Files
wipe/SECURITY.md

48 lines
2.2 KiB
Markdown

# Security Policy
## Destructive Operation Warning
**This tool performs irreversible destructive operations.**
Running `wipe` will permanently destroy all data on the target block device. This operation cannot be undone.
- Always verify the target device path (`lsblk`, `fdisk -l`) before running.
- Use `--dry-run` to preview what will happen without modifying data.
- The tool requires `--whole-disk` for whole-disk devices to prevent accidental wipes.
- Running system devices (`/`, `/boot`, `/boot/efi`, swap) are protected and will be refused even with `--yes` or `--force`.
## Logical Overwrite Limitations
Logical overwrite (zero, random, etc.) does **not** guarantee physical NAND erasure:
- Remapped sectors, SSD NAND cells, controller cache, and firmware-level storage may retain previous data.
- For SSDs/NVMe, prefer controller-level sanitize when supported:
```bash
sudo wipe /dev/nvme0n1 --whole-disk --method nvme-sanitize
sudo wipe /dev/nvme0n1 --whole-disk --method nvme-crypto # if OPAL/crypto supported
sudo wipe /dev/sda --whole-disk --method secure-discard # for SATA SSD with secure discard
```
- Multiple overwrite passes do not necessarily improve erasure on flash media; controller-level operations are semantically different.
> **Logical read-back verification (`--verify` / `OVERWRITE_VERIFIED`) ≠ forensic proof of irrecoverability.**
Verification confirms that the logical LBA range reads back as written, but cannot prove that all physical media, spare areas, or controller caches have been erased.
## Reporting Vulnerabilities
If you discover a safety bypass or security issue (e.g., system disk protection can be bypassed, or the tool wipes an unintended device):
1. Do not publicly disclose immediately.
2. Open a security advisory via GitHub or contact the maintainer.
3. Provide steps to reproduce, device layout, and expected vs actual behavior.
## Safe Usage Checklist
- [ ] Confirmed device path with `lsblk --json` and `/dev/disk/by-id/`
- [ ] Ran with `--dry-run` first
- [ ] Verified device is not holding the running system
- [ ] Unmounted or used `--unmount` for filesystems
- [ ] Understood method semantics for your media type (HDD vs SSD vs NVMe)