Why We Protest - IRAN

Anonymous Iran

Go Back   Why We Protest - IRAN > Inside Iran > Keeping Your Anonymity In Iran

Reply

 

LinkBack Thread Tools Display Modes
Old 06-20-2009   #11 (permalink)
Junior Member
 
Join Date: Jun 2009
Posts: 2
Default

Don't be too paranoid.

Factor in the number of people.
The number of computers and hard drives.
The amount of data!

Iran has only so many forensic experts/laboratories and limited time.
The can't try and recover thousands of empty harddrives.

I recomend having this little program handy and use it.
The more people use it the better, the bigger the number of trashed hard drives they need to look at.

Nothing is absolutely safe, but this is certainly a way to make it MUCH safer in case your computer is in danger to fall in their hands and you need it wiped quickly!
Crayson4Iran is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-20-2009   #12 (permalink)
Unregistered
Guest
 
Posts: n/a
Default

worse comes to worse if you've got the time you could attempt to physically destroy the hard drive.
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-20-2009   #13 (permalink)
Member
 
Join Date: Jun 2009
Location: The Netherlands
Posts: 41
Default

Of course that might give them more grounds to arrest you on. Just a wiped hard disk doesn't mean much.
Ver Greeneyes is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-20-2009   #14 (permalink)
Unregistered
Guest
 
Posts: n/a
Default

Quote:
Originally Posted by Ver Greeneyes View Post
Of course that might give them more grounds to arrest you on. Just a wiped hard disk doesn't mean much.

the free program ERASER works beautifully too. You can do a Gutzman erase or choose fewer passes...it also cleans the empty spaces on your hard drive >)
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-20-2009   #15 (permalink)
Yar
Guest
 
Posts: n/a
Default

I can't imagine there being many competent government forensic examiners in Iran? Federal agents in the US that do this can sometimes barely turn on a computer. It is the private sector which is light years ahead.

Another way to secure your data is to use full disk encryption with TrueCrypt and modify the boot loader with a hex editor to remove the string "truecrypt"

Modify TrueCrypt Encryption Boot Loader Strings | Anti-Forensics

This way you've a disk full of data, it's just unreadable.
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-20-2009   #16 (permalink)
Unregistered
Guest
 
Posts: n/a
Default

just get some thermite rigged over your PC theres a perfect solution
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-21-2009   #17 (permalink)
Junior Member
 
Join Date: Jun 2009
Posts: 20
Default

For those of you using linux, instead of using the 'rm' command, use the command 'shred' it effectively does the same thing as the tools above. For a more secure erase use 'shred -z' which will add a layer of Zeros over your "shreded" data.

Source: shred - Linux Command - Unix Command
DeiBellum is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-21-2009   #18 (permalink)
Unregistered
Guest
 
Posts: n/a
Default

Quote:
Originally Posted by Unregistered View Post
the free program ERASER works beautifully too. You can do a Gutzman erase or choose fewer passes...it also cleans the empty spaces on your hard drive >)
I spent two years working in a computer forensics shop - we used Eraser to wipe drives that were used to transport client data/backups/what have you, and we slept just fine at night.
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-21-2009   #19 (permalink)
Bob-a-bouy
Guest
 
Posts: n/a
Default

What about magnetic domains? Bit storage area boundry regions?
Why do you spread this kind of disinformation?

Sheesh, even shuffling a deck cards requires at least 8 passes to randomize. Disk storage is not numerical, it is physical. In forensic or recovery analysis we do not search the numerical content of a disk like a computer operating system would, we look at the magnetic properties of the entire platter surface.

Pshaw.

Quote:
Originally Posted by Yar from Anti-Forensics View Post
I am the owner of the anti-forensics.com domain above and work in computer forensics dealing with hard disk (and other storage media) wiping on a daily basis.

You cannot recover data from a modern hard drive which has been wiped just once. It is the equivalent of this:

We'll represent some data in binary first:
1000101

This is equal to "69" in decimal, a human readable format which you might see in a text document or anywhere really.

