Login Register


Stepping up my security filter_list
Author
Message
RE: Stepping up my security #31
(08-15-2016, 01:53 AM)God Wrote:
(08-15-2016, 01:20 AM)roger_smith Wrote:
(08-15-2016, 12:58 AM)God Wrote: Bookmarked. Although I would like to see some proof of concept somewhere. Specifically studies and experiments done entirely on overwrite/clear methods on drives. I think that would be more useful than NIST guidelines that tell you to overwrite your hard drive, and overwrite it more to be safer. Of course that's simplified but it's still nothing we haven't heard before and doesn't do a great job of lowering our suspicions.

To clarify, you understand that NIST is the National Institute of Standards and Technology right? They create the Special Publications in guidance w/ the National Security Agency (NSA) as required under the Computer Security Act of 1987. These are the guides that the Federal Government of the United States of America uses to secure their Top Secret data.

The proof of concept you seek exists, I'm sure plenty has been published on the Internetz. Ultimately all I'm saying is that if these guides from NIST are good enough to protect US Top Secret data such as launch codes and the like, it's good enough for me Wink

Remember the term "Top Secret" really means something. It means data that if exposed could cause "exceptionally grave" damage to the nation.
"Secret" classification means data that if exposed could cause "serious" damage.
"Confidential" is data that could cause damage if exposed.
There's also "sensitive but unclassified" data.

EDIT: I should say that the Fed Gov't is REQUIRED to use these guides under CSA 1987.

Also, the CSA 1987 was repealed by the Federal Information Security Management Act of 2002, but FISMA still assigned the same requirements of NIST/NSA, so it's a net difference of 0 basically.

I understand who the NIST is. I'm just saying there is still some grey areas despite that.
Quote:While most devices support some form of Clear, not all devices have a reli
able Purge
mechanism. For moderate confidentiality data, the media owner may choose to accept the risk of
applying Clear techniques to the media, acknowledging that some data may be able to be
retrieved by someone with the time, knowledge, and skills to do so.

I assume someone who is attempting to stay out of jail/prison would classify their information as high confidentiality. Based on this it sounds like clear techniques would not be suitable. But the clear techniques recommend 1 -2 overwrites for most devices, does continual reuse of the clear techniques on the device eventually lessen recovery? If 1-2 overwrites isn't the best choice for something with moderate + confidentiality, does 3-5, 7-10 overwrites make it suitable? Otherwise there's no reason to feel safer after re-writing when there's still too much risk unless you have the time/resources to purge and/or destroy.

I don't mean to undermine any of the work done here I'm just trying to point out where there might be grey areas for some people. I hope you understand what I'm getting at.

I believe I understand what you're getting at, but it's not really gray area. It ultimately depends on the risk appetite of the data owner. If they're willing to "take that chance" then that is their decision. They need to do a risk assessment and decide how much risk they are willing to live with, and apply the appropriate controls. In the case of Top Secret data, the US is unwilling to take a chance of that data being recoverable, regardless of the number of passes a clear or purge does. The only acceptable solution in terms of Top Secret data is total destruction of the storage media. They are planning not only for current known recovery methods, but potentially unknown methods as well.

As an end user, one has to decide the value of the data on their system, and how willing they are to "tempt fate" should that data fall into the wrong hands.

This document may be of interest to you. It shows the author attempting to recover data w/ the use of an electron microscope. He draws the conclusion that recovery of data after a number of write passes is infeasible.

https://www.vidarholen.net/~vidar/overwr...e_data.pdf

Now let me ask you this: How long do you think it takes to perform a wipe that effective on a modern hard drive? The answer is a VERY long time. When exploring DoD wipe standards for hard drives exceeding 1TB on a dedicated drive wiping machine, we had estimates of about 1 week to fully complete a wipe. Grab a Snickers...
---
Click here to get started with Linux!

If I helped you, please +rep me, apparently we've started over on Rep and I'd like to break 100 again...

