Older external drive enclosures

This is the layout that became standard in macOS 11 (Big Sur) and with the advent of Apple Silicon.

As you can see:

  • disk0 is your physical SSD

    • It has three APFS containers, synthesizing three virtual devices
  • disk1 (synthesized from disk0s1) is the “ISC”.

    This is effectively what Intel Macs had in their BootROM flash storage. It contains that critical low-level firmware necessary to boot everything, including from external volumes.

    If this container or its contents gets trashed, you can’t boot anything. But if the SSD is physically working, you can restore it via another Mac and Configurator (or via the Finder if that other Mac is running a current version of macOS).

    It isn’t normally mounted, which is why diskutil doesn’t show anything else in it, but (at least on my Mac running macOS 15), I see three of its volumes mounted:

    • disk1s1, mounted as /System/Volumes/iSCPreboot. It appears to have low-level things like system policy files and system recovery data.
    • disk1s2, mounted as /System/Volumes/xarts. It has one file, with a UUID for a name, so I have no clue what it’s for.
    • disk1s3, mounted as /System/Volumes/Hardware. It appears to have the root certificates for various security things and what I think is the lowest-layer of iCloud login information. I assume it’s part of the mechanism for remote-lockout/remote-wipe.
  • disk2 (synthesized from disk0s3) is a global Recovery container.

    This is what boots if you try to boot it without any macOS on the SSD. I think it’s also a fallback if you try to go to Recovery mode and your OS-specific Recovery partition isn’t bootable.

    It also isn’t normally mounted, which is why diskutil isn’t showing its contents.

  • disk3 (synthesized from disk0s2) is your macOS system container. As you can see, it has several volumes in it:

    • disk3s1 is your System volume.

      It contains all the parts of macOS that you are prevented from ever changing. It is not booted directly

    • disk3s1s1 is a snapshot of the System volume.

      This is the SSV. The “Signed System Volume”. It is a snapshot of disk3s1 and is digitally signed. macOS boots from this.

    • disk3s2 is your “Preboot” volume.

      It normally mounts as /System/Volumes/Preboot and appears to contain the cryptexes that Apple uses for certain core features (like WebKit, Safari and maybe other things).

      I assume (from the name) that it also sets up hardware devices necessary for macOS itself to boot.

    • disk3s3 is your “Recovery” volume.

      This is what boots when you enter recovery mode.

    • disk3s5 is your “Data” volume.

      It normally mounts as /System/Volumes/Data, and is fused with the System volume to form the root file system applications see. It contains everything you see on your internal SSD that isn’t stored in the SSV or a cryptex.

    • disk3s6 is the “VM” volume.

      It normally mounts as /System/Volumes/VM. This volume is empty on my system. I assume, from the name, that swap files go here. But I’m really not sure.

    • I also noticed that disk3s4 doesn’t appear in diskutil list, but is mounted as /System/Volumes/Update

      I believe that this is used to store temporary files, during software upgrades (e.g., where it unpacks macOS updates that have been downloaded). On my system, it has a lot of empty directories, a bunch of log files and not much else.

Howard Oakley has written extensively about the disk layout of modern Macs. It’s really big and complicated, but if you want more details than what I wrote, here’s a good starting place: Where’s my Data volume? Navigating boot volumes in macOS 10.15, 11 & 12 – The Eclectic Light Company

6 Likes

I have a business near me that takes old computer equipment and recycles. Usable equipment goes to people who can use it, and the rest goes to recyclers for the metal. I format the disks and they also erase them.

I use three of them to serve media over my local network. Big, cheap drives, plenty fast even for HDR formats, USB2 is compatible with my M1 Mini.

Thanks for the detailed reply. I don’t fully understand it yet but I’m slowly getting there. It is a bit complicated.

Also, I am performing a secure erase (two-pass) from my older Catalina iMac on one of the drives (which uses USB2). Not a fast process on this very slow old 250GB drive.

1 Like

This topic comes up now and then, often without important context and often with overstatements of government policies. My comments will be based on US government guidelines, but the basic principles can be found in guidelines issued in most other jurisdictions. As always, verify your own local requirements.

If you dig into any current data security regulations or guidelines, they always start with data identification and risk classification. Some government units deal with high percentages of very sensitive data, so they mandate physical destruction of all storage media under their control, but that is by no means universal. Examples of units that require device destruction include those handling sensitive defense/intelligence data and devices with sensitive tax information.

For units that do not merit universal high security categorization, simple methods to “clear” data may be acceptable if the device is to remain within the organization, while “purge” methods are required for low-to-moderate risk data on devices that are intended for reuse outside the organization. “Reuse” can include donation, refurbishment, and resale.

Methods to “clear” data include traditional methods to overwrite user accessible data, such as writing zeros or arbitrary data at least once across all media. It also includes cryptographic methods. Data “purge” methods most commonly refer to cryptographic erasure of all data, including data not normally accessible by end users, such as SSD cache data, garbage collection data, and other data managed by the device controller.

Everyone who is considering disposing of personal devices needs to consider their own risk profile, which is a combination of the sensitivity of one’s data and the likelihood of its compromise.

Personally, I think that for most individual personal devices, the risk of compromise is negligible if a device has been purged, and the risk is acceptably small for devices that have been cleared effectively. Of course, others may disagree. If you’re an individual in a sensitive line of work or if you have unusually high value data, your likelihood of being targeted specifically and your idea of “acceptably small” risk would be different, so physical destruction would be merited.

FWIW, if you have traditional hard drives that you plan to destroy, they typically have rare earth magnets that are of interest to recyclers or just as curiosities to play with.

The most commonly referenced source policy document I see in my own work is NIST SP 800-88r2: Guidelines for Media Sanitization. Keep in mind that it is a high-level policy document. Each device has its own specific, recommended methods for clearing, purging, or destroying. Consult the manufacturer’s documentation or general standards, like IEEE 2883 for more information. Also note that recommended methods for any device may change over time.

2 Likes

Hello. Where are you located?

I’m in New York City.

That is functionally equivalent to the command-line method I mentioned. If your macOS is old enough to have Secure Erase in the graphical Disk Utility, it’s the same thing.

I personally think the 2-pass erase is unnecessary - a single pass of writing zeros or random data should be sufficient. But it won’t hurt anything, it will just take longer to finish.

1 Like

The commercial data recovery app “Disk Drill” has a free/demo mode that I believe will let you shred data or wipe free space on many drives. I tried it (it even runs on Golden Gate) and it would even zero-out data on an MS-DOS formatted flash drive…

Some of the older OWC enclosures have eSATA ports, which with the right adapter cable are as good as USB 3.

2 Likes

I have a similar adapter. Note that these adapters support both SATA drives and older IDE/ATA drives, which can be very handy. At around $20-30, they’re definitely worth it if you have some older, loose hard drives that you wish to erase. Recommended!

1 Like

It’s usually not too hard to find smaller “mom and pop” computer repair shops that will resell donated equipment after refurbishing it. They’ll usually say that they will securely erase drives before reselling or disposing equipment, but I’d still do at least a basic “data clearing” operation before handing over any equipment.

Many towns have e-recycling programs that accept consumer electronics equipment for free or negligible cost. I’ll admit that there have been occasions when I’ve dropped off one or two things to be recycled yet returned home with three or four very interesting pieces of equipment. Most towns no longer allow that for, as you may have guessed, data security reasons.

It also took a long time to complete. And then at the very end, the info window said: Erase Failed. I then clicked Done. However looking at the drive in the sidebar of Disk Utility showed empty space. I have no idea what happened or if the erase went to completion. I was unable to eject the drive normally so I simply shut if off and disconnected, then restarted the iMac. No complaints from Catalina. Be that as it may, I disassembled the enclosure, pulled the drive, took it apart, removing the disks. Drive was really well made. Impressive construction. Turns out it was only a 125 GB drive (from 2003 I think).

1 Like

I’d like some hints on destruction as well. Mine were used as NAS drives and definitely have valuable information on them. Is smashing with a hammer the best way? None of the drives are bootable.

Brute force mostly.

I take the circuit board off…screwdriver or just pry it off. The. Take out the screws, pull the platters and smash those with a hammer. Sit them outside in the rain for a couple months and let them rust, then toss in the trash. Laptop spinning drives are generally glass and not metal so just mash those in a bucket and then toss the dust, they shatter into pretty small pieces. Everything but the putting them out in the rain takes maybe 10 minutes per drive.

It is…I guess…theoretically possible to reassemble them but the reassembled would need the exact same model drive to get heads and board from and the platters don’t have any useful identification on them, and the tight tolerances for the the heads mean you would never get the platters flat enough to make it work. I read a report once that a scanning electron microscope could recover some data even on a degaussed drive but with less than stellar reliability…don’t remember the details of how it was done or how the sectors were recovered but it was expensive and slow as I recall and of dubious reliability, so it would probably only be a nation trying it and not Joe Hacker.

If you’re taking a drive apart, save the magnets. I have a bucket full of those which are very useful for many things, despite their often awkward shape.

1 Like

The circuit boards are valuable to repair techs. If someone has a drive with a blown board, they can replace it to get the drive working again. If you know of a repair shop that does this sort of thing, consider giving the board (or the gutted enclosure) to them.

That will shatter glass platters, as you’ve mentioned. It should also make aluminum platters unusable, but I’d use some sandpaper to remove the (very thin) magnetic material from them.

Or use them in art projects.

I read plenty of reports about how a magnetic force microscope can reveal after-images of the magnetic flux on the platters. I’ve never read any report about anyone recovering actual data this way.

If it’s possible, then it’s only being done by government agencies and is an incredibly well-kept secret. I wouldn’t worry about it unless your data is incredibly sensitive, and if it is, you probably have a mandatory destruction protocol you’ll need to follow.

If you have an article talking about actual data recovery, please share it, because so far I’ve only read articles describing how it should be theoretically possible.

I heard somewhere that it is incredibly difficult, because there’s not just one after-image. It is a palimpsest of the current bits, and the bits that were there before the current bits, and the bits that were there before those, and the bits that were there before those, and so on.


Original research paper was Secure Deletion of Data from Magnetic and Solid-State Memory (Peter Gutmann, 1996). It talks about possible recovery using Magnetic force microscopy (MFM) and magnetic force scanning tunneling microscopy (STM), and concludes that a 35-pass override would be sufficient to prevent recovery.

But since then it has been debunked. Mr. Gutmann added two epilogues to the paper. See, for example, the 2008 Wright study Throwing Gutmann’s algorithm into the trash. After a single overwrite with zeros or random noise, not even a single byte can be recovered.

I think more interesting is the problem with SSDs, which contain more pages of data than are currently exposed to the operating system in the file system. If you use the OS to overwrite the data, it will not actually erase all of the pages – it can’t see the pages that are in reserve. What’s needed is to send a wipe command to the SSD drive, and let it do the secure erasure.

Google says that a TRIM command will take care of it, but it cites as a reference TidBITS Talk.

1 Like

Not of bits, of magnetic impulses. The mapping of flux onto bits is not straightforward or obvious for modern equipment.

I’ve read about the possibility of recovery from people like Steve Gibson, but he was referring to old FM, MFM, GCR and RLL drives (see also Wikipedia), where it is reasonably possible to do this kind of mapping.

But with modern drives implementing extremely high densities and perpendicular recording, even the experts (including Gibson) have concluded that this kind of recovery is not actually possible.

But don’t take my word for it. Here’s an excerpt from a GRC podcast from September 19, 2023 (emphasis is mine):

Although he does go on to claim that you need a 2-pass random-data process to be certain (and was promoting his software tool for this purpose):

1 Like