Files
wipe/SECURITY.md

2.2 KiB

Security Policy

Destructive Operation Warning

This tool performs irreversible destructive operations.

Running wipe will permanently destroy all data on the target block device. This operation cannot be undone.

  • Always verify the target device path (lsblk, fdisk -l) before running.
  • Use --dry-run to preview what will happen without modifying data.
  • The tool requires --whole-disk for whole-disk devices to prevent accidental wipes.
  • Running system devices (/, /boot, /boot/efi, swap) are protected and will be refused even with --yes or --force.

Logical Overwrite Limitations

Logical overwrite (zero, random, etc.) does not guarantee physical NAND erasure:

  • Remapped sectors, SSD NAND cells, controller cache, and firmware-level storage may retain previous data.

  • For SSDs/NVMe, prefer controller-level sanitize when supported:

    sudo wipe /dev/nvme0n1 --whole-disk --method nvme-sanitize
    sudo wipe /dev/nvme0n1 --whole-disk --method nvme-crypto  # if OPAL/crypto supported
    sudo wipe /dev/sda --whole-disk --method secure-discard   # for SATA SSD with secure discard
    
  • Multiple overwrite passes do not necessarily improve erasure on flash media; controller-level operations are semantically different.

Logical read-back verification (--verify / OVERWRITE_VERIFIED) ≠ forensic proof of irrecoverability.

Verification confirms that the logical LBA range reads back as written, but cannot prove that all physical media, spare areas, or controller caches have been erased.

Reporting Vulnerabilities

If you discover a safety bypass or security issue (e.g., system disk protection can be bypassed, or the tool wipes an unintended device):

  1. Do not publicly disclose immediately.
  2. Open a security advisory via GitHub or contact the maintainer.
  3. Provide steps to reproduce, device layout, and expected vs actual behavior.

Safe Usage Checklist

  • Confirmed device path with lsblk --json and /dev/disk/by-id/
  • Ran with --dry-run first
  • Verified device is not holding the running system
  • Unmounted or used --unmount for filesystems
  • Understood method semantics for your media type (HDD vs SSD vs NVMe)