Inori Wrote: got clickbaited by roger

Reply

RE: Stepping up my security #32
Here is the main representative I use for security and anonymity. Feel free to contact him any time. (contact details hidden from leechers)
Spoiler:
[Image: VZFo4tv.png]

Reply

RE: Stepping up my security #33
(08-15-2016, 02:42 AM)roger_smith Wrote:
(08-15-2016, 01:53 AM)God Wrote:
(08-15-2016, 01:20 AM)roger_smith Wrote: To clarify, you understand that NIST is the National Institute of Standards and Technology right? They create the Special Publications in guidance w/ the National Security Agency (NSA) as required under the Computer Security Act of 1987. These are the guides that the Federal Government of the United States of America uses to secure their Top Secret data.

The proof of concept you seek exists, I'm sure plenty has been published on the Internetz. Ultimately all I'm saying is that if these guides from NIST are good enough to protect US Top Secret data such as launch codes and the like, it's good enough for me Wink

Remember the term "Top Secret" really means something. It means data that if exposed could cause "exceptionally grave" damage to the nation.
"Secret" classification means data that if exposed could cause "serious" damage.
"Confidential" is data that could cause damage if exposed.
There's also "sensitive but unclassified" data.

EDIT: I should say that the Fed Gov't is REQUIRED to use these guides under CSA 1987.

Also, the CSA 1987 was repealed by the Federal Information Security Management Act of 2002, but FISMA still assigned the same requirements of NIST/NSA, so it's a net difference of 0 basically.

I understand who the NIST is. I'm just saying there is still some grey areas despite that.
Quote:While most devices support some form of Clear, not all devices have a reli
able Purge
mechanism. For moderate confidentiality data, the media owner may choose to accept the risk of
applying Clear techniques to the media, acknowledging that some data may be able to be
retrieved by someone with the time, knowledge, and skills to do so.

I assume someone who is attempting to stay out of jail/prison would classify their information as high confidentiality. Based on this it sounds like clear techniques would not be suitable. But the clear techniques recommend 1 -2 overwrites for most devices, does continual reuse of the clear techniques on the device eventually lessen recovery? If 1-2 overwrites isn't the best choice for something with moderate + confidentiality, does 3-5, 7-10 overwrites make it suitable? Otherwise there's no reason to feel safer after re-writing when there's still too much risk unless you have the time/resources to purge and/or destroy.

I don't mean to undermine any of the work done here I'm just trying to point out where there might be grey areas for some people. I hope you understand what I'm getting at.

I believe I understand what you're getting at, but it's not really gray area. It ultimately depends on the risk appetite of the data owner. If they're willing to "take that chance" then that is their decision. They need to do a risk assessment and decide how much risk they are willing to live with, and apply the appropriate controls. In the case of Top Secret data, the US is unwilling to take a chance of that data being recoverable, regardless of the number of passes a clear or purge does. The only acceptable solution in terms of Top Secret data is total destruction of the storage media. They are planning not only for current known recovery methods, but potentially unknown methods as well.

As an end user, one has to decide the value of the data on their system, and how willing they are to "tempt fate" should that data fall into the wrong hands.

This document may be of interest to you. It shows the author attempting to recover data w/ the use of an electron microscope. He draws the conclusion that recovery of data after a number of write passes is infeasible.

https://www.vidarholen.net/~vidar/overwr...e_data.pdf

Now let me ask you this: How long do you think it takes to perform a wipe that effective on a modern hard drive? The answer is a VERY long time. When exploring DoD wipe standards for hard drives exceeding 1TB on a dedicated drive wiping machine, we had estimates of about 1 week to fully complete a wipe. Grab a Snickers...

Okay, I think I'm pretty much with you here. I'll read through that document after this post but I appreciate the friendly discourse from you and the information you find and share.
"If you look for the light, you can often find it. But if you look for the dark, that is all you will ever see.”


[+] 1 user Likes Nil's post
Reply

RE: Stepping up my security #34
(08-15-2016, 03:49 AM)God Wrote:
(08-15-2016, 02:42 AM)roger_smith Wrote:
(08-15-2016, 01:53 AM)God Wrote: I understand who the NIST is. I'm just saying there is still some grey areas despite that.

I assume someone who is attempting to stay out of jail/prison would classify their information as high confidentiality. Based on this it sounds like clear techniques would not be suitable. But the clear techniques recommend 1 -2 overwrites for most devices, does continual reuse of the clear techniques on the device eventually lessen recovery? If 1-2 overwrites isn't the best choice for something with moderate + confidentiality, does 3-5, 7-10 overwrites make it suitable? Otherwise there's no reason to feel safer after re-writing when there's still too much risk unless you have the time/resources to purge and/or destroy.

I don't mean to undermine any of the work done here I'm just trying to point out where there might be grey areas for some people. I hope you understand what I'm getting at.

I believe I understand what you're getting at, but it's not really gray area. It ultimately depends on the risk appetite of the data owner. If they're willing to "take that chance" then that is their decision. They need to do a risk assessment and decide how much risk they are willing to live with, and apply the appropriate controls. In the case of Top Secret data, the US is unwilling to take a chance of that data being recoverable, regardless of the number of passes a clear or purge does. The only acceptable solution in terms of Top Secret data is total destruction of the storage media. They are planning not only for current known recovery methods, but potentially unknown methods as well.

As an end user, one has to decide the value of the data on their system, and how willing they are to "tempt fate" should that data fall into the wrong hands.

This document may be of interest to you. It shows the author attempting to recover data w/ the use of an electron microscope. He draws the conclusion that recovery of data after a number of write passes is infeasible.

https://www.vidarholen.net/~vidar/overwr...e_data.pdf

Now let me ask you this: How long do you think it takes to perform a wipe that effective on a modern hard drive? The answer is a VERY long time. When exploring DoD wipe standards for hard drives exceeding 1TB on a dedicated drive wiping machine, we had estimates of about 1 week to fully complete a wipe. Grab a Snickers...

Okay, I think I'm pretty much with you here. I'll read through that document after this post but I appreciate the friendly discourse from you and the information you find and share.

No problem friendo Smile The main goal at the end of the day is learnings :-D
---
Click here to get started with Linux!

If I helped you, please +rep me, apparently we've started over on Rep and I'd like to break 100 again...

Inori Wrote: got clickbaited by roger

[+] 1 user Likes roger_smith's post
Reply

RE: Stepping up my security #35
honestly if your worried dump all your USBs, hard drives and anything else that has something on it in the garbage far from your house. maybe even a lake.

there are companies that can find everything even after a fresh OS wipe. believe us when we say the data is still there.

Best way to prevent it, is to pyhiscally remove it. and start over.

Im sure at somepoint your transmitted something not securley at some point.

Your best bet is if your into that kinda stuff have a laptop that your never log into anything with your name, address etc on it. like ever.

Dont connect to your internet. Use a neighboors Smile

Reply

RE: Stepping up my security #36
I know I've nuked a few phones in my day to keep cops from grabbing em.... Not 100% sure if it really works but I've never been hemmed up over cell phone evidence though.

Reply

RE: Stepping up my security #37
The only "sure" way of having peace of mind that nothing can be linked back to you, Is to smash your HDD to bits, purchase a new one and hit an Installation of your OS thereafter.

As for removable devices, encryption Is the way to go. And when In the hacking sector, "never" get complacent. Always be on the assumption that you're being watched and/or under attack.
[Image: AD83g1A.png]

Reply

RE: Stepping up my security #38
The security is there, but for how long?

[+] 2 users Like pvnk's post
Reply

RE: Stepping up my security #39
(08-19-2016, 07:25 PM)Primitive Wrote: The security is there, but for how long?

I swear I've seen that quote somewhere
===
~I know who you are~
I hacked THIS account

Reply

RE: Stepping up my security #40
(08-20-2016, 10:17 AM)Cosvo Wrote:
(08-19-2016, 07:25 PM)Primitive Wrote: The security is there, but for how long?

I swear I've seen that quote somewhere

It's in @mothered 's signature.

Reply







Users browsing this thread: 1 Guest(s)