• 0

Permanently delete data from hdd by using format?


Question

21 answers to this question

Recommended Posts

  • 0

full format.

If you want to be sure do it two times. If you really want to be sure use a program that writes random data to your disc. But in all honesty, the tales about data recovery are hugely blown out of proportion anyway. Nobody will be able to read any kind of residual data from your drive after doing a full format twice. And your data wouldn't be worth that kind of trouble and cost anyway (sorry :p)

  • 0

A full format in XP does nothing but remove the pointers and make sure the sectors can be read. This will not remove the ability to recover a file. If you are using vista or higher then it does write zero's and that would be good enough

As long as you write something over the sectors - then data can not be recovered. Doing multiple wipes is overkill, once is enough.

  • 0

Ignore the comments regarding doing just a format, this is nonsense.

A format deletes where the information is on the disk, the information is still there. A format can easily be unformatted and information found.

U need to Erase ( http://en.wikipedia.org/wiki/Data_erasure ), Depending on the information stored, although a single pass might be ok, doing a few would be better ( Can always be done over night ). In the old days this would be done in DOS / out of windows, might have changed now. This sets the whole partition or disk to random 0s and 1s.

  • 0

"ignore the comments regarding doing just a format, this is nonsense."

http://support.microsoft.com/kb/941961

Change in the behavior of the format command in Windows Vista

The format command behavior has changed in Windows Vista. By default in Windows Vista, the format command writes zeros to the whole disk when a full format is performed. In Windows XP and in earlier versions of the Windows operating system, the format command does not write zeros to the whole disk when a full format is performed.

  • 0
Ignore the comments regarding doing just a format, this is nonsense.

A format deletes where the information is on the disk, the information is still there. A format can easily be unformatted and information found.

U need to Erase ( http://en.wikipedia....ki/Data_erasure ), Depending on the information stored, although a single pass might be ok, doing a few would be better ( Can always be done over night ). In the old days this would be done in DOS / out of windows, might have changed now. This sets the whole partition or disk to random 0s and 1s.

FUD.

If I write a series on 1's and 0's on a disk, then go through the whole disk again and replace everything with 1's, how will a program be able to tell where a 1 was a 0 before, and where a 1 should remain a 1? It can't.

A basic format does what you pointed out, it removes the headers. But once you do one pass on a disk you're fine.

  • 0

If you're really paranoid, or stored Top Secret government data on a hard drive, the drive needs to be physically destroyed. For everyone else there are all sorts of drive scrubbing apps available, McAfee for example includes this in at least some versions of their AV software.

Erasing or securely deleting files means overwriting that part of the hard drive's storage with new data, usually garbage but all ones or zeros, as with a full format works too. This is because data's stored all over the place on the hard drive's platter(s), with a Table of Contents at the front of the drive/partition recording where all the bits & pieces of each file are -- simply deleteing a file only removes its TOC entries. That's why all those utilities to recover lost files work -- you can fit all the pieces of a file back together like some sort of jigsaw puzzle [assuming all those pieces are still there, haven't yet been overwritten, which is why if there's something *Real* important you need to recover you click off the main power switch or pull the plug, running your recovery app(s) from a boot disc/USB stick]. Now, conventional hard drives work by having heads float above the disk platter(s) to read/write data -- since they float there's a very slight amount of wobble. If as a file is written one head happens to wobble to the right, then when it's overwritten that same head happens to wobble left, there could be traces of the original file remaining alongside the newly written data -- that's why erasing/scrubbing a drive usually means overwriting everything multiple times... the more passes you make the more chances the head(s) were on the right, the left, & everywhere in between overwriting data.

You can also erase, scrub, securely delete individual files, &/or all the free space to get rid of stuff without wiping the entire drive. In that case you might want to use an erasing app that goes after the unused portion of cluster blocks... On a conventional hard drive the storage space is divided up into small chunks & data's stored in those -- one way to think of it is if you set out a row of glasses & start pouring a bottle of your favorite beverage -- the last glass is likely to be only partially filled. If one of these blocks or chunks was completely filled, then only partly overwritten, there's old data still there that could potentially be recovered.

