Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


March 2008

Decommission Old Computers with Cipher

Encryption isn’t the tool’s only capability
RSS
Subscribe to Windows IT Pro | See More Tips Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

For the past two months, we’ve been tinkering with Cipher (cipher.exe), the Windows command- line tool for controlling Encrypting File System (EFS). The bulk of EFS’s job is to encrypt data files and manage the keys it uses for that encryption, as I demonstrated with the previous two column’s looks at the tool’s /e, /d, /r, and other options. But Cipher offers other cool functionality, not least of which is its ability— with its /w option—to simplify the decommissioning of old systems.

Disk Decommissioning
What do you do with old computers—sell them or donate them to a charity? The answer to that question is important because those old systems probably contain one or more hard disks that contain all sorts of confidential information. I always wince when I see someone selling an old laptop or desktop computer because I’m almost certain the seller hasn’t removed his or her personal data from the system’s hard disk. Perhaps the seller has formatted the disk, but there are so many tools on the market for restoring data from formatted disks that I wonder how many people have been embarrassed after selling a computer. A few times, I’ve purchased used computers and discovered personal-finance files, old email messages—you name it, all recovered without any genius.

So, before letting go of a computer, you need to ensure that its data won’t fall into the wrong hands. One solution is to get rid of the computer but keep the hard disk, but then we’re back to the question, “How do I get rid of the data on the disk?” Some people use old hard disks for target practice, which is fine if you live near a rifle range. I’ve seen an amazing US Army machine that shreds hard disks, but unfortunately I can’t afford a toy like that. The best solution is to overwrite every sector on the disk with random patterns, and—according to some—repeat that several times. One erasure might not entirely overwrite a magnetic area. (Having said that, I’m not aware of an off-the-shelf hardware or software solution that can reliably read a hard disk that’s been overwritten once.)

Cipher’s Solution
Cipher offers a method for erasing a hard disk so that you can feel fairly secure that none but the most technologically savvy bad guys can get to its erstwhile data. You perform the process in two steps. First, format the target disk. The easiest format procedure is probably to put the disk in a USB-compatible external hard-drive enclosure, then connect it to your new computer. Then, once you’ve emptied the disk, open a command prompt (I’m assuming your new computer is running at least Windows XP) and type

cipher /w:<d:>

where d: is the drive letter of the disk you’re decommissioning. Cipher /w will overwrite all unused sectors on the disk with zeroes, then ones, and finally a random number. The key to understanding the process is the phrase “unused sectors.” If you don’t first format the disk, Cipher won’t touch the sectors that contain your data!

You might be wondering why you need to go through the whole process of connecting the soon-to-be-decommissioned drive to a working system rather than, say, booting Windows Preinstallation Environment (PE) and running Cipher from Vista. I tried that latter solution with no success. Apparently, Windows PE lacks the suite of cryptographic support routines that Vista contains. Oh, and don’t expect to get Cipher’s overwrite process done quickly. In my experience, Cipher requires a minute or two per gigabyte. Start the encryption at night, and your disk will be clean as a whistle by the time you wake.

Don’t Worry
On a final note, let me save you some time and aggravation. When you make it known that you plan to use Cipher /w to decommission a drive, someone—inevitably a security guy—will no doubt claim that overwriting a drive a mere three times is insufficient to truly protect that drive from a determined hacker. Now, I freely admit to being a card-carrying security guy, but some of my compatriots seem more interested in worrying people than truly analyzing a security situation. Could the NSA or CIA retrieve data that has been overwritten only three times? Yes, those agencies probably could. But as long as you’re not a member of Al Qaeda, you can surely rest easy after accomplishing a “mere” three overwrites.

End of Article



Reader Comments
Hi Mark --

I'd like to recommend Darik's Boot and Nuke (http://dban.sourceforge.net/). It is a boot CD/floppy that you put in your old machine. It boots up, detects all drives, and then overwrites them using various options. The best part: You don't need to move drives to a separate computer.

drnebeker April 12, 2008 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
A Simple File Transfer Solution

My small business clients thought FTP was the answer to their file transfer problems, but I surprised them with an even better solution for their data delivery needs. ...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

August 2008 Reader Challenge and July Reader Challenge Winners

Whether you're new to Windows Vista or you've been using it for some time, there are some things that take getting used to after using Windows XP for a long time. Didja notice the following things? ...


Windows OSs Whitepapers Replay for Exchange: Enterprise Protection and an Affordable Price

Are You Satisfied?

A Preliminary Look at Deployment Plans for Microsoft Windows Vista

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Deploying SharePoint! In-Person Event Series – 8 Cities
Discover best practices and tips for deploying the perfect SharePoint infrastructure. Early Bird Price of $99 through Aug 29th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



Entrust Unified Communications Certs
Secure Exchange 2007 and save 20%. Now through Sept. 2008.

When managing just VMware isn’t enough
Plan/Manage/Secure – NetIQ VMware management. Download whitepaper.

Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing