Secure Erase: data security you already own

by Robin Harris on Wednesday, 2 May, 2007

Over at Storage Bits, my new ZDnet blog, I wrote about Secure Erase, a feature that Walter Purvis at Data Mobility Group told me about.

Secure Erase (SE) excited so much attention over there that I thought I’d take a more leisurely stroll through it here.

Free, secure, ATA drive erasure
SE is built into virtually all P/SATA drives built since 2001, when it became part of the ATA standard. It is virtually unknown however, because many BIOSes block the command and some even lock the drive to keep the data safe from Murphy’s-law-abiding citizens. Not to mention evil virus writers.

More secure than external wipers
Since it is internal to the drive, it doesn’t exact much overhead compared to external wipers like the open source Boot and Nuke or similar commercial products. Even better, it is more secure, protecting the data from keyboard (file recovery utilities) attacks and laboratory attacks.

In fact, NIST rates SE’s effectiveness on a par with degaussing a hard drive. Degaussing (strong magnetic field) is losing favor because of a combination of increasing media coercivity and improved magnetic shielding. Once HAMR (Heat Assisted Magnetic Recording) arrives, it may be practically impossible to degauss a drive short of a nuclear weapon’s electro-magnetic pulse. Then we’ll likely be down to Secure Erase and physical destruction as NIST-approved methods of sanitizing disks.

A blunt instrument
SE doesn’t give you many choices: it erases all the user space on the drive, one track at a time. It can erase HPA (Host Protected Area) or DCO (Device Configuration Overlay) areas, if any, as well. Some drives implement an enhanced Secure Erase which instead of writing zeros writes a pattern set by the vendor and that overwrites all bad blocks as well.

When the process is done your drive is empty and ready for OS formatting.

But wait! There’s more!
Check out UCSD’s Center for Magnetic Recording Research to learn more about a leading center of research with the goal of 1 terabit/sq. inch recording. Dr. Gordon Hughes, an IEEE fellow, on the faculty has created a utility that enables SE on Windows machines, available from his CMRR home page. This utility is for experienced storage heads and is not noob-friendly.

Dr. Hughes has also co-authored a paper (pdf) called Data Sanitization Tutorial that gives a brief, 12 page overview of the requirements and options for secure data elimination.

If you are in government, or deal with those who are, you should also check NIST’s special Computer Security publication page. Of special interest is publication 800-88 “Guidelines for Media Sanitization” which covers disks and other media as well.

The StorageMojo take
Secure Erase is an interesting and little known addition to the storage pro’s toolkit. If anyone whips up a tool for using it under Mac OS X or Linux, please let me know.

Comments welcome, as always.

{ 1 trackback }

JIRA: Infra Hardware - Issues Tracking
Wednesday, 3 June, 2009 at 4:38 pm

{ 16 comments… read them below or add one }

Charles A. Wednesday, 2 May, 2007 at 5:30 pm

Thanks for the info.

Is this what the IBM DFT tool “Erase Disk” function does?
What about the HD manufacturer’s own disk erasing tools?

Robin Harris Wednesday, 2 May, 2007 at 6:44 pm

Charles,

I looked it up – Hitachi has the docs for it now – and yes it the Drive Fitness Test “Erase Disk” function is similar. The big difference is that it is, like Boot and Nuke, an external drive wiper. So it won’t give the same level of security as Secure Erase, according to NIST.

Robin

Joerg M. Wednesday, 2 May, 2007 at 9:30 pm

In my opinion such concepts like secure deletion goes only the half way. The problem is: How do you delete media not attached to a computer and how delete them ultrafast. The concepts of Radia Perlman about Assured Deletion sound very promising in this regard. The basic concept vastly simplyfied : Encrypt everything. When you want to delete a file, simple throw away the key

Robin Harris Wednesday, 2 May, 2007 at 9:39 pm

Joerg,

An excellent point. In fact, that is the next level of security for 2.5″ drives: everything is encrypted with secure key deletion. A future post that ties back to one I did last year.

Thanks,

Robin

Robin Harris Wednesday, 2 May, 2007 at 9:47 pm

This came in over the transom, and it sounded pretty good, so I am putting it in as a comment from me. It is from Ryk Edelstein, director of operations for Converge Net, Inc. – a link to a white paper he wrote is in the comment – and I appreciate the quality of his presentation.

Normally I am deeply allergic to self-promotion on StorageMojo – with me as the obvious exception! – but I respect the fact that he has deeper knowledge than I do and presents it well. I do wish he didn’t point out my flaws, but what the hey:

I have read your article on Secure ERase and must state that although you are on the right track, and that the NIST does recognize SE as the single best means to destroy data on a hard dfrive beyond forensic reconstruction second to effective physical destruction. The CRMM software as developped by Dr. Gordon Hughes team, is an academic command line utility designed as a proof of concept tool to demonstrate Secure Erase. Yet, what you fail to state is that this software does not work on most stations or devices.

As a command line utility, the CRMM software does not provide a solution that offers a defensible audit log, or a reliable platform for the effective decomissioning of hard drives in the enterprise. Likewise, in many cases the SE command will not be sent to the device due to BIOS and OS inhibition of the command being presented to the target drive. PC vendors have in many cases inhibited SE from being initiated due to the threat it poses if it were to be exploited by virus and malware authors.

Furthermore, drive manufacturers have interpreted SE differently, and in some cases by the same vendor from one drive model to the next. As such, SE needs to be initiated in a manner specific to the device, in order to be effectively launched.

Please do not get me wrong, I am a big fan of Secure Erase, and more so, on the proper means to use SE. See http://www.deadondemand.com/assets/documents/edt_digital_shredder_2.pdf for more details on the proper means to decomission hard drives using Secure Erase. Even on SATA devices.

Samuel Landau Thursday, 3 May, 2007 at 12:44 am

AFAIK for Linux, current hdparm allows to use ATA security functions, amongst which commands ERASE PREPARE and ERASE UNIT. Just make sure your kernel supports it : recent enough release and compiled with CONFIG_IDE_TASK_IOCTL enabled.

Ron Thursday, 3 May, 2007 at 6:52 am

$ /sbin/hdparm –security-help

ATA Security Commands:
Most of these are VERY DANGEROUS and can KILL your drive!
Due to bugs in most Linux kernels, use of these commands may even
trigger kernel segfaults or worse. EXPERIMENT AT YOUR OWN RISK!

–security-freeze Freeze security settings until reset.

–security-set-pass PASSWD Lock drive, using password PASSWD:
Use ‘NULL’ to set empty password.
Drive gets locked if user-passwd is selected.
–security-unlock PASSWD Unlock drive.
–security-disable PASSWD Disable drive locking.
–security-erase PASSWD Erase a (locked) drive.
–security-erase-enhanced PASSWD Enhanced-erase a (locked) drive.

The above four commands may optionally be preceeded by these options:
–security-mode LEVEL Use LEVEL to select security level:
h high security (default).
m maximum security.
–user-master WHICH Use WHICH to choose password type:
u user-password.
m master-password (default).

Ryk Edelstein Thursday, 17 May, 2007 at 7:16 pm

Thanks for the posting… However, although I may have pointed out a minor error (rather, a point in need of a bit of elaboration), I will throw myself on my sword and correct a few errors in my own message…(probably why I should not be writing in the very early a.m.)

1/ the Acronym is the CMRR – Center for Magnetic Recording Research at the University of California San Diego.

2/ the first sentence is a mess… sorry.

3/ This is not self promotion.. I do not work for Ensconce Data Technology, the manufacturer of the Dead on Demand Digital Shredder. The white paper was originally developed as a presentation of the acceptable means to responsibly destroy hard drive data, and to dispel many of the half baked and potentially dangerous concepts floating about. EDT had requested the rights to the paper for their own purpose.

Clearly my perspective on their product and the value it offers the public and private sector as a portable data destruction appliance made the piece very appealing to them. The presentation is facts based, and you can draw your own conclusion.

If you want to see a broad array of half baked data destruction methods, by self proclaimed experts, go to YOUTUBE and search on data or drive destruction. It is like calling in your crazy cousin Bob to bring over his sledge hammer for a session or data destruction.

I apologize for the errors.

Ryk

mark stumpo Friday, 24 July, 2009 at 10:28 am

I used SE on maxtor and seagate drives, but when installing xp on any of them, after xp formats and copies files, the install fails. It only seems to happen on drives that were SE.. Any idea?

Robin Harris Friday, 24 July, 2009 at 6:44 pm

Mark,

Did you do reformat the drives from Windows before the install? That could be it.

Robin

Anonymous Thursday, 29 October, 2009 at 6:00 pm

Hi,

I want to enhanced secure erase my seagate drive but:
-HDDerase gives memory error on startup and I am not experienced enough to track reasons.
-I do not know how to boot with hdparm so that I cant use it. I guess I need to initialize hddparm from a physically different location, i.e. not from the drive i am going to erase.

I just want to want to enhanced secure erase the only hard drive on my laptop. What is the easiest way to do that?

Thanks.

Gregg E. Saturday, 7 November, 2009 at 1:11 am

I just want to wipe a Maxtor 40 gig QuickView drive that came from an old DVR of unknown make. There’s something secured or locked with it so I can’t just plug it into a normal PC and partition/format it.

I know there are master passwords for these drives, I can find them online for any brand *except Maxtor*.

Would be great, in this case, if it had something like “WARNING! INCORRECT PASSWORD ENTERED 5 TIMES! ENTERING INCORRECT PASSWORD AGAIN WILL START SECURE ERASE PROCESS!”.
I’d just poke in some randomness and let the thing wipe itself, as long as that would unlock it.

F2 Friday, 18 June, 2010 at 11:34 am

Hello Robin,
You say that the Security Extensions are prevalent on most drives. I have scanned a few SATA units from Hitachi, Maxtor and Seagate, and so far found the extension only on the Hitachi drive.

I have been researching the topic myself — there is very little out there on this subject.

David Wednesday, 19 January, 2011 at 5:56 pm

Just in case people find this blog entry when searching Google (or Bing) for secure erase, hdparm is on the gparted live distribution and can used to secure erase (enhanced) an HDD. I completed this yesterday (2011/01/18) on a Seagate drive.

gparted here:
http://gparted.sourceforge.net/download.php

instructions here:
http://www.ocztechnologyforum.com/forum/showthread.php?67253-Alternative-to-HDDerase-(Gparted)-compatible-with-AHCI-!
AND here:
https://ata.wiki.kernel.org/index.php/ATA_Secure_Erase

Caveats:
Yes, the drive needs to be attached locally or possibly eSATA. USB and FireWire probably have a chance to fail.
Yes you DO have to use ‘sudo’.
No, you should not use NULL. for the password.
If the drive is SATA and frozen you can unfreeze it by “hot plugging” the drive (remove, CTRL-R, insert, CTRL-R).
If the drive is IDE/PATA and frozen– I haven’t gotten that far yet.
Secure Erase can take a while. A 500 GB 2.5 inch drive took around 2 hours, 20 minutes.
Secure Erase will wipe the partition table. You will need to create a new one before trying to install anything (like Windows). Luckily you have gparted, right?

Paul L Friday, 29 April, 2011 at 3:20 pm

The Ultimate Boot CD 5.0.3 is a bootable cd with HDDerase 4.0 set to run from FreeDOS. I have been using it to erase a bunch of drives in machines that I am prepping for donation/discarding. Most Seagate and WD hard drives above 20GB performed secure erase quite easily and quickly. About 20 min for a 40GB PATA drive. FYI – Maxtor DiamondMax drives don’t seem to allow secure erase to happen. They always come back with “security count exceeded”.

Mike Sunday, 28 August, 2011 at 2:28 am

I’m sorry I didn’t copy the URL on the work computer where I’m writing this from, but I was reading earlier on how (E)SE on SSD’s is commonly not implemented correctly, and on at least one drive *SAID* it completed but in reality DID NOTHING!! Apparently these manufacturers consider SE on SSD to be nothing more than a controller FTL reset. :(

I believe it may have been a recent CMRR paper, but again I’m going from my fuzzy memory–sorry.

Oh, and “hdparm” on recent Linux kernels (and, I’m assuming, *BSD kernels including OS-X) seems to be fine and stable issuing (E)SE commands: in fact, I’m doing an ESE on my 160GB Toshiba drive right now as I’m replacing it with a Corsair 115GB SSD and will sell the HDD.

Leave a Comment

Previous post:

Next post: