175
Why ‘deleted’ doesn’t mean gone: How police recovered Nancy Guthrie’s doorbell footage
(www.theverge.com)
This is a most excellent place for technology news and articles.
From the article:
This is more or less how local storage works as well. The creator of BleachBit, a file cleaning tool made famous for being present on Hillary Clinton’s email servers, has some great insights in their documentation about the methods for destroying data on hard drives. As it turns out, data “deletion” is just a series of operations on your hard disk like any other, and retrieval depends on the methods used - de-indexing, metadata and file structure removal, and overwriting to name a few.
Once, I accidentally formatted the wrong drive in Windows and it ended up being my 20TB platter (oops). I was able to recover 99% of the files on the drive with some free recovery software just because I disconnected and stopped using the drive immediately. The only files lost were large ones partially overwritten by the new blank file system created when I formatted the drive. Windows had only deleted the file system indexing the drive, and all of the file data and metadata was intact, waiting to be randomly overwritten. I had to string together four cheap failing 4TB SATA drives I bought used on Amazon, but it worked.
The point is, if I could do this as an amateur, and storage technology operating on the same principals is in use at enterprise scale, what are the lengths that the likes of the FBI and Google are willing to go to recover old data that has been “deleted”? I’m frankly surprised that Google does not overwrite their discarded data, and it’s probably for reasons like this, beyond the additional processing time it would take. Given their vast resources and storage capacity, it could be some time before “deleted” data is at least partially overwritten, if ever.
If you ever have data that you absolutely need destroyed, overwrite the entire drive with random data more than once, then physically shred the drive completely. And never connect your devices to a cloud storage service. It’s the only way to be sure.
I was under the impression that Google just didn’t delete data — ever. Like, it’s way more valuable compared to the cost of the disk.
I've never understood the overwrite more than once instruction. If the entire drive is overwritten how in the world do you pull back data out from an overwrite?