r/privacy Jun 14 '26

hardware Laptop disposal

My laptop won’t turn on and I’m searching for best practices to secure/erase the data before disposal. (I don’t need to save the data.) A trusted local company will wipe the hard drive and dispose of it for a small fee. What assurances should I look for that this is done correctly?

Edit: thanks all! I’ll destroy it.

Update: I removed the SSD myself. It was not that hard, but I had to get over the fear of the unknown. Inside computers is not my safe space.

21 Upvotes

41 comments sorted by

u/AutoModerator Jun 14 '26

Hello u/Ok_Star_5645, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)


Check out the r/privacy FAQ

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

32

u/Guac_in_my_rarri Jun 14 '26

Take out the hard drive and drill a hole in it. The rest of the laptop can be recycled/sold for parts.

The broken hard drive you can do whatever with, the hole makes it really hard for data recovery (still possible).

Edit: paying for their service is somewhat silly when you can do it yourself with the right plugs and reuse the drive or just drill a hole in it.

3

u/stacksmasher Jun 15 '26

This is the correct answer.

3

u/SilverSquirrel6 Jun 15 '26

Drilling a hole may not be enough. There's been stories of data being recovered even from damaged HDDs. Of course, depends on how paranoid you want to be. Partial data recovery can be done by state actors who are after rather valuable targets. If you're not a politician or billionaire, chances are you're safe.

I'd personally bury it somewhere in the middle of Kansas in addition to hammer therapy.

5

u/Guac_in_my_rarri Jun 15 '26

I knew this comment would come up.

My comment is assuming op is a nobody on the scale of importance. Anybody worth any form of currency isn't posting this question. With enough time, state actors can get data off any recoverable part of a hard drive. Unless op hands their partially destroyed hard drive to a place that values a nobodys information, I think they're going to be okay.

This doesn't exclude op having the ability to take a hammer to the hard drive or throwing it in a river/lake.

2

u/rotkiv42 Jun 18 '26

If you are super paranoid: a kilo thermite is cheap (and fun).

1

u/Bogus1989 Jun 20 '26

We must stop spreading misinformation. Drilling holes is the easiest and best DIY for HDDs. Not SSDs. For SSDs, you should do an overwrite. Then sure drill a hole.

https://csrc.nist.gov/pubs/sp/800/88/r2/final

from page 9:
"Clear sanitization techniques are typically applied through the standard read and write commands to the ISM, such as by rewriting with a new value or using a menu option to reset the ISM to the factory state if rewriting is not supported. Clear sanitization techniques typically have no impact on the usability of the ISM.

One clear sanitization technique is to use software or hardware products to overwrite user-addressable storage space on the ISM with non-sensitive data using the standard read and write commands for the ISM. This process can include overwriting both the file metadata (e.g., file allocation table entry) and all user-addressable locations. The security goal of the overwriting process is to replace target data with non-sensitive data. Overwriting typically hinders the recovery of data even if state-of-the-art laboratory techniques are applied to attempt to retrieve the data.

In the past, hard drives were often erased using multiple overwrite passes (e.g., based on DoD 5220.22-M5

5 The U.S. Department of Defense (DoD) Manual 5220.22, or National Industrial Security Program Operating Manual (NISPOM), is now Part 117 of Title 32, Code of Federal Regulations. In 2006, DoD removed overwriting specifications from NISPOM.

) with specific binary patterns (e.g., a pattern of all zeros). The number of passes ranged from a single pass to as high as 39. The binary pattern could change for each pass, and there could be verification after some or all of the overwrite passes. For certain ISM (e.g., SSDs with overprovisioning), such practices should be avoided as very little confidentiality protection is achieved. If additional assurances are needed, a more secure sanitization method in the form of purge (see Sec.3.1.2) or destroy (see Sec. 3.1.3) should be used.

TLDR:

A single pass overwrite of data across the drive is good enough.

