SlideShare a Scribd company logo
1 of 21
Sponsored by
SolidStateDrives(SSD)SecureErasure
DeepDive:What itTakestoReallyMake
theDataGoAway
© 2017 Monterey Technology Group Inc.
Thanks to
 Made possible by
Preview of key
points
 Data erasure fundamentals
 Solid State Drives
 Enterprise data destruction that
 lets you forget about the technology
 provable
Data erasure
fundamentals
 Deletion does not equal destruction
 Security is always an after thought in hardware design
 Different technologies require different methods
 Can be a black-box
HowSSDs are
different than
HDDs and why
that impacts
security
You can read/write a given “page” of a magnetic HDD as many times as you like
HowSSDs are
different than
HDDs and why
that impacts
security
You can read/write a given “page” of a magnetic HDD as many times as you like
And there’s just 2 operations – read and write
HowSSDs are
different than
HDDs and why
that impacts
security
Programmed
Erased
writeerase
 NAND memory has 3 operations write (aka program), read and
erase
 Block can only be written once, then must be completely erased
and rewritten
Read many
HowSSDs are
different than
HDDs and why
that impacts
security
 NAND memory is bits organized into blocks
 Start off will all bits set to 1
 Write a block by setting necessary bits to 0 so that the block reflects the data you
want to store
 Now you have a “programmed” block storing the data
 You can read that block repeatedly
 (Reading it too many times will disturb nearby blocks)
 When you need to update a single bit within that block you need to first erase the
entire block and re-write the whole thing
 Technically if that the bit you want to write is a 0 you could update just that bit
 That’s a 50/50 chance
 But normally you have to update more
than one bit. So what’s the chance that
all the bits you need you to change are
going to be 0? If even one 1 bit needs to go
from 0 to 1 you have to
 Read the entire block into SSD RAM
 Update the bits or bytes or words necessary
 Erase the block
 Re-write the block
HowSSDs are
different than
HDDs and why
that impacts
security
 But NAND can only be programmed/erased so many times
 Each p/e cycle causes physical damage to the medium
 In real life some chunks of data get updated far more frequently
than others
 So SSD manufacturers implement
 Wear levelling
 Over-provisioning
HowSSDs are
different than
HDDs and why
that impacts
security
Wear levelling and over-provisioning
HowSSDs are
different than
HDDs and why
that impacts
security
 But to make SSDs take off really fast, they didn’t want to make
every OS manufacture implement a new physical file system
with knowledge specific to each implementation of NAND as
SSD
 So make an SSD look like a HDD and just translate it
Application
Operating System
ATA driver
ATA
commands
HowSSDs are
different than
HDDs and why
that impacts
security
Application
Operating System
ATA driver
ATA
commands
Flash translation
layer (FTL)
Direct, page-for-page
Traditional
erasure
algorithms
unsuitable for
SSDs
Military Spec Overwrite
each sector
Other issues
 Freeze lock
 BIOS of most modern computers blocks access to these
commands with a “freeze lock” on the drive’s security feature
set.
 Unless the freeze lock is removed, it’s extremely difficult to
conduct the necessary firmware-based erasure that scrubs
entire SSD storage
Other issues
 What is ATA Secure Erase?
 Set of commands embedded in
most hard drives since 2001
 Secure Erase is a command not a
physical operation
 Therefore it’s all about the
implementation (i.e. code)
behind that command
 “it’s up to each manufacturer to
implement it correctly. In their
review of the secure erase
command,Wei et al., 2011, have
shown that over the 12 models
of SSDs studied, only eight
offered the ATA Secure Erase
functionality, and over those
eight drives, three had buggy
implementations [11].” -
http://codecapsule.com/2014/02
/12/coding-for-ssds-part-4-
advanced-functionalities-and-
internal-parallelism/
https://www.usenix.org/leg
acy/event/fast11/tech/full_
papers/Wei.pdf
Other issues
 Cryptographic “erasure”
 Drive firmware encrypts each page
 SSD or HDD
 To “erase” drive – just overwrite the key
 In theory – great
 But encryption in theory and in practice are 2 very different
things
 Over and over again see poor encryption implementations
 “Given the bugs we found in some implementations of secure
erase commands, it is unduly optimistic to assume that SSD
vendors will properly sanitize the key store. Further, there is no
way verify that erasure has occurred”
 https://www.usenix.org/legacy/event/fast11/tech/full_papers/Wei.pdf
 Bruce Schneier says, cryptographic systems “must be
implemented exactly, perfectly, or they will fail.”
(https://www.schneier.com/essays/archives/1997/01/why_crypt
ography_is.html)
 https://www.owasp.org/images/5/57/OWASPIL2011-
ErezMetula-WhenCryptoGoesWrong.pdf
Bottom line
 SSD erasure
 Must deal with
 Flash translation layer
 Freeze lock
 Requires manufacturer specific logic
 OEM cooperation
 Multi-stage, multi-method
 Verifiable
 Provable
 Reporting
 Applies beyond just SSD
© 2017 Monterey Technology Group Inc.
Securing the
audit trail
Sample Report
SSD Erasure
Approvals
 The Finnish Communications Regulatory
Authority (FICORA) has approved Blancco
erasure software for erasing data from hard
drives and Solid State Drives.
 The AIVD is the General Intelligence and
Security Service of the Netherlands and
evaluate information security products. In their
deployment advisory for Blancco 5 they state
that, for SSD media, the “Blancco SSD
Erasure”-standard should be used.
Additional
Resources
 Research Study: Security Limitations of Solid State Drives
 https://www.blancco.com/resources/rs-security-limitations-of-
ssds
 Whitepaper: SSDs and the Unseen Data Destruction Risks
 https://www.blancco.com/resources/wp-a-look-inside-ssds-
unseen-data-destruction-risks
 Free Evaluation: Blancco Drive Eraser for HDDs and SSDs
 http://info.blancco.com/en-eval-blancco-5

