514
submitted 6 months ago by misk@sopuli.xyz to c/technology@lemmy.world

cross-posted from: https://sopuli.xyz/post/12670977

iPhone owners say the latest iOS update is resurfacing deleted nudes

you are viewing a single comment's thread
view the rest of the comments
[-] Liz@midwest.social 2 points 6 months ago

Question: what fraction of bits do you need to randomly flip to ensure the data is unrecoverable?

[-] barsoap@lemm.ee 5 points 6 months ago* (last edited 6 months ago)

Information theory aside: In practice all because you can't write bit-by-bit and if you leave full bytes untouched there still might be enough information for an attacker to get information, especially if it's of the "did this computer once store this file" kind of information, not the actual file contents.

If I'm not completely mistaken overwriting the file once will be enough to prevent recovering with logical means, that is, reading the bits the way the manufacturer intended you to, physical forensics can go further by being able to discern "this bit, before it got overwritten, was a 1 or 0" by looking very closely at the physical medium, details on how much flipping you need to defeat that will depend on the physical details.

And I wouldn't be too terribly sure about that electro magnet you built into your case to erase your HDD with a panic button: It's in a fixed place, will have a fixed magnetic field, it's going to scramble everything sure but the way it scrambles is highly uniform so the bits can probably be recovered. If you want to be really sure buy a crucible and melt the thing.

Also, may I interest you in this stylish tin-foil hat, special offer.

[-] Hildegarde@lemmy.world 3 points 6 months ago

If you delete normally, only the index of the files are removed, so the data can be recovered by a recovery program reading the "empty" space on the disk and looking for readable data.

If you do a single pass erase, the bits will overwritten one time. About half the bits will be unchanged, but that makes little difference. Any recovery software trying to read it will read the newly written bits instead of the old ones and will not be able to recover anything.

However, forensic investigation can probably recover data after a single pass erase. The shred command defaults to 3 passes, but you can do many more if you need to be even more sure.

Unless you have data that someone would spend large sums on forensics to recover, 1 to 3 passes is probably enough.

[-] Natanael@slrpnk.net 0 points 6 months ago

If it's completely random then 50%, that's how stream ciphers works.

this post was submitted on 15 May 2024
514 points (97.4% liked)

Technology

59598 readers
2364 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS