EH-Net

Resources => News from the Outside World => Topic started by: jason on February 11, 2009, 03:20:05 PM



Title: 40% of the hard drives sold on Ebay still hold personal & corp data
Post by: jason on February 11, 2009, 03:20:05 PM
In a study by a forensics company in NY, 40% of the drives bought from Ebay still held personal or company data, including financial information and downloads from someone with a foot fetish. This is right on track with previous research that I've seen on the issue. It's that whole security mindset problem again.

http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=security&articleId=9127717&taxonomyId=17&intsrc=kc_top


Title: Re: 40% of the hard drives sold on Ebay still hold personal & corp data
Post by: jason on February 11, 2009, 03:25:16 PM
Here's the paper from Garfinkel that I was referring to:

http://www.computer.org/portal/cms_docs_security/security/v1n1/garfinkel.pdf


Title: Re: 40% of the hard drives sold on Ebay still hold personal & corp data
Post by: dalepearson on February 12, 2009, 09:06:12 AM
Hiya Jason,

I am surprised its only 40% to be honest.
I have only bought 2 drives that were 2nd hand, both external USB HDs, and both had only had a high level wipe, and full partition recovery was possible.

I have not read the links, so not sure if you are saying they just hadnt been deleted, or no appropriate data destruction had taken place.

It all comes back to awareness and education.


Title: Re: 40% of the hard drives sold on Ebay still hold personal & corp data
Post by: jason on February 12, 2009, 09:53:45 AM
In both of the cases above, I believe, the data was completely intact. IIRC in the study that Garfinkel did, they even found an intact disk from an ATM machine.