More Related Content

What's hot

Samsung SSDs Speed Scientific Discovery
Samsung SSDs Speed Scientific DiscoverySamsung SSDs Speed Scientific Discovery
Samsung SSDs Speed Scientific DiscoverySamsung Business USA
 
Samsung Solid-State Drives Enable Ultra-Reliable Point of Sale Terminals for ...
Samsung Solid-State Drives Enable Ultra-Reliable Point of Sale Terminals for ...Samsung Solid-State Drives Enable Ultra-Reliable Point of Sale Terminals for ...
Samsung Solid-State Drives Enable Ultra-Reliable Point of Sale Terminals for ...Samsung Business USA
 
does avast remove malware
does avast remove malwaredoes avast remove malware
does avast remove malwaressuser1eca7d
 
Get Your GeekOn with Ron - Session One: Designing your VDI Servers
Get Your GeekOn with Ron - Session One: Designing your VDI ServersGet Your GeekOn with Ron - Session One: Designing your VDI Servers
Get Your GeekOn with Ron - Session One: Designing your VDI ServersUnidesk Corporation
 
Solid State Drives (Third Generation) 2013
Solid State Drives (Third Generation) 2013Solid State Drives (Third Generation) 2013
Solid State Drives (Third Generation) 2013Hemanth HR
 
Solid State Drives - Seminar for Computer Engineering Semester 6 - VIT,Univer...
Solid State Drives - Seminar for Computer Engineering Semester 6 - VIT,Univer...Solid State Drives - Seminar for Computer Engineering Semester 6 - VIT,Univer...
Solid State Drives - Seminar for Computer Engineering Semester 6 - VIT,Univer...ravipbhat
 
SSD vs HDD - A Shift In Data Storage by Todd Dinkelman
SSD vs HDD - A Shift In Data Storage by Todd DinkelmanSSD vs HDD - A Shift In Data Storage by Todd Dinkelman
SSD vs HDD - A Shift In Data Storage by Todd Dinkelmannomathjobs
 
Duco Dokter - Plone for the enterprise market: technical musing on caching, C...
Duco Dokter - Plone for the enterprise market: technical musing on caching, C...Duco Dokter - Plone for the enterprise market: technical musing on caching, C...
Duco Dokter - Plone for the enterprise market: technical musing on caching, C...Vincenzo Barone
 
snapshot vs backup
snapshot vs backupsnapshot vs backup
snapshot vs backupssuser1eca7d
 
Backup and Recovery Solution for VMware vSphere on EMC Isilon Storage
Backup and Recovery Solution for VMware vSphere on EMC Isilon Storage Backup and Recovery Solution for VMware vSphere on EMC Isilon Storage
Backup and Recovery Solution for VMware vSphere on EMC Isilon Storage EMC
 
Upgrade laptopshdd
Upgrade laptopshddUpgrade laptopshdd
Upgrade laptopshddVicent Bit
 
it's time for data recovery company to upgrade your imaging tool
it's time for data recovery company to upgrade your imaging toolit's time for data recovery company to upgrade your imaging tool
it's time for data recovery company to upgrade your imaging toolking
 
Hard Disk Drive versus Solid State Drive
Hard Disk Drive versus Solid State DriveHard Disk Drive versus Solid State Drive
Hard Disk Drive versus Solid State DriveDac Khue Nguyen
 
Install custom recovery
Install custom recoveryInstall custom recovery
Install custom recoveryIfah Anwar
 
Choosing the Right SSD: Consumer, Workstream and Enterprise SSDs
Choosing the Right SSD: Consumer, Workstream and Enterprise SSDsChoosing the Right SSD: Consumer, Workstream and Enterprise SSDs
Choosing the Right SSD: Consumer, Workstream and Enterprise SSDsSamsung Business USA
 

What's hot (20)

Samsung SSDs Speed Scientific Discovery
Samsung SSDs Speed Scientific DiscoverySamsung SSDs Speed Scientific Discovery
Samsung SSDs Speed Scientific Discovery
 
Samsung Solid-State Drives Enable Ultra-Reliable Point of Sale Terminals for ...
Samsung Solid-State Drives Enable Ultra-Reliable Point of Sale Terminals for ...Samsung Solid-State Drives Enable Ultra-Reliable Point of Sale Terminals for ...
Samsung Solid-State Drives Enable Ultra-Reliable Point of Sale Terminals for ...
 
does avast remove malware
does avast remove malwaredoes avast remove malware
does avast remove malware
 
