logo
Choose Secure Data Erasure Over Factory Reset for Mac

Choose Secure Data Erasure Over Factory Reset for Mac

Geeky Gadgets5 days ago

Apple Silicon or Intel-based Macs have an option to be reset to factory mode. Once the Mac device is reset, all the applications and saved personal data are formatted, and the device is restored to factory settings. This hard reset frees up storage space, deleting stored data and thereby increasing its processing speed. Several areas on the disk store data such as user credentials, built-in app data, backup information, etc., that are inaccessible to the user, operating system, BIOS, or UEFI. Existing in different forms, Host Protected Area (HPA), Disk Configuration Overlay (DCO), or Accessible Max Address (AMA), these hidden disk areas mainly contain disk utilities for the device to function smoothly. It is of utmost importance that data from these disk zones be erased to prevent data leakage. However, a factory reset is incapable of fulfilling this purpose. The Hidden Risks: Recoverable Data Post Factory Reset
A factory reset only removes the pointers to the file system, removing only access to the data and not the data itself. In most cases, the actual contents of the Mac drive still reside on the Mac, which is recoverable using freely available Mac data recovery software or through forensic in-lab services.
The data traces left behind after a factory reset can comprise Personally Identifiable Information (PII), Protected Health Information (PHI), credit card information, etc., which, if leaked, can ruin decades of reputation for a business in seconds, and this is just the beginning. Data protection laws and regulations like EU-GDPR, HIPAA, CCPA, GLBA, etc., require businesses to erase personal data collected for processing after the retention period is over, the purpose has been served, or the individual has requested the removal of their data.
Data removal has to be permanent beyond recovery from the entire Mac device, including inaccessible disk zones HPA, DCO, and other remapped sectors. Contrary to popular belief, a factory reset does not meet the secure erase requirements such as those needed by NIST 800-88, DoD 5220.22 M, or other regulatory guidelines. On Mac devices with SSDs, data is stored in memory blocks that also have the TRIM command enabled. While TRIM helps in optimizing the performance of SSDs, however, there is no way to ensure that the data has been permanently erased, as the TRIM command can be disabled by individuals, either intentionally or due to system configurations.
Further, laws also mandate a proof of data destruction to be maintained by the organization in the form of a report or certificate of destruction. A software-based data erasure tool is highly recommended if the Mac devices are in a functional state and the business intends to reuse them; however, if the device is non-functional and cannot be repaired, then the device must be destroyed using physical destruction methods. The Real World Impact: When Factory Reset Fails
Consider an organization that has no policies or mechanisms in place for data destruction. For reusing, repurposing, reselling, or donating their end-of-life devices, including Mac devices, the organization performs a factory reset on all the functional devices. These reset devices are either handed over to their new owners or discarded. Since the business-critical information still remains on these devices, the threat to data privacy lingers continually. The sensitive information can be recovered from all these devices using forensic tools or data recovery software, which can then be misused or can result in a data breach episode.
The 2016 Morgan Stanley data breach case is one such example where confidential data such as social security numbers, passports, and credit card information, was recovered from decommissioned IT assets. These IT assets were not only not properly erased but also were resold to a third party without sanitization verification. This unauthorized access to personal data brought the organization penalties close to USD 100 million imposed by authorities, including the Office of the Comptroller of the Currency (OCC) and Securities and Exchange Commission (SEC), over a span of more than 5 years. One data breach caused Morgan Stanley operational downtime, penalties, and loss of customer trust. The Secure Solution: Software-Based Data Erasure
Organizations must devise data destruction policies, including data retention guidelines, to ensure secure erasure is performed periodically without any scope for gaps in the process. The policies should also include guidelines on how data of varying sensitivity should be securely erased from different Mac devices and what tool should be used to perform secure data erasure.
For example, the Mac devices containing data related to intellectual property or financial information that is critical must be sanitized using a certified data erasure tool like BitRaser before Mac devices are reallocated or refurbished.
A software-based data erasure tool applies international data erasure algorithms like NIST 800-88 Clear, NIST 800-88 Purge, and DoD 5220.22 M (3 pass). It permanently erases data from all devices, including Mac's with erasure from inaccessible hidden disk areas. It also generates immutable erasure reports and a certificate of data destruction, which assist in complying with the governing data protection laws and regulations. Resetting Isn't Enough, Erasure is Essential
Organizations have always been proactive in adapting to modern-day technology to gain more profits, gain a competitive edge, and establish their brand as progressive. However, many lag in assimilating this strategy when it comes to policy implementation in terms of data destruction. The risk of a data breach creeps over every business today, whether it is a startup or an enterprise. According to IBM's Cost of a Data Breach Report 2024, an average data breach costs USD 4.88 million. This cost is 10% higher than that mentioned in the IBM 2023 report. Clearly, there is a dire need for organizations to prevent data breaches by including secure data erasure as one of their cybersecurity strategies.
To prevent this risk from turning into a tragic event, businesses must leverage data erasure programs to destroy data on their Mac devices, comply with the requirements of data protection laws, and build trust with their customers. Compliance is no longer optional, and a factory reset is not compliant. Filed Under: Apple, Guides, Laptops
Latest Geeky Gadgets Deals
Disclosure: Some of our articles include affiliate links. If you buy something through one of these links, Geeky Gadgets may earn an affiliate commission. Learn about our Disclosure Policy.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

US lawyer sanctioned after caught using ChatGPT for court brief
US lawyer sanctioned after caught using ChatGPT for court brief

The Guardian

timean hour ago

  • The Guardian

US lawyer sanctioned after caught using ChatGPT for court brief

The Utah court of appeals has sanctioned a lawyer after he was discovered to have used ChatGPT for a filing he made in which he referenced a nonexistent court case. Earlier this week, the Utah court of appeals made the decision to sanction Richard Bednar over claims that he filed a brief which included false citations. According to court documents reviewed by ABC4, Bednar and Douglas Durbano, another Utah-based lawyer who was serving as the petitioner's counsel, filed a 'timely petition for interlocutory appeal'. Upon reviewing the brief which was written by a law clerk, the respondent's counsel found several false citations of cases. 'It appears that at least some portions of the Petition may be AI-generated, including citations and even quotations to at least one case that does not appear to exist in any legal database (and could only be found in ChatGPT and references to cases that are wholly unrelated to the referenced subject matter,' the respondent's counsel said in documents reviewed by ABC4. The outlet reports that the brief referenced a case titled 'Royer v Nelson', which did not exist in any legal database. Following the discovery of the false citations, Bednar 'acknowledged 'the errors contained in the petition' and apologized', according to a document from the Utah court of appeals, ABC4 reports. It went on to add that during a hearing in April, Bednar and his attorney 'acknowledged that the petition contained fabricated legal authority, which was obtained from ChatGPT, and they accepted responsibility for the contents of the petition'. According to Bednar and his attorney, an 'unlicensed law clerk' wrote up the brief and Bednar did not 'independently check the accuracy' before he made the filing. ABC4 further reports that Durbano was not involved in the creation of the petition and the law clerk responsible for the filing was a law school graduate who was terminated from the law firm. The outlet added that Bednar offered to pay any related attorney fees to 'make amends'. In a statement reported by ABC4, the Utah court of appeals said: 'We agree that the use of AI in the preparation of pleadings is a legal research tool that will continue to evolve with advances in technology. However, we emphasize that every attorney has an ongoing duty to review and ensure the accuracy of their court filings. In the present case, petitioner's counsel fell short of their gatekeeping responsibilities as members of the Utah State Bar when they submitted a petition that contained fake precedent generated by ChatGPT.' As a result of the false citations, ABC4 reports that Bednar was ordered to pay the respondent's attorney fees for the petition and hearing, refund fees to their client for the time used to prepare the filing and attend the feeling, as well as donate $1,000 to the Utah-based legal non-profit And Justice for All.

Trump to withdraw billionaire Jared Isaacman's nomination to lead NASA, AP source says
Trump to withdraw billionaire Jared Isaacman's nomination to lead NASA, AP source says

The Independent

timean hour ago

  • The Independent

Trump to withdraw billionaire Jared Isaacman's nomination to lead NASA, AP source says

President Donald Trump is withdrawing the nomination of tech billionaire Jared Isaacman to lead NASA, a person familiar with the administration's personnel decisions said Saturday. The individual was not authorized to comment publicly. The White House and NASA did not immediately respond to emailed requests for comment. Trump announced last December during the presidential transition that he had chosen Isaacman to be the space agency's next administrator. Isaacman is the CEO and founder of Shift4, a credit card processing company. He also bought a series of spaceflights from SpaceX and conducted the first private spacewalk. Isaacman testified at his Senate confirmation hearing on April 9 and a vote to send his nomination to the full Senate was expected soon. SpaceX is owned by billionaire Elon Musk, a Trump supporter and adviser who announced this week that he is leaving the government after several months at the helm of the Department of Government Efficiency, or DOGE. Trump created the agency to slash the size of government and put Musk in charge. Semafor was first to report that the White House had decided to pull Isaacman's nomination.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store