  • 0
Nobody will be able to read any kind of residual data from your drive after doing a full format twice. And your data wouldn't be worth that kind of trouble and cost anyway
As long as you write something over the sectors - then data can not be recovered. Doing multiple wipes is overkill, once is enough.

Purely FWIW I agree, but I still will either destroy an old drive I'm getting rid of, or use multiple passes if the drive's going to someone else... Connecting the drive to a PC/laptop I'm not using at the time & running whatever to erase that drive costs me only a few minutes connecting/disconnecting the drive & fireing up whatever app -- the [admitedly small amount of] additional peace of mind I get is well worth it to me. :) 'Sides, makes it harder for someone to get away with claiming they recovered this or that from the drive, they can't as easily get away with saying whatever files were on there when they got it & so on.

  • 0

i've done in the morning the (only) format for the 3 partitions by using my windows 7 ultimate dvd.. I hope I'm ok with this, I'm not paranoid and the buyer is not an experienced user.. as I know. Hdd is on it's way to the client but my best friend that routes it still can help me.. should I?

Install-Windows-7-12-format.jpg

  • 0

Get Parted Magic and do a secure erase. HDDerase will also do a secure erase. Secure erase is suppose to the best method. I have been told zero wiping is good enough. I would do more than that though. If your drive does not support secure erase Parted Magic has other methods. https://www.youtube.com/watch?v=g8t2ZXOMGKY. As mentioned before DBAN too.

  • 0

A full format in XP does nothing but remove the pointers and make sure the sectors can be read. This will not remove the ability to recover a file. If you are using vista or higher then it does write zero's and that would be good enough

As long as you write something over the sectors - then data can not be recovered. Doing multiple wipes is overkill, once is enough.

+1

a full format on xp doesnt write 0's and 1's. it just does a standard format then fully checks the disk.

i'm a fan of the shred command in linux myself. i just put my hdd in a usb enclosure. boot up my favorite linux live cd and shred -n 2 -fvz /dev/X

i think there's a ton of free erasing programs that you can make a live cd with. but it's been a while since i've looked up any.

  • 0

you can do a similar command with windows

cipher /w

http://support.microsoft.com/kb/814599

How to Use the Cipher Security Tool to Overwrite Deleted Data

Note The cipher /w command does not work for files that are smaller than 1 KB. Therefore, make sure that you check the file size to confirm whether is smaller than 1 KB. This issue is scheduled to be fixed in longhorn.

To overwrite deleted data on a volume by using Cipher.exe, use the /w switch with the cipher command:

  1. Quit all programs.
  2. Click Start, click Run, type cmd, and then press ENTER.
  3. Type cipher /w:folder, and then press ENTER, where folder is any folder in the volume that you want to clean. For example, the cipher /w:c:\test command causes all deallocated space on drive C to be overwritten. If C:\folder is a Mount Point or points to a folder on another volume, all deallocated space on that volume will be cleaned.

Data that is not allocated to files or folders is overwritten. This permanently removes the data. This can take a long time if you are overwriting a large amount of space.

But full windows since vista does work as well.

  • 0

Even then, it is recommended to perform this multiple times to ensure the drive has been truly zeroized. Every IT Security company I have worked for state that we need to wipe 3-5 times. Normal users won't need this and I feel it to be a little over kill. but it will ensure not a single bit is flipped.

  • 0

"I have worked for state that we need to wipe 3-5 times."

This is just pure FUD plain and simple! Even if you missed a few bits from being flipped - there is no actual data that is going to be recovered.

So in NIST 800-88, clearly states

http://csrc.nist.gov...with-errata.pdf

"That is, for ATA disk drives manufactured after 2001 (over 15 GB) clearing by overwriting the media once is adequate to protect the media from both keyboard and laboratory attack."