Get Your GeekOn with Ron - Session One: Designing your VDI Servers
Get Your GeekOn with Ron - Session One: Designing your VDI ServersGet Your GeekOn with Ron - Session One: Designing your VDI Servers
Get Your GeekOn with Ron - Session One: Designing your VDI Servers
 
Solid State Drives (Third Generation) 2013
Solid State Drives (Third Generation) 2013Solid State Drives (Third Generation) 2013
Solid State Drives (Third Generation) 2013
 
Solid State Drives - Seminar for Computer Engineering Semester 6 - VIT,Univer...
Solid State Drives - Seminar for Computer Engineering Semester 6 - VIT,Univer...Solid State Drives - Seminar for Computer Engineering Semester 6 - VIT,Univer...
Solid State Drives - Seminar for Computer Engineering Semester 6 - VIT,Univer...
 
SSD vs HDD - A Shift In Data Storage by Todd Dinkelman
SSD vs HDD - A Shift In Data Storage by Todd DinkelmanSSD vs HDD - A Shift In Data Storage by Todd Dinkelman
SSD vs HDD - A Shift In Data Storage by Todd Dinkelman
 
Duco Dokter - Plone for the enterprise market: technical musing on caching, C...
Duco Dokter - Plone for the enterprise market: technical musing on caching, C...Duco Dokter - Plone for the enterprise market: technical musing on caching, C...
Duco Dokter - Plone for the enterprise market: technical musing on caching, C...
 
snapshot vs backup
snapshot vs backupsnapshot vs backup
snapshot vs backup
 
Backup and Recovery Solution for VMware vSphere on EMC Isilon Storage
Backup and Recovery Solution for VMware vSphere on EMC Isilon Storage Backup and Recovery Solution for VMware vSphere on EMC Isilon Storage
Backup and Recovery Solution for VMware vSphere on EMC Isilon Storage
 
Solid state drives
Solid state drivesSolid state drives
Solid state drives
 
FailOver Clustring
FailOver ClustringFailOver Clustring
FailOver Clustring
 
Unity v1 unity_xt_380
Unity v1 unity_xt_380Unity v1 unity_xt_380
Unity v1 unity_xt_380
 
Upgrade laptopshdd
Upgrade laptopshddUpgrade laptopshdd
Upgrade laptopshdd
 
it's time for data recovery company to upgrade your imaging tool
it's time for data recovery company to upgrade your imaging toolit's time for data recovery company to upgrade your imaging tool
it's time for data recovery company to upgrade your imaging tool
 
Hard Disk Drive versus Solid State Drive
Hard Disk Drive versus Solid State DriveHard Disk Drive versus Solid State Drive
Hard Disk Drive versus Solid State Drive
 
Specification
SpecificationSpecification
Specification
 
Install custom recovery
Install custom recoveryInstall custom recovery
Install custom recovery
 
3 5 SSD
3 5 SSD3 5 SSD
3 5 SSD
 
Choosing the Right SSD: Consumer, Workstream and Enterprise SSDs
Choosing the Right SSD: Consumer, Workstream and Enterprise SSDsChoosing the Right SSD: Consumer, Workstream and Enterprise SSDs
Choosing the Right SSD: Consumer, Workstream and Enterprise SSDs
 

Viewers also liked

Security Regulations & Guidelines: Is Your Business on the Path to Compliance?
Security Regulations & Guidelines:  Is Your Business on the Path to Compliance? Security Regulations & Guidelines:  Is Your Business on the Path to Compliance?
Security Regulations & Guidelines: Is Your Business on the Path to Compliance? Blancco
 
Bahrain – Early adapting Glas Trösch products
Bahrain – Early adapting Glas Trösch productsBahrain – Early adapting Glas Trösch products
Bahrain – Early adapting Glas Trösch productsBenjamin Schulz
 
Insights From the Lean Startup Conference 2016
Insights From the Lean Startup Conference 2016Insights From the Lean Startup Conference 2016
Insights From the Lean Startup Conference 2016Jeffrey Tobias
 
How To Drive User Engagement By Creating Habits
How To Drive User Engagement By Creating HabitsHow To Drive User Engagement By Creating Habits
How To Drive User Engagement By Creating HabitsBusiness 2 Community
 
Designing Superpowering Experiences
Designing Superpowering ExperiencesDesigning Superpowering Experiences
Designing Superpowering ExperiencesUnicorn Titans
 
Intelligence artificielle et e-commerce
Intelligence artificielle et e-commerceIntelligence artificielle et e-commerce
Intelligence artificielle et e-commerceHenri ISAAC
 

Viewers also liked (8)

Security Regulations & Guidelines: Is Your Business on the Path to Compliance?
Security Regulations & Guidelines:  Is Your Business on the Path to Compliance? Security Regulations & Guidelines:  Is Your Business on the Path to Compliance?
Security Regulations & Guidelines: Is Your Business on the Path to Compliance?
 
