Are Multiple Passes Necessary for Permanent Data Erasure? (2024)

Summary:Exponential growth of data and rising cases of data breach incidents have necessitated organizations to not overlook data security concerns at the end-of-life of IT assets. Businesses need to realign their approach to how they deal with end-of-life equipment. The safest way to deal with devices at their disposal stage is to ensure they are permanently wiped and erased to ensure that data cannot be recovered even by laboratory techniques. Performing Data Erasure on storage devices that can be re-used is the most environment-friendly and cost-effective approach to data destruction. Data erasure generally involves overwriting the data stored in media with single or multiple overwriting cycles or Passes which may range from 1 pass (zeroes) to 35 passes (Peter Gutmann).

So, the question that arises is why we need multiple passes for data destruction.
Is performing more overwriting passes better than just performing lesser or even one?
Why do different global data erasure standards propose different overwriting passes?

Or which standard is suitable for a business or individual needing to perform permanent data erasure?

In this article, we will provide answers to all the above questions and help you understand the mechanism of overwriting using different passes for Hard Drives and SSDs.

How Many Passes Are Necessary For Permanently Wiping Hard Drives?

The answer to the number of passes to securely overwrite a hard drive permanently is not straightforward as it would involve several considerations including the technology, latest research findings, evolution of data erasure techniques, and recommended methods by governments and international agencies. Before we arrive at a conclusion, we would first need to understand the basics of hard drive erasure, the emergence of data erasure standards, and the evolution of faster and more complex flash-based storage media including the solid state drives.

Hard Disk Drives- Permanent Data Erasure

Deleting a file from your hard disk drive or formatting the entire hard drive does free up space on your hard disk but does not destroy the data making it easier to be recovered by freely available data recovery tools. Deleting simply removes the pointers to the file, making it invisible and allowing free space for further storage.

However, when a hard disk drive is overwritten with a stream of zeros, ones, or pseudo-random patterns on all sectors of a hard drive (all user-addressable locations including logical file storage locations), it leads to permanent erasure of data or media sanitization beyond any scope of recovery.

The Emergence of Data Erasure Standards - Specifying Differing Number of Passes

Data Erasure has been guided by various industry-specific and government-prescribed standards for data destruction, typically specifying the number of overwriting passes to be used for securely and permanently erase data. NISPOM (National Industrial Security Program) manual introduced in the year 1995 by the US Department of Defense specified DoD 3 Pass standard (DoD 5220.22-M) as a data erasure technique by overwriting all addressable locations with a character, its complement, and a pseudo-random character. However, in 2001, it was removed from the NISPOM manual and was not permitted for Top Secret Media.

Peter Gutmann, a computer scientist in the Department of Computer Science, University of Auckland, New Zealand, proposed a 35-pass erasure method to prevent data recovery using sophisticated tools such as magnetic force microscopes. However, the arrival of newer HDDs, that used PRML coding techniques instead of older MFM/RLL techniques used in early HDD, made Gutmann method obsolete. Gutmann’s contemporary, Bruce Schneier, a security expert, also proposed a 7 pass overwriting method to erase data. A German information security agency, BSI, in early 2000 devised a 7-pass method (VSITR) which became popular in Europe. Another standard published by Britain’s National Cyber Security Center, HMG Infosec Standard 5, proposed the Baseline method with 1 pass and the Enhanced method with three passes. Click here to learn more about 24 global data erasure standards.

NIST 800-88: Globally Adhered Media Sanitization Standard

NIST 800-88 with one write pass is the most preferred standard by the US federal government today. NIST (National Institute of Standards and Technology, U.S.) guidelines for media sanitization, first published in 2006 and revised in 2014, is now one of the most prevalent media sanitization guidelines in the world today. It specifies ‘Clear’ and ‘Purge’ as methods of media sanitization to attain data destruction through overwriting. The guidelines state that “for ATA disk drives manufactured after 2001 (over 15 GB) clearing by overwriting the media once is adequate to protect the media.” Also, the revised guidelines in 2014 stated that “For storage devices containing magnetic media, a single overwrite pass with a fixed pattern such as binary zeros typically hinders recovery of data even if state of the art laboratory techniques are applied to attempt to retrieve the data.” The NIST purge technique can also be executed with a single pass, although it also offers an inverted 3-pass method. NIST also recommends that hidden areas of the drive should also be addressed, before overwriting.

SSD Erasure- NIST Recommends 1 Pass with Specialized Commands

SSDs do not contain magnetic coatings. Instead, they rely on embedded processors & flash memory chips that retain data. Flash storage allows data to be written and erased from a given location for a fixed number of times (typically 10,000) in their lifecycle and this can exhaust the overall lifetime of SSD, making sanitization of SSDs complex. NIST recommends the erasure of SSDs with one overwriting pass combined with specialized commands. It proposes “Secure Erase, Block Erase, or Cryptographic Erasure” if supported by the SSD, as a standard erasure procedure.

Conclusion: Benefits of Single Overwriting Pass Outweighs the Multiple Passes

With the NIST guidelines of 2014, the fear of recovery after just one cycle of overwriting has been put to rest. NIST clearly states that one write pass is sufficient to erase data from drives beyond recovery. In recent years with innovations around the hard drive technology, such as the high data density on disk platters, makes data recovery impossible after a single overwriting pass followed by verification of the overwrite.

Overwriting by multiple passes can be considered, however, organizations will have to consider the time and cost involved in each processed IT asset being overwritten multiple times. Also, global government bodies (NIST 800-88, NCSC, BSI, etc.) and agencies advocate 1 write pass as the standard method for overwriting, but it is mandated to follow the overwriting process with actual verification of the overwrite, ensuring that every addressable storage locations have been overwritten.

NIST SP 800-88 guidelines, however, do not offer a one size fits all formula for erasing hard drives and it shall be an organizational prerogative to ensure which method is more suitable for them and how many overwriting passes are needed as per the security categorization and sensitivity of data to be erased. You can read more about the different erasure standards and learn how a offers a solution that can help you securely and permanently erase data on all storage drives including HDDs, SSDs across PC, Mac, and servers here.

Are Multiple Passes Necessary for Permanent Data Erasure? (2024)

FAQs

Are Multiple Passes Necessary for Permanent Data Erasure? ›

So, how many times should you overwrite a hard disk for complete data erasure? The answer: One pass is enough.

Is one pass erase enough? ›

Is 1 pass erase enough? Yes, according to NIST SP 800-88 Rev 1, one pass overwrite with binary Zeros or Ones is enough to erase data permanently.

How many passes to erase an HDD? ›

One overwriting pass for most HDD erasure.

Remember to weigh data sensitivity against the costs of a higher level of security and the time you want to spend on each processed asset. More passes take longer and are usually unnecessary.

Is 7 pass erase secure enough? ›

It follows that choosing the 7-pass option will be the most effective way of erasing your drive. The United States Department of Defense recommends using a 7-pass wipe to clean media.

Is 1 pass of pseudorandom data enough? ›

One pass of pseudorandom data is (more) than enough to securely erase a magnetic hard drive. A 2008 research paper tested real files on new and used magnetic hard disk drives, The results showed it is effectively impossible to accurately recover even a single ASCII character after just one erasure pass.

How many times should I overwrite my hard drive? ›

In the media sanitization circles, it is known as the US DoD data wipe standard. The standard involves overwriting the previously stored information on a hard drive with specific binary patterns repeatedly (3 times or 7 times) depending upon the number of passes defined in the organization's policy.

How many wipes does a hard drive take? ›

You Only Need to Wipe a Disk Once to Securely Erase It

For spinning-disks do 1-pass pseudorandom overwrite or pay a shredder. With modern disk densities there is no need for more than one write for a spinning hard drive. And if you do not want to reuse them then a chisel through the platters is all you need.

Can a hard drive be permanently erased? ›

Yes, it is possible to completely wipe a hard drive. Your computer comes with tools to help you wipe its hard drive. But it's not always easy to do, and if your computer has an SSD hard drive, you'll need to use encryption or perform a full format to reliably wipe it completely.

What is a 3 pass wipe? ›

The DoD Short Wipe

Pass 1: Overwrite all addressable locations with binary zeroes. Pass 2: Overwrite all addressable locations with binary ones (the compliment of the above). Pass 3: Overwrite all addressable locations with a random bit pattern.

How long does a 2 pass erase take? ›

Disk Utility has 4 options for this. I tried Option 2, which states that it is two-pass. It looks like it is going to take around 4-5 hours for one drive (2 TB).

Does eraser permanently delete files? ›

It supports both file and volume wiping. Eraser securely erases data by overwriting it such that the data is irrecoverable. It supports a variety of data destruction standards, including British HMG IS5 (Infosec Standard 5), American DoD 5220.22-M, and the Gutmann method which features a 35-pass overwrite.

What is the difference between 7 pass erase and 35-pass erase? ›

7-Pass Erase is highly secure, but it takes seven times longer than the Zero Out Data option. 35-Pass Erase: 35-Pass Erase provides the most security. It writes zeros to the entire disk 35 times, and takes 35 times as long as the Zero Out Data Option.