So unless you have some DOD **** and some out dated procedures/policies that you have to follow in your job. 1 overwrite all that is required. Now I would make sure you trust that the wipe is actually being done, etc. But there is no reason to do the wipe more than once.

Here is a good read on the why you only need 1 wipe

http://computer-fore...ard-drive-data/

  • 0

Data on a disk which has had its data overwritten cannot be recovered with a simple software program, right?

Such data recovery would require the dismantling of the disk and the use special hardware.

Unless the data on your drive is worth millions, the average person is not going to go through all that trouble.

A single overwrite pass should be enough for your needs.

Please correct me if I am wrong.

  • 0

And if you read the documentation I provided already, even dismantling of is not going to work.

http://csrc.nist.gov...with-errata.pdf

"That is, for ATA disk drives manufactured after 2001 (over 15 GB) clearing by overwriting the media once is adequate to protect the media from both keyboard and laboratory attack."

Notice the laboratory attack part ;)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft had to shut down 70+ GitHub repos after getting hacked, brings back some by Aditya Tiwari The self-replicating malware campaign known as Miasma took the open-source world by storm. It was reported that almost 73 Microsoft GitHub repositories were infected by the worm and had to be temporarily shut down to determine how attackers compromised projects and stuffed password-stealing malware in the code. These GitHub repos span across different organizations, including Microsoft Azure, Azure-Samples, Microsoft, and MicrosoftDocs. The malware enabled attackers to steal passwords and credentials when compromised tools were opened in popular AI coding apps, including Claude Code, Gemini CLI, VS Code, and Cursor. The security firm Cloudsmith, malware analysis site OpenSourceMalware, and 404 Media were among the first to report the hack. For background, Miasma is a variant of the Mini Shai-Hulud worm, open-sourced by the threat group TeamPCP. It started its journey by compromising a Red Hat employee's GitHub account to attack the @redhat-cloud-services npm namespace. Earlier this month, Microsoft Threat Intelligence reported that the Miasma attackers published 32 malicious packages across more than 90 versions under the @redhat-cloud-services npm scope to steal cloud credentials. The worm didn't take long to start attacking source repos directly rather than package registries. It is known to skip the npm registry entirely for several targets and plant malicious code straight into public repos like "icflorescu/mantine-datatable." The delivery approach was designed to weaponize AI coding tools. Miasma's malicious payload embedded into projects can trigger automatic code execution when the infected repo is opened in an AI coding tool or IDE. The list of affected projects includes "durabletask", a Python package compromised by TeamPCP a month earlier to deliver an information stealer designed for Linux systems. That said, Microsoft has begun restoring some repos affected by the malware campaign, The Hacker News reports. A company spokesperson stated the following: Microsoft will continue to investigate the attack. It has notified a small number of customers who may have removed their content from the affected repos. The company will reach out to customers again through established support channels "if anything further is identified that requires customer action."
    • Why is Opera doing this notification at all? They have their own extension store. They don't have to obey anything dictated by Google. Others like Brave and Vivaldi that rely on Chrome's extension store, not so much. Firefox is entirely separate as well with its own extensions store. I honestly don't understand why entire world is just insisting on Chrome. Like, why? It's a stupid fat browser with barely any functionality. But sure, it's installed on everything by default. I don't understand how people even use web that's filled with tracking garbage and ads all over the place.
    • Just for anyone reading, AdGuard (the free, standalone MV3 extension) is quite good now, a direct competitor to uBlock Origin Lite and much more built-out than it.
  • Recent Achievements

    • Week One Done
      rubentuben8 earned a badge
      Week One Done
    • Week One Done
      ARaclen earned a badge
      Week One Done
    • One Year In
      jojodbn earned a badge
      One Year In
    • One Month Later
      jojodbn earned a badge
      One Month Later
    • Week One Done
      jojodbn earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      531
    2. 2
      PsYcHoKiLLa
      231
    3. 3
      +Edouard
      130
    4. 4
      ATLien_0
      88
    5. 5
      Steven P.
      83
  • Tell a friend

    Love Neowin? Tell a friend!