RE: Stepping up my security 08-15-2016, 03:49 AM
#33
(08-15-2016, 02:42 AM)roger_smith Wrote:(08-15-2016, 01:53 AM)God Wrote:(08-15-2016, 01:20 AM)roger_smith Wrote: To clarify, you understand that NIST is the National Institute of Standards and Technology right? They create the Special Publications in guidance w/ the National Security Agency (NSA) as required under the Computer Security Act of 1987. These are the guides that the Federal Government of the United States of America uses to secure their Top Secret data.
The proof of concept you seek exists, I'm sure plenty has been published on the Internetz. Ultimately all I'm saying is that if these guides from NIST are good enough to protect US Top Secret data such as launch codes and the like, it's good enough for me
Remember the term "Top Secret" really means something. It means data that if exposed could cause "exceptionally grave" damage to the nation.
"Secret" classification means data that if exposed could cause "serious" damage.
"Confidential" is data that could cause damage if exposed.
There's also "sensitive but unclassified" data.
EDIT: I should say that the Fed Gov't is REQUIRED to use these guides under CSA 1987.
Also, the CSA 1987 was repealed by the Federal Information Security Management Act of 2002, but FISMA still assigned the same requirements of NIST/NSA, so it's a net difference of 0 basically.
I understand who the NIST is. I'm just saying there is still some grey areas despite that.
Quote:While most devices support some form of Clear, not all devices have a reli
able Purge
mechanism. For moderate confidentiality data, the media owner may choose to accept the risk of
applying Clear techniques to the media, acknowledging that some data may be able to be
retrieved by someone with the time, knowledge, and skills to do so.
I assume someone who is attempting to stay out of jail/prison would classify their information as high confidentiality. Based on this it sounds like clear techniques would not be suitable. But the clear techniques recommend 1 -2 overwrites for most devices, does continual reuse of the clear techniques on the device eventually lessen recovery? If 1-2 overwrites isn't the best choice for something with moderate + confidentiality, does 3-5, 7-10 overwrites make it suitable? Otherwise there's no reason to feel safer after re-writing when there's still too much risk unless you have the time/resources to purge and/or destroy.
I don't mean to undermine any of the work done here I'm just trying to point out where there might be grey areas for some people. I hope you understand what I'm getting at.
I believe I understand what you're getting at, but it's not really gray area. It ultimately depends on the risk appetite of the data owner. If they're willing to "take that chance" then that is their decision. They need to do a risk assessment and decide how much risk they are willing to live with, and apply the appropriate controls. In the case of Top Secret data, the US is unwilling to take a chance of that data being recoverable, regardless of the number of passes a clear or purge does. The only acceptable solution in terms of Top Secret data is total destruction of the storage media. They are planning not only for current known recovery methods, but potentially unknown methods as well.
As an end user, one has to decide the value of the data on their system, and how willing they are to "tempt fate" should that data fall into the wrong hands.
This document may be of interest to you. It shows the author attempting to recover data w/ the use of an electron microscope. He draws the conclusion that recovery of data after a number of write passes is infeasible.
https://www.vidarholen.net/~vidar/overwr...e_data.pdf
Now let me ask you this: How long do you think it takes to perform a wipe that effective on a modern hard drive? The answer is a VERY long time. When exploring DoD wipe standards for hard drives exceeding 1TB on a dedicated drive wiping machine, we had estimates of about 1 week to fully complete a wipe. Grab a Snickers...
Okay, I think I'm pretty much with you here. I'll read through that document after this post but I appreciate the friendly discourse from you and the information you find and share.
"If you look for the light, you can often find it. But if you look for the dark, that is all you will ever see.”






![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)