Feeds

Working up an appetite for destruction

Data disposal without tears

  • alert
  • submit to reddit

Internet Security Threat Report 2014

Never fear, Smith is here

The items I mentioned above are relatively easy to handle because destroying data usually means wiping the device clean. It gets much more complicated when you need to keep some data while getting rid of other bits of information. For instance, what if you want to delete mail logs or spools while keeping the rest of the server up and running? Do you know what log files are being generated? Can you safely delete them?

And here's another thing that many people forget about: what about destroying data inside files? I'm talking, of course, about the famous problem of Microsoft Word's ability to keep deleted information behind in a file, which has caused embarrassment and worse for the British government. Word is not the only program with this ability - digital imaging software has also caused embarrassment for some individuals, and Adobe Acrobat does not always hide things as well as some users think.

Recently, Michal Zalewski wrote an informative piece titled "Strike that out, Sam" in which he reported the results of an interesting experiment. Zalewski wrote a spider that searched microsoft.com for Word documents and then grabbed the 10,000 or so that it found. He then found the documents that had used change tracking and still had deleted text left behind, which narrowed his set down to 500. Then he started looking at the Word documents using software that shows the complete text of the documents, deletions and all. He was pretty nice about his results, posting fairly innocuous examples, but even those don't exactly paint the company in a favourable light.

As Zalewski points out, his findings are particularly ironic considering that Microsoft recently released a tool to take care of this very problem. Too bad that it only works for documents created using Office XP and Office 2003, and only on Windows XP - maybe the recent embarrassment caused by Zalewski's article will encourage Microsoft to release a tool that would be useful for all the folks still using prior versions of Office and Windows.

One final thought: I've been focusing a lot on electronic data, but as security pro's, we need to think about non-electronic data as well. Getting rid of stuff we don't need also means shredding the pounds and pounds of paper that every office has in it (and then recycling that now-useless stuff, if you can). Too often we focus on computers, because that is what many of us use every day, but there is still danger lurking in printouts, and we would be remiss to forget them.

It's time for us to accept that we live in an environment with a great many dangers lurking in it, dangers that we can lessen as long as we create a policy that everyone in our organisation can understand and actually use, as long as we discipline ourselves to delete the stuff we just don't need, and as long as we remember to look both ways before crossing the railroad tracks - or the lawyers.

Copyright © 2004, 0

Scott Granneman is a senior consultant for Bryan Consulting Inc. in St. Louis. He specializes in Internet Services and developing Web applications for corporate, educational, and institutional clients.

Beginner's guide to SSL certificates

More from The Register

next story
Docker's app containers are coming to Windows Server, says Microsoft
MS chases app deployment speeds already enjoyed by Linux devs
'Hmm, why CAN'T I run a water pipe through that rack of media servers?'
Leaving Las Vegas for Armenia kludging and Dubai dune bashing
'Urika': Cray unveils new 1,500-core big data crunching monster
6TB of DRAM, 38TB of SSD flash and 120TB of disk storage
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
SDI wars: WTF is software defined infrastructure?
This time we play for ALL the marbles
Windows 10: Forget Cloudobile, put Security and Privacy First
But - dammit - It would be insane to say 'don't collect, because NSA'
Oracle hires former SAP exec for cloudy push
'We know Larry said cloud was gibberish, and insane, and idiotic, but...'
Symantec backs out of Backup Exec: Plans to can appliance in Jan
Will still provide support to existing customers
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.