Overwriting software that operate through the BIOS/OS perform an incomplete erasure leaving some of the data still intact •Overwriting software that do not generate detailed reporting of the erasure process are unable to provide a gapless audit trail •Modern hard drives use thicker shielding and require a much stronger electromagnetic field in order to ensure a complete erasure •No way to guarantee that a particular degaussing machine is strong enough to destroy all the data on every hard drive •Hard drives have to be physically removed from the PC •Hard drives cannot be reused •Other components of the drive are also damaged making it difficult to verify the erasure process •Degaussing machines are expensive and special care must be taken to protect nearby equipment •Often involves using the services of a third party. Theft and uncontrolled handling can lead to unauthorized exposure of confidential data •Degaussing does not provide reporting of the erasure process which is needed to prove regulatory compliance •Reduces the remarketing value of a PC •Can only be used on magnetic media •Physical destruction does not provide reporting of the erasure process which is needed to prove regulatory compliance •Hard drives cannot be reused and is therefore not an environmentally safe approach. •Reduces the remarketing value of the PC •Usually has to be outsourced to a third party therefore compromising data security as theft and uncontrolled handling can lead to unauthorized exposure of confidential data •The time period between the physical destruction of hard drives can create an internal storage and security challenge. •If not carried out correctly data can still be recovered from small broken, fragments of the hard Japan NHK news z6pe_yyyyy-yyyyyyyyy_tech The news said that Japanese government and Hitachi will start the recycling project to collect hard drives and recycle rare metal and rare earth all over Japan soon. 