Computer Science · Ch 1 — Computer System
Data Deletion and Recovery
Data Deletion and Recovery
One of the biggest threats to digital data is its deletion — and deletion can happen in several ways:
- storage devices can malfunction or crash, wiping out the data stored on them;
- users can accidentally erase data;
- a hacker or malware can delete data intentionally.
What "deleting" a file really means
Truly deleting digitally stored data would mean changing the data at the bit level, which is very time-consuming. So operating systems take a shortcut: when data is "deleted", its address entry is simply marked as free, and that space is shown to the user as empty — without actually erasing the underlying data. The bits are still on the disk until something else overwrites them.
Data recovery
Because deletion only marks space as free, deleted data can often be brought back. Data recovery is the process of retrieving deleted, corrupted or lost data from secondary storage devices.
The key condition: recovery is possible only if the contents (the memory space marked as deleted) have not yet been overwritten by other data. Once new data occupies that space, the old contents are gone.
Activities 1.4 and 1.5 (from the book): explore the ways of recovering deleted data or data from a corrupted device; then create a test file, delete it with Shift+Delete, and try recovering it using the methods you found.
The two security concerns
There are two opposite security concerns around data, and each has its own safeguards:
1. Unwanted deletion — someone destroys data you want to keep
The threat is deletion by an unauthorised person or software. Safeguards:
- limit access to the computer system;
- use passwords for user accounts and files wherever possible;
- encrypt files to protect them from unwanted modification.