Bahrain – Early adapting Glas Trösch products
Bahrain – Early adapting Glas Trösch productsBahrain – Early adapting Glas Trösch products
Bahrain – Early adapting Glas Trösch products
 
Insights From the Lean Startup Conference 2016
Insights From the Lean Startup Conference 2016Insights From the Lean Startup Conference 2016
Insights From the Lean Startup Conference 2016
 
How to Pitch to Investors
How to Pitch to InvestorsHow to Pitch to Investors
How to Pitch to Investors
 
How To Drive User Engagement By Creating Habits
How To Drive User Engagement By Creating HabitsHow To Drive User Engagement By Creating Habits
How To Drive User Engagement By Creating Habits
 
GtoPdb_ITMAT_2017
GtoPdb_ITMAT_2017GtoPdb_ITMAT_2017
GtoPdb_ITMAT_2017
 
Designing Superpowering Experiences
Designing Superpowering ExperiencesDesigning Superpowering Experiences
Designing Superpowering Experiences
 
Intelligence artificielle et e-commerce
Intelligence artificielle et e-commerceIntelligence artificielle et e-commerce
Intelligence artificielle et e-commerce
 

Similar to Solid State Drives (SSDs) -What it Takes to Make Data Go Away

Getting The Most Out Of Your Flash/SSDs
Getting The Most Out Of Your Flash/SSDsGetting The Most Out Of Your Flash/SSDs
Getting The Most Out Of Your Flash/SSDsAerospike, Inc.
 
Designing SSD-friendly Applications for Better Application Performance and Hi...
Designing SSD-friendly Applications for Better Application Performance and Hi...Designing SSD-friendly Applications for Better Application Performance and Hi...
Designing SSD-friendly Applications for Better Application Performance and Hi...Zhenyun Zhuang
 
SSDs: A New Generation of Storage Devices
SSDs: A New Generation of Storage DevicesSSDs: A New Generation of Storage Devices
SSDs: A New Generation of Storage DevicesHTS Hosting
 
SSD Seminar Report
SSD Seminar ReportSSD Seminar Report
SSD Seminar ReportVishalKSetti
 
Dell whitepaper busting solid state storage myths
Dell whitepaper busting solid state storage mythsDell whitepaper busting solid state storage myths
Dell whitepaper busting solid state storage mythsNatalie Cerullo
 
Open Ware Ramsan Dram Ssd
Open Ware Ramsan  Dram SsdOpen Ware Ramsan  Dram Ssd
Open Ware Ramsan Dram SsdSidnir Vieira
 
Solid State Drives - Seminar Report for Semester 6 Computer Engineering - VIT...
Solid State Drives - Seminar Report for Semester 6 Computer Engineering - VIT...Solid State Drives - Seminar Report for Semester 6 Computer Engineering - VIT...
Solid State Drives - Seminar Report for Semester 6 Computer Engineering - VIT...ravipbhat
 
Apresentacao Solid Access Corp Presentation Openware 5 20 10
Apresentacao Solid Access Corp Presentation Openware 5 20 10Apresentacao Solid Access Corp Presentation Openware 5 20 10
Apresentacao Solid Access Corp Presentation Openware 5 20 10Sidnir Vieira
 
What is the average rotational latency of this disk drive What seek.docx
 What is the average rotational latency of this disk drive  What seek.docx What is the average rotational latency of this disk drive  What seek.docx
What is the average rotational latency of this disk drive What seek.docxajoy21
 
5 Things You Need to Know About Enterprise Fl
 5 Things You Need to Know About Enterprise Fl 5 Things You Need to Know About Enterprise Fl
5 Things You Need to Know About Enterprise FlWestern Digital
 
MySQL Oslayer performace optimization
MySQL  Oslayer performace optimizationMySQL  Oslayer performace optimization
MySQL Oslayer performace optimizationLouis liu
 
AsawariKhedkar_SSD_HDD_Comparison
AsawariKhedkar_SSD_HDD_ComparisonAsawariKhedkar_SSD_HDD_Comparison
AsawariKhedkar_SSD_HDD_ComparisonAsawari Khedkar
 
Ceph Day Shanghai - SSD/NVM Technology Boosting Ceph Performance
Ceph Day Shanghai - SSD/NVM Technology Boosting Ceph Performance Ceph Day Shanghai - SSD/NVM Technology Boosting Ceph Performance
Ceph Day Shanghai - SSD/NVM Technology Boosting Ceph Performance Ceph Community
 
How to deploy SQL Server on an Microsoft Azure virtual machines
How to deploy SQL Server on an Microsoft Azure virtual machinesHow to deploy SQL Server on an Microsoft Azure virtual machines
How to deploy SQL Server on an Microsoft Azure virtual machinesSolarWinds
 
Insiders Guide- Managing Storage Performance
Insiders Guide- Managing Storage PerformanceInsiders Guide- Managing Storage Performance
Insiders Guide- Managing Storage PerformanceDataCore Software
 

Similar to Solid State Drives (SSDs) -What it Takes to Make Data Go Away (20)

Getting The Most Out Of Your Flash/SSDs
Getting The Most Out Of Your Flash/SSDsGetting The Most Out Of Your Flash/SSDs
Getting The Most Out Of Your Flash/SSDs
 
Designing SSD-friendly Applications for Better Application Performance and Hi...
Designing SSD-friendly Applications for Better Application Performance and Hi...Designing SSD-friendly Applications for Better Application Performance and Hi...
Designing SSD-friendly Applications for Better Application Performance and Hi...
 
