Silk Road forums

Discussion => Security => Topic started by: BillGates on July 12, 2012, 06:39 am

Title: Removing all traces of Tor without complete format
Post by: BillGates on July 12, 2012, 06:39 am
If someone wanted to remove all traces of tor without a complete format (and they didnt load of a USB or anything silly like that) from Windows.

Would simply deleted the folder and running a Redactor program to wipe all deleted files be sufficent?

Or does Tor leave any traces in the documents folder or anywhere else?
Title: Re: Removing all traces of Tor without complete format
Post by: ecspl0ded on July 13, 2012, 01:18 pm
complicated topic

the only sure way to remove all traces is to remove your hard drive and take a sledge hammer to it

I'm no expert, but traces are probably left everywhere. Perhaps you still have a page file enabled? disk erasor tools don't work with SSD drives and there are many caveats of usage -- personally I would say if you are even considering using one of these tools you should consider yourself compromised.

if you are only buying personal amounts of drugs over the internet though, who cares?
Title: Re: Removing all traces of Tor without complete format
Post by: club on July 13, 2012, 01:34 pm
If someone wanted to remove all traces of tor without a complete format (and they didnt load of a USB or anything silly like that) from Windows.

Would simply deleted the folder and running a Redactor program to wipe all deleted files be sufficent?

Or does Tor leave any traces in the documents folder or anywhere else?

I think that is sufficient. I suppose someone could verify using software that compares system snapshots before and after the deletion of the tor directory. But I think youre in the clear. Next time, you could try keeping tor on a flash drive, or better yet, on a flash drive within a truecrypt volume.
Title: Re: Removing all traces of Tor without complete format
Post by: fuckthepolice101 on July 15, 2012, 08:57 am
There are several ways to stay stealth with the tor program itself.

as already suggested there's truecrypt. Create a truecrypt volume and have your tor bundle in a folder in the truecrypt volume.

Another option is to have a virutal machine and run tor inside that. Then have a panic button ready to go if you ever get raided. The panic button will delete the tor folder inside the vm, then delete the vm hard drive itself, then it will zero out the sectors where the vm was.

Another simpler solution is to have tor bundle package on a iron key.
Title: Re: Removing all traces of Tor without complete format
Post by: kmfkewm on July 15, 2012, 09:18 am
complicated topic

the only sure way to remove all traces is to remove your hard drive and take a sledge hammer to it

I'm no expert, but traces are probably left everywhere. Perhaps you still have a page file enabled? disk erasor tools don't work with SSD drives and there are many caveats of usage -- personally I would say if you are even considering using one of these tools you should consider yourself compromised.

if you are only buying personal amounts of drugs over the internet though, who cares?

Taking a sledge hammer to your drive is exactly what forensic data recovery people want you to do. They can recover data from severely damaged drives but they have a much much much harder time to recover data from a drive that has been overwritten even once. The best method is to overwrite once on track center and once off center using firmware like ATA secure erase. There are currently not any known techniques for recovering data from drives wiped in such a way, but spin stand microscopy will pull a fuck ton of data from a drive that is smashed into even a thousand pieces with a sledge hammer.