feat: initial wipe implementation - block device safety, HDD overwrite, NVMe/secure-discard, verification
This commit is contained in:
+47
@@ -0,0 +1,47 @@
|
||||
# Security Policy
|
||||
|
||||
## Destructive Operation Warning
|
||||
|
||||
**This tool performs irreversible destructive operations.**
|
||||
|
||||
Running `wipe` will permanently destroy all data on the target block device. This operation cannot be undone.
|
||||
|
||||
- Always verify the target device path (`lsblk`, `fdisk -l`) before running.
|
||||
- Use `--dry-run` to preview what will happen without modifying data.
|
||||
- The tool requires `--whole-disk` for whole-disk devices to prevent accidental wipes.
|
||||
- Running system devices (`/`, `/boot`, `/boot/efi`, swap) are protected and will be refused even with `--yes` or `--force`.
|
||||
|
||||
## Logical Overwrite Limitations
|
||||
|
||||
Logical overwrite (zero, random, etc.) does **not** guarantee physical NAND erasure:
|
||||
|
||||
- Remapped sectors, SSD NAND cells, controller cache, and firmware-level storage may retain previous data.
|
||||
- For SSDs/NVMe, prefer controller-level sanitize when supported:
|
||||
|
||||
```bash
|
||||
sudo wipe /dev/nvme0n1 --whole-disk --method nvme-sanitize
|
||||
sudo wipe /dev/nvme0n1 --whole-disk --method nvme-crypto # if OPAL/crypto supported
|
||||
sudo wipe /dev/sda --whole-disk --method secure-discard # for SATA SSD with secure discard
|
||||
```
|
||||
|
||||
- Multiple overwrite passes do not necessarily improve erasure on flash media; controller-level operations are semantically different.
|
||||
|
||||
> **Logical read-back verification (`--verify` / `OVERWRITE_VERIFIED`) ≠ forensic proof of irrecoverability.**
|
||||
|
||||
Verification confirms that the logical LBA range reads back as written, but cannot prove that all physical media, spare areas, or controller caches have been erased.
|
||||
|
||||
## Reporting Vulnerabilities
|
||||
|
||||
If you discover a safety bypass or security issue (e.g., system disk protection can be bypassed, or the tool wipes an unintended device):
|
||||
|
||||
1. Do not publicly disclose immediately.
|
||||
2. Open a security advisory via GitHub or contact the maintainer.
|
||||
3. Provide steps to reproduce, device layout, and expected vs actual behavior.
|
||||
|
||||
## Safe Usage Checklist
|
||||
|
||||
- [ ] Confirmed device path with `lsblk --json` and `/dev/disk/by-id/`
|
||||
- [ ] Ran with `--dry-run` first
|
||||
- [ ] Verified device is not holding the running system
|
||||
- [ ] Unmounted or used `--unmount` for filesystems
|
||||
- [ ] Understood method semantics for your media type (HDD vs SSD vs NVMe)
|
||||
Reference in New Issue
Block a user