Generic SAN Acceleration White Paper DRAFT
Generic SAN Acceleration White Paper DRAFTGeneric SAN Acceleration White Paper DRAFT
Generic SAN Acceleration White Paper DRAFT
 
SSDs: A New Generation of Storage Devices
SSDs: A New Generation of Storage DevicesSSDs: A New Generation of Storage Devices
SSDs: A New Generation of Storage Devices
 
SSD Seminar Report
SSD Seminar ReportSSD Seminar Report
SSD Seminar Report
 
Dell whitepaper busting solid state storage myths
Dell whitepaper busting solid state storage mythsDell whitepaper busting solid state storage myths
Dell whitepaper busting solid state storage myths
 
Open Ware Ramsan Dram Ssd
Open Ware Ramsan  Dram SsdOpen Ware Ramsan  Dram Ssd
Open Ware Ramsan Dram Ssd
 
Solid State Drives - Seminar Report for Semester 6 Computer Engineering - VIT...
Solid State Drives - Seminar Report for Semester 6 Computer Engineering - VIT...Solid State Drives - Seminar Report for Semester 6 Computer Engineering - VIT...
Solid State Drives - Seminar Report for Semester 6 Computer Engineering - VIT...
 
Apresentacao Solid Access Corp Presentation Openware 5 20 10
Apresentacao Solid Access Corp Presentation Openware 5 20 10Apresentacao Solid Access Corp Presentation Openware 5 20 10
Apresentacao Solid Access Corp Presentation Openware 5 20 10
 
Cor T558 Wh08
Cor T558 Wh08Cor T558 Wh08
Cor T558 Wh08
 
SSD-Bondi.pptx
SSD-Bondi.pptxSSD-Bondi.pptx
SSD-Bondi.pptx
 
What is the average rotational latency of this disk drive What seek.docx
 What is the average rotational latency of this disk drive  What seek.docx What is the average rotational latency of this disk drive  What seek.docx
What is the average rotational latency of this disk drive What seek.docx
 
5 Things You Need to Know About Enterprise Fl
 5 Things You Need to Know About Enterprise Fl 5 Things You Need to Know About Enterprise Fl
5 Things You Need to Know About Enterprise Fl
 
MySQL Oslayer performace optimization
MySQL  Oslayer performace optimizationMySQL  Oslayer performace optimization
MySQL Oslayer performace optimization
 
AsawariKhedkar_SSD_HDD_Comparison
AsawariKhedkar_SSD_HDD_ComparisonAsawariKhedkar_SSD_HDD_Comparison
AsawariKhedkar_SSD_HDD_Comparison
 
Ceph Day Shanghai - SSD/NVM Technology Boosting Ceph Performance
Ceph Day Shanghai - SSD/NVM Technology Boosting Ceph Performance Ceph Day Shanghai - SSD/NVM Technology Boosting Ceph Performance
Ceph Day Shanghai - SSD/NVM Technology Boosting Ceph Performance
 
PC Hardware Servicing Hand Out 2
PC Hardware Servicing Hand Out 2PC Hardware Servicing Hand Out 2
PC Hardware Servicing Hand Out 2
 
Introduction to Hard Disk Drive by Vishal Garg
Introduction to Hard Disk Drive by Vishal GargIntroduction to Hard Disk Drive by Vishal Garg
Introduction to Hard Disk Drive by Vishal Garg
 
How to deploy SQL Server on an Microsoft Azure virtual machines
How to deploy SQL Server on an Microsoft Azure virtual machinesHow to deploy SQL Server on an Microsoft Azure virtual machines
How to deploy SQL Server on an Microsoft Azure virtual machines
 
Insiders Guide- Managing Storage Performance
Insiders Guide- Managing Storage PerformanceInsiders Guide- Managing Storage Performance
Insiders Guide- Managing Storage Performance
 

More from Blancco

Beyond Diagnostics & Erasure – The Future of Ultra-Efficient Mobile Device Pr...
Beyond Diagnostics & Erasure – The Future of Ultra-Efficient Mobile Device Pr...Beyond Diagnostics & Erasure – The Future of Ultra-Efficient Mobile Device Pr...
Beyond Diagnostics & Erasure – The Future of Ultra-Efficient Mobile Device Pr...Blancco
 
Enabling End-to-End Mobile Customer Journey
Enabling End-to-End Mobile Customer JourneyEnabling End-to-End Mobile Customer Journey
Enabling End-to-End Mobile Customer JourneyBlancco
 
Blancco Recharge - BMDE Optimizations & Updates
Blancco Recharge - BMDE Optimizations & UpdatesBlancco Recharge - BMDE Optimizations & Updates
Blancco Recharge - BMDE Optimizations & UpdatesBlancco
 
Meet GDPR ‘Right to Erasure’ Requirements: Erase Customer Data Permanently & ...
Meet GDPR ‘Right to Erasure’ Requirements: Erase Customer Data Permanently & ...Meet GDPR ‘Right to Erasure’ Requirements: Erase Customer Data Permanently & ...
Meet GDPR ‘Right to Erasure’ Requirements: Erase Customer Data Permanently & ...Blancco
 
Blancco Bytes- Product Updates for ITADs
Blancco Bytes- Product Updates for ITADsBlancco Bytes- Product Updates for ITADs
Blancco Bytes- Product Updates for ITADsBlancco
 
Toronto Event- How to Protect Data Throughout Its Lifecycle
Toronto Event- How to Protect Data Throughout Its Lifecycle Toronto Event- How to Protect Data Throughout Its Lifecycle
Toronto Event- How to Protect Data Throughout Its Lifecycle Blancco
 
[UK & EU Webinar] The Top 3 Data Sanitisation Challenges – And How to Overcom...
[UK & EU Webinar] The Top 3 Data Sanitisation Challenges – And How to Overcom...[UK & EU Webinar] The Top 3 Data Sanitisation Challenges – And How to Overcom...
[UK & EU Webinar] The Top 3 Data Sanitisation Challenges – And How to Overcom...Blancco
 
[US & Canda Webinar] The Top 3 Data Sanitization Challenges – And How to Over...
[US & Canda Webinar] The Top 3 Data Sanitization Challenges – And How to Over...[US & Canda Webinar] The Top 3 Data Sanitization Challenges – And How to Over...
[US & Canda Webinar] The Top 3 Data Sanitization Challenges – And How to Over...Blancco
 
Making the Case- Blancco Data Center Eraser Solution
Making the Case- Blancco Data Center Eraser Solution Making the Case- Blancco Data Center Eraser Solution
Making the Case- Blancco Data Center Eraser Solution Blancco
 
Data Erasure Management: How to Protect Data Throughout Its Lifecycle - Blanc...
Data Erasure Management: How to Protect Data Throughout Its Lifecycle - Blanc...Data Erasure Management: How to Protect Data Throughout Its Lifecycle - Blanc...
Data Erasure Management: How to Protect Data Throughout Its Lifecycle - Blanc...Blancco
 
EU GDPR- The Countdown to Compliance, Research Study Highlights
EU GDPR- The Countdown to Compliance, Research Study Highlights EU GDPR- The Countdown to Compliance, Research Study Highlights
EU GDPR- The Countdown to Compliance, Research Study Highlights Blancco
 
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...Blancco
 
Data Governance in the Enterprise: Highlights from Our Research Report
Data Governance in the Enterprise: Highlights from Our Research Report Data Governance in the Enterprise: Highlights from Our Research Report
Data Governance in the Enterprise: Highlights from Our Research Report Blancco
 
Webinar- Overcoming the Unseen Data Destrution Issues in Solid State Drives
Webinar- Overcoming the Unseen Data Destrution Issues in Solid State DrivesWebinar- Overcoming the Unseen Data Destrution Issues in Solid State Drives
Webinar- Overcoming the Unseen Data Destrution Issues in Solid State DrivesBlancco
 
Cloud Storage: How to Fight Off Data Security Threats & Stay Compliant
Cloud Storage: How to Fight Off Data Security Threats & Stay CompliantCloud Storage: How to Fight Off Data Security Threats & Stay Compliant
Cloud Storage: How to Fight Off Data Security Threats & Stay CompliantBlancco
 
Delete vs Erase: How Are Companies Wiping Active Files
Delete vs Erase: How Are Companies Wiping Active Files Delete vs Erase: How Are Companies Wiping Active Files
Delete vs Erase: How Are Companies Wiping Active Files Blancco
 
Data Sanitization: When, Why & How
Data Sanitization: When, Why & How Data Sanitization: When, Why & How
Data Sanitization: When, Why & How Blancco
 
An Introduction to Live Environment and Cloud Eraser
An Introduction to Live Environment and Cloud EraserAn Introduction to Live Environment and Cloud Eraser
An Introduction to Live Environment and Cloud EraserBlancco
 
Data erasure's role in limiting cyber attacks
Data erasure's role in limiting cyber attacksData erasure's role in limiting cyber attacks
Data erasure's role in limiting cyber attacksBlancco
 
What One Digital Forensics Expert Found on Hundreds of Hard Drives, iPhones a...
What One Digital Forensics Expert Found on Hundreds of Hard Drives, iPhones a...What One Digital Forensics Expert Found on Hundreds of Hard Drives, iPhones a...
What One Digital Forensics Expert Found on Hundreds of Hard Drives, iPhones a...Blancco
 

More from Blancco (20)

Beyond Diagnostics & Erasure – The Future of Ultra-Efficient Mobile Device Pr...
Beyond Diagnostics & Erasure – The Future of Ultra-Efficient Mobile Device Pr...Beyond Diagnostics & Erasure – The Future of Ultra-Efficient Mobile Device Pr...
Beyond Diagnostics & Erasure – The Future of Ultra-Efficient Mobile Device Pr...
 
Enabling End-to-End Mobile Customer Journey
Enabling End-to-End Mobile Customer JourneyEnabling End-to-End Mobile Customer Journey
Enabling End-to-End Mobile Customer Journey
 
Blancco Recharge - BMDE Optimizations & Updates
Blancco Recharge - BMDE Optimizations & UpdatesBlancco Recharge - BMDE Optimizations & Updates
Blancco Recharge - BMDE Optimizations & Updates
 
Meet GDPR ‘Right to Erasure’ Requirements: Erase Customer Data Permanently & ...
Meet GDPR ‘Right to Erasure’ Requirements: Erase Customer Data Permanently & ...Meet GDPR ‘Right to Erasure’ Requirements: Erase Customer Data Permanently & ...
Meet GDPR ‘Right to Erasure’ Requirements: Erase Customer Data Permanently & ...
 
