mailing list archives
Re: Interesting One
From: Greg van der Gaast <greg.van.der.gaast () ordina nl>
Date: Fri, 01 Nov 2002 14:11:48 +0100
This is exactly what I meant. The magnetic trace elements that are left
off to the sides of the track can contain data from a write to that
location that has since been overwritten, multiple times. This trace
information even layers, to some degree, making it possible to actually
see what was on the same specific area of the drive at different times.
Much like layers of sedimentory rock.
There are limits to this as you can only have a fixed X number of layers
with a fixed amount Y of magnetic material. I hope it's obvious to
everyone here that any material off to the side of the tracks isn't
going to be recoverable by any software method as the read thereof is
beyond the hardware of the drive.
Greg van der Gaast
Where do you want to hit your account manager today? (tm)
Chet Uber wrote:
Fact: You cannot read the drive if it is overwritten without being
manipulate the path of the drive head. I do not mean deleting a file
I mean overwriting the drive with dd for example. What they are talking
about is that the edges of the tracks have data still, and you can
disassemble the drive and use force microscopy to read what is left.
a well known issue.
The overwritten by X times is irrelevant if you are trying to recover
software. You cannot recover these drives.
----- Original Message -----
From: "Greg van der Gaast" <greg.van.der.gaast () ordina nl>
To: <security-basics () securityfocus com>
Sent: Wednesday, October 30, 2002 4:53 AM
Subject: RE: Interesting One
Last I heard from some DoD/NIPC people (and this was well over a year
ago) is that they were able to successfully retrieve at least partial
information off a disk that had been overwritten 153 times. Assume that
(at least government) forensic techniques have improved since.
Hope this helps!
Greg van der Gaast
Ordina Public SDS West
Van: Carol Stone [mailto:carol () carolstone com]
Verzonden: Tuesday, October 29, 2002 9:58 PM
Aan: security-basics () securityfocus com
Onderwerp: Re: Interesting One
I don't know much about this, but yesterday I read in one of the later
chapters of Bruce Schneier's book, "Secrets and Lies," (link to amazon
follows) that over-writing data on a disk does *not* completely
obliterate it, it just makes it a lot more difficult to recover with
each over-write. I believe he said just how many re-writes were still
recoverable was a secret one of our governmental organizations wasn't
about to give up. I'll look at my book later when I have it in my
hands and see if I can't find part and post a pointer to *his*
I had an interesting conversation today with someone from FAST
Against Software Theft) They pretend not to be a snitch wing of the
Anyway, to get to the point, the guy that came to see me said that
forensics guys could read data off a hard drive that had been written
up to thirty times. I find this very hard to believe and told him I
he was mistaken but the guy was adamant that it could be done. My
is, does anyone have any views on this, or, can anyone point me to a
of information where I can get the facts on exactly how much data can
retrieved off a hard drive and under what conditions etc etc.
This message (and any associated files) is intended only for the
use of the individual or entity to which it is addressed and may
contain information that is confidential, subject to copyright or
constitutes a trade secret. If you are not the intended recipient
you are hereby notified that any dissemination, copying or
distribution of this message, or files associated with this message,
is strictly prohibited. If you have received this message in error,
please notify us immediately by replying to the message and deleting
it from your computer. Messages sent to and from
John Crowley (Maidstone) Ltd may be monitored.
Internet communications cannot be guaranteed to be secure or error-
as information could be intercepted, corrupted, lost, destroyed,
late or incomplete, or contain viruses. Therefore, we do not accept
responsibility for any errors or omissions that are present in this
message, or any attachment, that have arisen as a result of e-mail
transmission. If verification is required, please request a hard-copy
version. Any views or opinions presented are solely those of the
and do not necessarily represent those of John Crowley (Maidstone)
Real people for the virtual world.