What is the most secure method of data erasure? ›

Top 7 Methods of Secure Data Sanitization
  1. Degaussing. Degaussing involves using a machine to produce a magnetic field, effectively disrupting the magnetic domains on storage media, rendering the data unreadable. ...
  2. Overwriting. ...
  3. Physical Destruction. ...
  4. Secure Erase. ...
  5. Cryptographic Erasure. ...
  6. Shredding. ...
  7. Electromagnetic Destruction.
Nov 14, 2023

What is the difference between random and pseudorandom? ›

Software-generated random numbers only are pseudorandom. They are not truly random because the computer uses an algorithm based on a distribution, and are not secure because they rely on deterministic, predictable algorithms.

What is pseudorandom pattern and why it called pseudorandom? ›

A string of binary digits (1's and 0's) is called a pseudorandom binary sequence when the bits appear to be random in the local sense, but they are in some way repeatable, hence only pseudorandom.

Why do we use a pseudorandom number rather than a truly random number generator? ›

Although sequences that are closer to truly random can be generated using hardware random number generators, pseudorandom number generators are important in practice for their speed in number generation and their reproducibility.

Is simple overwrite enough? ›

NIST clearly states that one write pass is sufficient to erase data from drives beyond recovery. In recent years with innovations around the hard drive technology, such as the high data density on disk platters, makes data recovery impossible after a single overwriting pass followed by verification of the overwrite.

What is the one pass zero erase method? ›

The One Pass Zeros Eraser Method is a data-wiping algorithm that involves overwriting all the data on a storage device with zeroes (0s) in a single pass. It is a variant of the Zero Pass Erasure method, where all data is overwritten with zeroes only once.

Should I wipe free space? ›

Leaving free space untouched poses significant risks to both personal and customer privacy and security. Residual data, also known as Data Remanence, persists even after completing common activities such as deleting or moving files.

How many times can you write to a hard drive? ›

The number of write cycles for a HDD is infinite for the platters (the actual magnetic discs). The read/write process is done by magnetic head 'floating' a hair's breadth above the platter surface. Nothing, in a properly functioning HDD, ever touches the platters, so there is no wear.

Top Articles
Google Data Breaches: Full Timeline Through 2023
I have a credit score of 730. Can I easily get approved for a home loan?
Public Opinion Obituaries Chambersburg Pa
Stadium Seats Near Me
Don Wallence Auto Sales Vehicles
Roblox Developers’ Journal
How do you mix essential oils with carrier oils?
Doby's Funeral Home Obituaries
You can put a price tag on the value of a personal finance education: $100,000
2021 Lexus IS for sale - Richardson, TX - craigslist
Oc Craiglsit
Hca Florida Middleburg Emergency Reviews
Aldi Sign In Careers
Dr Adj Redist Cadv Prin Amex Charge
Vandymania Com Forums
Jang Urdu Today
Google Doodle Baseball 76
Ratchet & Clank Future: Tools of Destruction
Leccion 4 Lesson Test
라이키 유출
Scout Shop Massapequa
Catherine Christiane Cruz
Reptile Expo Fayetteville Nc
Raz-Plus Literacy Essentials for PreK-6
Bjerrum difference plots - Big Chemical Encyclopedia
[PDF] NAVY RESERVE PERSONNEL MANUAL - Free Download PDF
Craigslist Battle Ground Washington
Sand Dollar Restaurant Anna Maria Island
Webworx Call Management
Revelry Room Seattle
Abga Gestation Calculator
Ofw Pinoy Channel Su
Dreamcargiveaways
Metra Union Pacific West Schedule
Mgm Virtual Roster Login
SF bay area cars & trucks "chevrolet 50" - craigslist
The Thing About ‘Dateline’
Mars Petcare 2037 American Italian Way Columbia Sc
Craigslist Tulsa Ok Farm And Garden
Indiana Jones 5 Showtimes Near Cinemark Stroud Mall And Xd
Metro Pcs Forest City Iowa
Obituaries in Hagerstown, MD | The Herald-Mail
Cnp Tx Venmo
Who Is Responsible for Writing Obituaries After Death? | Pottstown Funeral Home & Crematory
No Boundaries Pants For Men
Nina Flowers
Breaking down the Stafford trade
Mcoc Black Panther
Ronnie Mcnu*t Uncensored
Myapps Tesla Ultipro Sign In
Gummy Bear Hoco Proposal
Latest Posts
Article information

Author: Msgr. Refugio Daniel

Last Updated:

Views: 6306

Rating: 4.3 / 5 (74 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Msgr. Refugio Daniel

Birthday: 1999-09-15

Address: 8416 Beatty Center, Derekfort, VA 72092-0500

Phone: +6838967160603

Job: Mining Executive

Hobby: Woodworking, Knitting, Fishing, Coffee roasting, Kayaking, Horseback riding, Kite flying

Introduction: My name is Msgr. Refugio Daniel, I am a fine, precious, encouraging, calm, glamorous, vivacious, friendly person who loves writing and wants to share my knowledge and understanding with you.