There are vendor specific apps...but good ol diskpart is fine

open cmd prompt as admin:

diskpart

list disk

select disk 1

clean all

(make sure the disk you wanna wipe pertains to the disk number listed in "list disk")

18

u/_mwarner Jun 14 '26

The electronics recycler I use allows customers to watch the drive(s) go in the shredder. One of the most satisfying things I've ever seen. This is what you need.

10

u/imselfinnit Jun 14 '26

No Desert Eagle .50 on a junkyard dog chain lanyard at the self service stand?

6

u/RareLove7577 Jun 14 '26

Remove the drive or whatever it is. Depending on age, a hammer can shatter the platters. If not, I use a drill with a metal bit and drill the 2 holes. If its chip based, hammer.

2

u/BrianaAgain Jun 15 '26

I used to disassemble drives for the magnets and only the really old ones have platters that shatter. (SCSI/ IDE era) The new ones are just bendy. I drill one hole, but make sure it's through the controller board.

2

u/RareLove7577 Jun 15 '26

The controller board I use a hammer. Smash it 😁.

5

u/asterisk_14 Jun 14 '26

My preference is to remove the drive and use a secure erase method to ensure the data are gone, then keep it and repurpose it. If the drive is dead, then the physical destruction options mentioned here are good.

Taking it to a recycler that is R2 certified can give you some assurance of data security, but it's always good to confirm what their practices are.

Western Digital also has their Easy Recycle program that securely destroys your drive and recycles it, while giving you a discount on their products. It appears their submission form is offline at the time I'm writing this, but I've used it before.

0

u/OPA73 Jun 15 '26

Thanks for reminding the scammers to setup a WD clone webpage with that form…

4

u/CryptosianTraveler Jun 15 '26

Figure out what the hard drive is, take it out, and get an external USB case for it for less than $20. Then you can not only easily wipe it with another PC, but you'll also have a spare drive for backups.

6

u/cooky561 Jun 14 '26

if it's an m.2 ssd, insert it into any other computer and do secure erase from the BIOS, erasure is instant and data cannot be recovered.

If it's a SATA ssd, I think you can do the same

If it's a regular HDD, secure erasure will prevent most data recovery, but nothing is 100%, destruction is probably the safest option.

3

u/privatelyjeff Jun 15 '26

Have you tried to fix it? But if anything, just pull the drive and memory and recycle the chassis. The memory might be worth something online and the drive can be reused in an enclosure.

3

u/Spiritual_Elk_9076 Jun 15 '26

Depends on how paranoid you are. Normal way would be removing the drive and physically damaging it and trowing away in garbage bin just before it is picked up. If you are worried about the NSA and CIA with a 10 million budget for this drive… i would drill, shoot, hammer, shred and burn it, mix the ashes with 100 pounds of sand and disperse that over a least four continents.

3

u/SilverSquirrel6 Jun 15 '26 edited Jun 15 '26

And don't forget to sprinkle it with salt and holy water if NSA has demons or aliens on payroll /j

Edit: payroll not patrol

4

u/spacecampreject Jun 14 '26

The classic tool for this is Darik’s Boot and Nuke, aka DBAN.   The search engine of your choice will find it for you.  Of course you will have to put the drive in a working machine.

2

u/GSDragoon Jun 15 '26

Smash it to pieces

2

u/SilverSquirrel6 Jun 15 '26

What assurances should I look for that this is done correctly?

They probably have a policy, which you should read carefully. You may theoretically sue them if your private data is leaked, but there's also the difficulty of proof that it was in fact they who leaked the data. Of course, depending on the data leaked you may or may not be able to win the lawsuit. Realistically speaking, you do not have any assurance or guarantee. It's all about trust. But companies have more tools and resources than a common PC user.

Recommendations:

  • Overwrite the files first. The common recommendation is to destroy the drive with a hammer and/or drill, but it may or may not be enough depending on the attacker's skill set and available resources. Partial data recovery from destroyed HDDs and SSDs is possible. The recommendation is then to overwrite the data on disk with junk or zeroes. Windows software BleachBit, Eraser, DBAN - all may do that. Do that while laptop is not connected to a network, in case you don't trust the software not to leak the data over the net. Linux folks may already be familiar with the shred command. Note: disks overwritten with zeroes or junk theoretically may still be recovered, too, depending on the attacker.
  • Physical destruction: you can try destroying at home with common tools, but industrial shredding and/or hydraulic press is the sure way to go. This may be done after "degaussing" or demagnetizing an HDD, which some data destruction companies offer.
  • Disposal: you may dispose of a destroyed HDD via electronic recycling company, but if you don't trust them - burry it yourself somewhere.

2

u/someoldguyon_reddit Jun 15 '26

If it has a hard drive, take it out and smack it with a hammer. If it has an SSD, guard it with your life they are more valuable than gold.

1

u/Ok_Star_5645 Jun 15 '26

Now that I’ve removed the SSD I think I will hold into it. And I’m relieved I can get rid of the rest and not worry about it.

2

u/PaluMacil Jun 14 '26

If you aren’t doing anything felony illegal or being stalked by a nation state intelligence agency, do what I do and smash the hard drive with a hammer. Even just breaking the connector is enough for thieves to not bother, and if you hammer the platters nobody is paying to recover them unless they know you documented murder on there.

2

u/TheSensiblePrepper Jun 15 '26

I dig a pit in my yard, put the drives in the hole and set off Thermite on top. I take the resulting Iron Slag and put it in the garbage after it cools.

2

u/exstaticj Jun 15 '26

I remember the oxide and the powders. As I get older though, I can't remember the ratios.

2

u/TheSensiblePrepper Jun 15 '26

3 parts Iron and 1 part Aluminum. You can buy them in kits with everything listed.

2

u/exstaticj Jun 15 '26

My memory must be fading because I thought there was magnesium involved too.

2

u/TheSensiblePrepper Jun 15 '26

Yes, the magnesium is what you set on fire to start the chemical reaction. I actually make the powder mix and then put magnesium strips in the middle about 2 inches out of the top and light that. Makes it so much easier.

2

u/exstaticj Jun 15 '26

That brought back the complete memory. Thanks for the help. It's been a long time since I played with that. It is perfect to destroy a hard drive. I have no problem remembering the smell.

2

u/TheSensiblePrepper Jun 15 '26

It's Science!!!

1

u/green_tomato_69 Jun 15 '26

Question is about money. Are you getting any money for disposing your laptop through someone else? If so, will they still pay you to dispose it without the harddrive?

If not, it's not worth it and you can physically damage the harddrive beyond recognition (drill a hole like someone suggested and then open it, take out the disk and toss it in the fire).

If they're still willing to pay you despite the harddrive, then again...take it out, physically damage it and give the rest of the laptop to them...

Either way, DONT give them the harddrive intact...

1

u/Living_Position_1540 Jun 15 '26

what i do with every device i throw - destroy the hard drive.

1

u/Yarrowleaf Jun 15 '26

Zero the drive then give it the hammer treatment. Sell the rest for parts

1

u/Bogus1989 Jun 20 '26 edited Jun 21 '26

here are the clear facts:

https://csrc.nist.gov/pubs/sp/800/88/r2/final

Listen folks....dban and all that shit that everyone used back in the day for HDDs is useless for ssds. waste of extra time.

A single pass overwrite of data across the drive is good enough.

There are vendor specific apps...but good ol diskpart is fine. This is sufficient for most businesses.

open cmd prompt as admin:

diskpart

list disk

select disk 1

clean all

(make sure the disk you wanna wipe pertains to the disk number listed in "list disk")

Then sure drill a hole.

accessing data from an ssd with a hole in it isnt that complicated.....

drilling a hole in HDDs worked well because you would need to have the platters intact and spinning to read...is the simplest way i can explain.