full-disclosure-uk January 2010 archive
Main Archive Page > Month Archives  > full-disclosure-uk archives
full-disclosure-uk: Re: [Full-disclosure] Disk wiping -- An alte

Re: [Full-disclosure] Disk wiping -- An alternate approach?

From: T Biehn <tbiehn_at_nospam>
Date: Tue Jan 26 2010 - 16:05:27 GMT
To: Michael Holstein <michael.holstein@csuohio.edu>


Entropy vs zeros vs random content.

Plausible deniability will only be there if there is legitimate data that looks like it's been used and the prosecutor cannot construe any of your data as that used for wiping or otherwise obscuring the data on your drive. If you don't have this you better request a trial by judge rather than jury.

Now;
Your best solution is to use an exterior OS on FDE, then, in a TC Hidden Disk container have a VM image that you use for 'hidden works.' You can hand over your FDE's PW and location of TC disk including the exterior password for great fed win.

-Travis

On Tue, Jan 26, 2010 at 10:08 AM, Michael Holstein <michael.holstein@csuohio.edu> wrote:
>
>> By the way, does somebody knows about the flash memory?
>> Is zeroing a whole usb key enough to make the data unrecoverable?
>>
>
> No, wear-leveling (done at the memory controller level) will dynamically
> re-map addresses on the actual flash chip to ensure a relatively
> consistent number of write cycles across the entire drive.
>
> The only way to completely "wipe" a flash disk is with a hammer.
>
> Regards,
>
> Michael Holstein
> Cleveland State University
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
-- FD1D E574 6CAB 2FAF 2921 F22E B8B7 9D0D 99FF A73C http://pgp.mit.edu:11371/pks/lookup?search=tbiehn&op=index&fingerprint=on http://pastebin.com/f6fd606da _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/