What should I do if I have to access a USB drive that is untrusted?
Its not really a privacy question but I think it is important to answer this.
Best case you just throw the USB stick in a certified shredder but that might not always work out.
So what I do is in these cases, take an old empty laptop and remove the network card. Then boot in UEFI/Bios, make sure to also disable networking there, some laptops have network chips soldered or part of the motherboard so this step is not to be skipped. Boot the laptop, preferably also a non-persistent system like Tails on another USB drive. Only after plug in the suspected drive. Check contents. If you suspect anything actually malicious you are advised to throw both the USB and the laptop in the shredder after.
Apologies if this is a stupid question, but what does a certified shredder refer to? I’m assuming it’s not a physical shredder, but I’m not succeeding in finding a good answer.
depending on how it was go in order of priority:
- Wipe the drive in the OS
- if that’s dangerous wipe it in a live usb
- if that’s dangerous shred the drive
- if the drive is not even in question, solder a new BIOS or replace the motherboard
- If none of those options work then shred the laptop
Well it is actually probably both a device and a company offering that service to use such device.
Obviously depends on your situation but I personally never want to be responsible for something not being adequately destroyed. So I like to ‘transfer’ that risk.
Definitely not a stupid question.
No.
Wiping a drive is the worst advice you could give, sorry.
Wiping drives is near impossible. In most cases forensic tools can easily recover data.
If you find anything seriously suspicious, you should not take any risk and discard the device completely. Persistent malware exists in far to many ways to make assumptions about where it will reside. You should always treat the hardware as compromised.
If the hardware you use to test is not worth the test in the first place, just shred the USB drive right away.
What if you put the USB in a little bit of gasoline and light it up?
I cannot really say all that much about it. It might work but i would never take that risk when providing advice. I guess all depending on threat model like with anything is the case.
In forensic studies, I did, we found quite nifty ways to recover data from even disks who got recovered from burned down buildings. Take that for what you will.
The question to ask is how much money/effort is someone in the worst case going to invest in getting that data?