Blancco Bytes- Product Updates for ITADs
Blancco Bytes- Product Updates for ITADsBlancco Bytes- Product Updates for ITADs
Blancco Bytes- Product Updates for ITADs
 
Toronto Event- How to Protect Data Throughout Its Lifecycle
Toronto Event- How to Protect Data Throughout Its Lifecycle Toronto Event- How to Protect Data Throughout Its Lifecycle
Toronto Event- How to Protect Data Throughout Its Lifecycle
 
[UK & EU Webinar] The Top 3 Data Sanitisation Challenges – And How to Overcom...
[UK & EU Webinar] The Top 3 Data Sanitisation Challenges – And How to Overcom...[UK & EU Webinar] The Top 3 Data Sanitisation Challenges – And How to Overcom...
[UK & EU Webinar] The Top 3 Data Sanitisation Challenges – And How to Overcom...
 
[US & Canda Webinar] The Top 3 Data Sanitization Challenges – And How to Over...
[US & Canda Webinar] The Top 3 Data Sanitization Challenges – And How to Over...[US & Canda Webinar] The Top 3 Data Sanitization Challenges – And How to Over...
[US & Canda Webinar] The Top 3 Data Sanitization Challenges – And How to Over...
 
Making the Case- Blancco Data Center Eraser Solution
Making the Case- Blancco Data Center Eraser Solution Making the Case- Blancco Data Center Eraser Solution
Making the Case- Blancco Data Center Eraser Solution
 
Data Erasure Management: How to Protect Data Throughout Its Lifecycle - Blanc...
Data Erasure Management: How to Protect Data Throughout Its Lifecycle - Blanc...Data Erasure Management: How to Protect Data Throughout Its Lifecycle - Blanc...
Data Erasure Management: How to Protect Data Throughout Its Lifecycle - Blanc...
 
EU GDPR- The Countdown to Compliance, Research Study Highlights
EU GDPR- The Countdown to Compliance, Research Study Highlights EU GDPR- The Countdown to Compliance, Research Study Highlights
EU GDPR- The Countdown to Compliance, Research Study Highlights
 
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
IAPP Canada Privacy Symposium- "Data Retention Is a Team Sport: How to Get It...
 
Data Governance in the Enterprise: Highlights from Our Research Report
Data Governance in the Enterprise: Highlights from Our Research Report Data Governance in the Enterprise: Highlights from Our Research Report
Data Governance in the Enterprise: Highlights from Our Research Report
 
Webinar- Overcoming the Unseen Data Destrution Issues in Solid State Drives
Webinar- Overcoming the Unseen Data Destrution Issues in Solid State DrivesWebinar- Overcoming the Unseen Data Destrution Issues in Solid State Drives
Webinar- Overcoming the Unseen Data Destrution Issues in Solid State Drives
 
Cloud Storage: How to Fight Off Data Security Threats & Stay Compliant
Cloud Storage: How to Fight Off Data Security Threats & Stay CompliantCloud Storage: How to Fight Off Data Security Threats & Stay Compliant
Cloud Storage: How to Fight Off Data Security Threats & Stay Compliant
 
Delete vs Erase: How Are Companies Wiping Active Files
Delete vs Erase: How Are Companies Wiping Active Files Delete vs Erase: How Are Companies Wiping Active Files
Delete vs Erase: How Are Companies Wiping Active Files
 
Data Sanitization: When, Why & How
Data Sanitization: When, Why & How Data Sanitization: When, Why & How
Data Sanitization: When, Why & How
 
An Introduction to Live Environment and Cloud Eraser
An Introduction to Live Environment and Cloud EraserAn Introduction to Live Environment and Cloud Eraser
An Introduction to Live Environment and Cloud Eraser
 
Data erasure's role in limiting cyber attacks
Data erasure's role in limiting cyber attacksData erasure's role in limiting cyber attacks
Data erasure's role in limiting cyber attacks
 
What One Digital Forensics Expert Found on Hundreds of Hard Drives, iPhones a...
What One Digital Forensics Expert Found on Hundreds of Hard Drives, iPhones a...What One Digital Forensics Expert Found on Hundreds of Hard Drives, iPhones a...
What One Digital Forensics Expert Found on Hundreds of Hard Drives, iPhones a...
 

