Solved

Wipe SSD Drive for PCI Compliance

Posted on 2014-03-12
6
437 Views
Last Modified: 2014-03-27
i know for normal SATA drive i have to do 7 passes when wiping the hard drive, i use DBAN for SATA/ATA Drives.

What can i use for SSD Drives?
0
Comment
Question by:NxJNY
6 Comments
 
LVL 27

Assisted Solution

by:Thomas Zucker-Scharff
Thomas Zucker-Scharff earned 167 total points
ID: 39924369
You should take a gander at the paper I recently came upon in my collection.  It is a attached.
SAFE---scramble-and-finally-eras.pdf
0
 
LVL 54

Assisted Solution

by:McKnife
McKnife earned 166 total points
ID: 39924453
Hmm, in that document, the term "secure erase" is not even mentioned, although it should be the "buzz-word" here. That document is a little old. The same people, only a few months later published this: http://www.usenix.org/events/fast11/tech/full_papers/Wei.pdf which is also linked here: http://en.wikipedia.org/wiki/Data_remanence#Data_on_solid-state_drives

Conclusion: two ways to go:
-encrypt new drives before data gets onto them (whole disk encryption methods), then you won't have to worry.
-if sensitive data is already on unencrypted media, the only way to get rid of it is to use secure erase commands based at the firmware level of the drive. Usually this takes only some seconds (!) and is done via manufacturer provided tools.

Simply erasing using the same tools as for HDDs is not applicable to SSD due to wear features.
0
 
LVL 27

Expert Comment

by:Thomas Zucker-Scharff
ID: 39924501
Good one - thanks for the link.  You can also see a few decent papers on SSDs by techtarget here:

http://searchstorage.techtarget.com/definition/solid-state-drive 

Check the bottom for links to various discussions of SSDs.
0
Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

 
LVL 38

Expert Comment

by:Rich Rumble
ID: 39925379
SSD's, depending on the model and age, have undergone quite a few changes, and that can affect what is and isn't able to be recovered or even wiped. Modern SSD's evenhave built-in tools for it.SSD's can have bad sectors that don't allow you to access them anymore, but that doesn't mean they aren't accessible at some (hardware)level and thus able to be recovered.
http://www.kingston.com/us/community/articledetail?ArticleId=10
http://arstechnica.com/security/2011/03/ask-ars-how-can-i-safely-erase-the-data-from-my-ssd-drive/
-rich
0
 
LVL 62

Accepted Solution

by:
btan earned 167 total points
ID: 39928435
Another for sharing
- Secure Erase (HDDErase.exe, but pretty out dated in development)
- Parted Magic suite of tools (may be better candidate)

http://howto.cnet.com/8301-11310_39-20115106-285/how-to-securely-erase-an-ssd-drive/

I am skeptical if really erasure can be that clean (also ref what richrumble shared in the ars article) but probably just encrypt your hard drive and then zero it, also not "killing" te lifespan with too much wiping etc
0
 
LVL 27

Expert Comment

by:Thomas Zucker-Scharff
ID: 39929180
Lifespan of an SSD is measured in the number of writes.  It is my understanding that you will probably never reach the number in the life of a given SSD, but it would be wise not to defragment.
0

Featured Post

ScreenConnect 6.0 Free Trial

Explore all the enhancements in one game-changing release, ScreenConnect 6.0, based on partner feedback. New features include a redesigned UI, app configurations and chat acknowledgement to improve customer engagement!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
gparted boot manager 4 61
forensics tools for file amendments/associations 2 80
Problem to search 5 43
md5 password 3 62
If you thought ransomware was bad, think again! Doxware has the potential to be even more damaging.
As a financial services provider, your business is impacted by two of the strictest federal regulations on record: the Sarbanes-Oxley Act and the Gramm-Leach-Bliley Act. Correctly implementing faxing into your organization to provide secure, real-ti…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question