Recently, whenever there is a discussion about secure erase of files on SSD/flash devices, I always think of the classic experiment from a psychology textbook. The one involves five monkeys in a cage and a banana.
In case, you have not heard about the experiment: it starts with five monkeys in a cage. A banana hung inside the cage with a ladder underneath. After a while, a monkey tries to climb the ladder to get the banana. As soon as he touches the ladder, all monkeys are sprayed with cold water. Another monkey tries to reach the banana with the same result. And so on, until the monkeys learn that the best way to stay dry is to prevent any monkey from attempting to reach the banana.
The next stage is to exclude cold water and replace one monkey with a new one. Of course, the new monkey tries to get the banana and the other monkeys attacked him to prevent that. After few attempts, the new monkey will learn that touching the ladder is bad.
Next, replace another of the original five monkeys with a new one. The newcomer goes to the ladder and is attacked by all the other monkeys, including the previous newcomer. Likewise, replace a third original monkey, then a fourth, then the fifth. Every time the newest monkey takes to the ladder, he is attacked.
After replacing the fifth monkey, none of the monkeys had ever been sprayed with cold water. They have no idea why they were not allowed to climb the ladder and get the banana. Still, no monkey ever again approaches the ladder to try for the banana. The reason is simple: as far as they knew, it was the way it had always been around here.
How is this relevant to secure erasure?
Well, most of so-called “security experts” are like that monkeys. They have no idea why exactly multi-pass overwrite procedures were introduced in a first place. They do not know the physics of the process. They could not tell the difference between magnetic storage media and SSD/flash devices. They have no clue about blocks randomization. They are unaware about the limited number of writes. Yet they bluntly recommend using the same multi-pass secure erase methods for SSD/flash, just because it was the way it had always been around here.
Reddit this /
Add to del.icio.us /
Digg this!