Recently uploaded

Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusZilliz
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...apidays
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfOverkill Security
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbuapidays
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024The Digital Insurer
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...apidays
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024The Digital Insurer
 

Recently uploaded (20)

Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
A Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source MilvusA Beginners Guide to Building a RAG App Using Open Source Milvus
A Beginners Guide to Building a RAG App Using Open Source Milvus
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 

Solid State Drives (SSDs) -What it Takes to Make Data Go Away

  • 2. Thanks to  Made possible by
  • 3. Preview of key points  Data erasure fundamentals  Solid State Drives  Enterprise data destruction that  lets you forget about the technology  provable
  • 4. Data erasure fundamentals  Deletion does not equal destruction  Security is always an after thought in hardware design  Different technologies require different methods  Can be a black-box
  • 5. HowSSDs are different than HDDs and why that impacts security You can read/write a given “page” of a magnetic HDD as many times as you like
  • 6. HowSSDs are different than HDDs and why that impacts security You can read/write a given “page” of a magnetic HDD as many times as you like And there’s just 2 operations – read and write
  • 7. HowSSDs are different than HDDs and why that impacts security Programmed Erased writeerase  NAND memory has 3 operations write (aka program), read and erase  Block can only be written once, then must be completely erased and rewritten Read many
  • 8. HowSSDs are different than HDDs and why that impacts security  NAND memory is bits organized into blocks  Start off will all bits set to 1  Write a block by setting necessary bits to 0 so that the block reflects the data you want to store  Now you have a “programmed” block storing the data  You can read that block repeatedly  (Reading it too many times will disturb nearby blocks)  When you need to update a single bit within that block you need to first erase the entire block and re-write the whole thing  Technically if that the bit you want to write is a 0 you could update just that bit  That’s a 50/50 chance  But normally you have to update more than one bit. So what’s the chance that all the bits you need you to change are going to be 0? If even one 1 bit needs to go from 0 to 1 you have to  Read the entire block into SSD RAM  Update the bits or bytes or words necessary  Erase the block  Re-write the block
  • 9. HowSSDs are different than HDDs and why that impacts security  But NAND can only be programmed/erased so many times  Each p/e cycle causes physical damage to the medium  In real life some chunks of data get updated far more frequently than others  So SSD manufacturers implement  Wear levelling  Over-provisioning
  • 10. HowSSDs are different than HDDs and why that impacts security Wear levelling and over-provisioning
  • 11. HowSSDs are different than HDDs and why that impacts security  But to make SSDs take off really fast, they didn’t want to make every OS manufacture implement a new physical file system with knowledge specific to each implementation of NAND as SSD  So make an SSD look like a HDD and just translate it Application Operating System ATA driver ATA commands
  • 12. HowSSDs are different than HDDs and why that impacts security Application Operating System ATA driver ATA commands Flash translation layer (FTL) Direct, page-for-page
  • 14. Other issues  Freeze lock  BIOS of most modern computers blocks access to these commands with a “freeze lock” on the drive’s security feature set.  Unless the freeze lock is removed, it’s extremely difficult to conduct the necessary firmware-based erasure that scrubs entire SSD storage
  • 15. Other issues  What is ATA Secure Erase?  Set of commands embedded in most hard drives since 2001  Secure Erase is a command not a physical operation  Therefore it’s all about the implementation (i.e. code) behind that command  “it’s up to each manufacturer to implement it correctly. In their review of the secure erase command,Wei et al., 2011, have shown that over the 12 models of SSDs studied, only eight offered the ATA Secure Erase functionality, and over those eight drives, three had buggy implementations [11].” - http://codecapsule.com/2014/02 /12/coding-for-ssds-part-4- advanced-functionalities-and- internal-parallelism/ https://www.usenix.org/leg acy/event/fast11/tech/full_ papers/Wei.pdf
  • 16. Other issues  Cryptographic “erasure”  Drive firmware encrypts each page  SSD or HDD  To “erase” drive – just overwrite the key  In theory – great  But encryption in theory and in practice are 2 very different things  Over and over again see poor encryption implementations  “Given the bugs we found in some implementations of secure erase commands, it is unduly optimistic to assume that SSD vendors will properly sanitize the key store. Further, there is no way verify that erasure has occurred”  https://www.usenix.org/legacy/event/fast11/tech/full_papers/Wei.pdf  Bruce Schneier says, cryptographic systems “must be implemented exactly, perfectly, or they will fail.” (https://www.schneier.com/essays/archives/1997/01/why_crypt ography_is.html)  https://www.owasp.org/images/5/57/OWASPIL2011- ErezMetula-WhenCryptoGoesWrong.pdf
  • 17. Bottom line  SSD erasure  Must deal with  Flash translation layer  Freeze lock  Requires manufacturer specific logic  OEM cooperation  Multi-stage, multi-method  Verifiable  Provable  Reporting  Applies beyond just SSD © 2017 Monterey Technology Group Inc.
  • 20. SSD Erasure Approvals  The Finnish Communications Regulatory Authority (FICORA) has approved Blancco erasure software for erasing data from hard drives and Solid State Drives.  The AIVD is the General Intelligence and Security Service of the Netherlands and evaluate information security products. In their deployment advisory for Blancco 5 they state that, for SSD media, the “Blancco SSD Erasure”-standard should be used.
  • 21. Additional Resources  Research Study: Security Limitations of Solid State Drives  https://www.blancco.com/resources/rs-security-limitations-of- ssds  Whitepaper: SSDs and the Unseen Data Destruction Risks  https://www.blancco.com/resources/wp-a-look-inside-ssds- unseen-data-destruction-risks  Free Evaluation: Blancco Drive Eraser for HDDs and SSDs  http://info.blancco.com/en-eval-blancco-5