Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

However, "unlink the pointer" has been good enough for ages.

The data is effectively deleted short of an application having the privileges to read the underlying raw block device and having an understanding of the raw filesystem structures to be able to search though that unallocated, raw space and reconstruct file entries.

No application outside of special-purpose data recovery apps (and even then you'd need to run them with elevated privileges) would have any reason to be capable of this, so in practice a deleted file means it is deleted from the perspective of the vast majority of applications.

Similarly, SSD TRIM is also irrelevant - TRIM'med space is hidden from the host. Sure, an intentional tool exploiting some undocumented vendor command or side-channel could probably recover it but again you'd have to do this intentionally.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: