NORTH PALM BEACH, Fla. (Bankrate.com) -- At Computers 4 Rent in North Palm Beach, Fla., it's not unusual for customers to leave personal financial information on the hard drive of a computer they rented or one they want to sell to the store.
The store has a policy of reformatting the hard drive every time a computer is returned, or whenever someone sells a used computer to the store. Reformatting is supposed to "wipe off" any personal information left on the hard drive. "An elderly gentleman came in today to sell us his computer," says store manager Rick Zinser. "He said he wanted the hard drive. I said, 'I can wipe it,' but he said, 'no,' he wanted it. It was because he had financial information on it." The elderly gentleman was savvier than a lot of people when it comes to personal financial information on computer hard drives. Too often, people sell or give away their old computers never realizing that the next user may be able to access that information. Even if the information is "wiped." Deleted, but not gone "When we get a computer back we restore it. The hard drive is repartitioned and reformatted every time it comes back," Zinser says. "If an expert wanted to restore it, and it wasn't overwritten, (the information) could be found, but it's very expensive to retrieve data." Zinser is right. It might take an expert to retrieve information from a hard drive after Zinser wipes it clean, but it can be done. If the data wasn't overwritten it could be retrieved by anyone. Would you really want someone to be able to see your financial data? Maybe you have bank, brokerage or credit card information on your hard drive. The kind of information an identity thief would welcome. Two MIT graduate students, Simson Garfinkel and Abhi Shelat, recently bought 158 used hard drives from computer stores, small businesses and eBay, the online auction site. Many of the hard drives were physically damaged and/or had unreadable sections. Nevertheless, the pair managed to retrieve a lot of information from directories and files that had been deleted. Forty-two of the drives had what appeared to be credit card numbers. Garfinkel says they don't know for sure if they're working credit card numbers because that would have required trying to make a transaction. One drive appeared to have been used in an Illinois ATM. Garfinkel says it had nearly 3,000 numbers that he suspects were ATM card numbers. It also contained account numbers and balances. He says no effort had been made to remove the drive's financial information. Another drive had a credit card number with expiration information that Garfinkel says he believes was used for Internet purchases. "People are not generally aware that even after the computer says the information has been deleted, it can be recovered," says Garfinkel. Covering your digital tracks To really get rid of something on your hard drive you have to go way beyond pressing the delete key. Keep in mind, if you don't use a lot of graphics, video or music files, you may not run out of space, so your system may never need to write over data you deleted. So, is taking a sledgehammer to the hard drive the best way to make sure no one else eyeballs your financial information? "It's safer to do that, but I don't believe it's a socially responsible thing to do," says Garfinkel. "There are a lot of people who can't afford new computers and you're destroying something they could use. "Some people say it's impossible to clean off the hard drive. It's not impossible. There is free software and commercial software that do an excellent job of cleaning off data. It also does a good job of cleaning off the operating system, but that can be reinstalled." But if you really want to be sure, opt for the heavy-duty programs. "Our programs offer many different layers of overwriting," says Bill Adler, president of Atlanta-based CyberScrub. "It depends on the level of security you feel is required. Do you want one lock on the door or four?" CyberScrub has two erasure programs. One, cyberCide, is designed to erase everything on the hard drive, including the operating system. The other program, CyberScrub, is designed for daily use. "It can erase your files on demand, plus it can take all your previously deleted material, stuff you think is gone but is recoverable. This will make sure it's not recoverable," Adler says. You can access the CyberScrub programs at CyberScrub.com. Bring the hammer down? Simson Garfinkel agrees that physically destroying the hard drive is the best way to make sure no one retrieves your data. But, as mentioned, Garfinkel thinks that's socially irresponsible. CyberScrub's Adler, who also isn't in favor of destroying hard drives, says drilling makes the hard drive inoperable, but someone with forensics ability would be able to recover the data where it wasn't drilled. Perhaps the sledgehammer would be best.
|