How to securely erase (wipe) data from an SSD or hard drive - sanitize

preview_player
Показать описание
Learn how to use the sanitize command built into the firmware of your SSD or hard drive to securely erase / remove / wipe the data.

Sanitize Purge Cryptographic erase (CE) will change the media encryption key on a device, typically encoded today using AES256. The benefits are that it is secure and fast, typically just a few seconds.
Sanitize Purge Overwrite securely overwrites the storage media with various patterns that can be verified later. Most hard drives support even if they don’t support CE.
Sanitize Purge Block Erase can zero out the erase blocks on SSDs, the native way that NAND flash operates for erasing, able to complete in seconds to minutes for an entire SSD.

Using NVMe-CLI
Find a NVMe SSD’s sanitize capabilities through Identify Controller command, to see what types it supports

nvme id-ctrl /dev/nvme0 -H | grep sanicap -A 5

Send Sanitize command with action -2, block erase
nvme sanitize -a 2 /dev/nvme0n1

Loop: Monitor Sanitize Status with Sanitize Log
nvme sanitize-log -H /dev/nvme0n1

Sanitize completes
nvme sanitize-log -H /dev/nvme0n1
Sanitize Progress (SPROG) : 65535
Sanitize Status (SSTAT) : 0x101
[2:0] Most Recent Sanitize Command Completed Successfully.

With Open Sea Chest
openSeaChest_Erase -d /dev/sgX --sanitize overwrite

If you want to learn more about media sanitization, here are some links
Data Sanitization for the Circular Economy (OCP)
New IEEE Media Sanitization Specification Enables Circular Economy for Storage

Is The Data Really Gone? A Primer on Data Sanitization Brighttalk Webcast
SDC2022 – Storage Sanitization - The Right Way to Make Data Go Away
Рекомендации по теме
Комментарии
Автор

Just a question is shredding also a safe type to wipe hd and ssd drives and consider a cryptographic erase. Thank you

calvin
Автор

Thanks. I've been looking for programs to sanitze my SSD prior to travel... Now, I found it... Thank you...

AlainLafond
Автор

I bought some 2.5 inch sas hard drives, 4 of them are write protected. I cant seem to erase the drives . Will that sanitize method work for that ?

freddobrowski
Автор

Interesting about not wanting to write repeatedly to SSD...what I'm seeking is an ability to wipe folders/directories/unused space (previously deleted) instead of reinstalling OS. I guess proper partitioning would have prevented that...

girohead
Автор

For me, my Samsung 970 Evo Plus nvme drives shows "Block Erase Sanitize Operation Not Supported"...

infinitestars
Автор

Title should specify Linux, Windows users can’t use the same way can they?

botsquad
Автор

I have tried both hdparm and openSeagate methods with an SSD. The device was compatible with block erase and crypto erase. I started the crypto erase method and checked for the status using the --progress sanitize command. However, I received an output like "sanitize command is not currently in progress. It is either complete or has not been run". Please note that I executed the status checking command within 1 minute of running the sanitize command. Even after that I tried block erase and the output was exactly the same.

vishnuchandran
Автор

Thank you for the video. I’ve been trying to learn more about how to properly restrained before I sell them. However, isn’t there some sort of program that will walk you through this graphically? There is no way I’m gonna remember all the typing in a little coat as you enter here, please let us know if there is an application that will walk you through this and make it easier. Thank you.

joeglennaz
Автор

i have this ssd that had some problem where it stopped showing up. After a while i was able to make it showing again but the data is just not showing up. The drive is blue in disk management somehow it's like no data is installed at all. Nothing is working i thought maybe if i just deleted everything on it then i could start over again and reinstall the games i had on the ssd. Or should i just admit defeat and that the ssd is broken and i should go get a new one?

gabriellebenard
Автор

Thank you for creating valuable content. I would really like to learn about other methods as well, such as SG utils. Can you please make more videos on those ?

vishnuchandran
Автор

Why is there nothing like this for windows?.. No one seems to have bothered making a free utility, so we have to rely on the manufacturers utilities which don't always work, and many time refuse to work with any other brand NVME.

Lloyd.B.
Автор

gparted shows 2 partitions of the same drive, one is the boot p1 and the other is the drive. If I'm correct I would need to identify the p2 in the sanitize command to prevent sanitizing the boot drive as well since there is only one drive on my laptop.

TBr-cd
Автор

Heard that there is some kind of D.O.D. erasure requirement for some sensitive data.

ronwatkins
Автор

Could you explain the response from 'grep sanicap', was the first response a mistake having missed the '-A 5' or a required step. And how are '-A 5' and '-a 2' determined. Is it just your experience that tells you those are the commands, or is it something in the list you got from a prior command that tells you which action to call? Is '-a 2' always sanitize?

tsonaqua
Автор

We are suspicious of anyone with a clicky keyboard. ....it's like a barking dog who
has a deaf owner. ..noise for noise sake, no care whatsoever for anyone within hearing range

relaxingnature
Автор

how do check where is my boot drive located in? I have 2 sdd that are identical and one has endeavour os and the other one has fedora, how do I tell them a part?

saintswolfgang_
Автор

I presume rhis utility is for skilled programers, quite difficult to understand for a layman like me

carlosroji
Автор

5 sec: bios of mb: security erase ssd. Done!

григориймосковский-вя