Disk wiping software will go through a storage medium randomly writing one's and zero's (or all zero's or custom patterns, basically whatever it is programmed to do).

So if you were to just "zero" out the storage media then you would be left with a drive filled with zero's. Your data "69" would now be:
00000000

Which in decimal is: 0

You cannot recover the previous contents of this data, it is now gone. There is a technique called Magnetic Force Microscopy which uses a device to "detect" the previous value of a bit (1 or 0). Modern hard disks are far too efficient for this method to yield accurate results.

This method may recover 1 bit correctly (extremely slim chance), but it then has to recover seven more bits correctly to recover the original decimal value "69" (which is a byte). Documents are normally made up of several kilobytes. The chances of recovering a single bit are very slim. The chances of recovering a document in its original form (not coming out as random letters and numbers) is pretty much 0%. If even a single bit is different in a byte, then the bytes value is not equal to what it was originally.

Apply this to other file formats such encrypted files, even if you have the password, the encrypted container is now corrupt and destroyed. Open a picture in a hex editor and change some bytes, watch colors change. Do the same with other files and documents.

Currently there is about a 0% chance of data being recovered after a single wipe.

Hope this helps.
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-21-2009   #20 (permalink)
Junior Member
 
Join Date: Jun 2009
Posts: 7
Default

Quote:
Originally Posted by Unregistered View Post
I spent two years working in a computer forensics shop - we used Eraser to wipe drives that were used to transport client data/backups/what have you, and we slept just fine at night.
Forget software means of erasing data. Unless you have enough time to wipe drives with the standard DoD 7 pass wipe you should go for complete destruction and use thermite to melt the drives down to molten metal. The recipe is extremely simple and cheap to make. You should have as many batches of these prepared ahead of time in the event you have to throw the hard drives into it and light it before bailing. Here is how you make it:

You take 8 grams of powdered iron oxide to 3 grams of powdered aluminum and put them in a standard clay flowerpot. It's best to have a thin magnesium strip of metal to act as an ignition method. All you need to do is light the magnesium strip with a match or preferably a butane lighter. Before lighting it bury the hard drive in the middle of the mix and light. Security forces or police will not be able to put out the thermite once ignited and it will burn at around 2500 deg C effectively melting the entire hard drive in minutes. EXTREMELY IMPORTANT!!! - Ensure you do this outside, because if you do this inside of a building it will set the building on fire and will be next to impossible to extinguish.

Another tip - make sure your computers have easily removable hard drives. Ideally you should be able to pop the front of the computer case off and pull out the hard drives in under a minute without tools. This is essential! You won't have much leeway time when you hear the police busting in your apartment. Keep all your pots, computers and ignition methods prepared and close to each other so you do not have to search for them when and if the time comes. Put the pots outside with the hard drives, light, and run! It will not explode but you do not want to be anywhere close because they will arrest you for destroying potential evidence against you. Be careful with itself. It will not ignite on it's own (non-volatile) but if you come in contact with it while it's burning you will be severely injured or die as a result.

Wiping is okay, encryption is better, but full destruction is the ONLY guaranteed means of keeping your data secure. It is cheap and easy in most countries to secure the supplies for this method of data destruction. It can also be used for quickly destroying anything else that would take time to burn.

I guarantee this will work for you in an emergency. When I was in the Army we'd use thermite grenades for destroying sensitive communications, vehicle engines and weapon systems if we felt they were going to imminently fall into enemy hands. A simple soda can with a hole in the bottom filled with thermite can easily melt through the engine block of a car if placed on the hood. Cover the hole with paper or tape on the outside so it does not leak out. Light on a security force vehicle's hood and run. They will be unable to stop the reaction or use the vehicle to pursue you before the damage is done. I do not condone violence but I fully support the Iranians cause for democracy which under extreme circumstances call for sabotage.
xtheory is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Tags
data, dban, destruction, emergency

Thread Tools
Display Modes

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 07:01 AM.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.0
no new posts