Skip to content

Informatics Practices · Ch 1 — Computer System

Data Deletion and Recovery

1.3.4

Data Deletion and Recovery

Digital data can vanish far more easily than it was created — a storage device can crash, a user can erase a file by mistake, or a hacker or a piece of malware can wipe it out deliberately. Because deletion is such a routine threat, a student of informatics needs to understand two things clearly: what actually happens inside the storage device when data is "deleted", and how — and under what condition — deleted data can be brought back.

How data gets deleted

Deletion of stored data happens in three broad ways:

  • Device failure — a storage device can malfunction or crash, taking the data stored on it along.
  • Human error — a user can accidentally erase files from a storage device.
  • Malicious action — a hacker or malware can intentionally delete digital data.

What "delete" really means inside the device

Truly erasing data would mean changing the details of the data at the bit level — rewriting the actual zeroes and ones that encode it. Doing this for every deleted file would be very time-consuming. Operating systems therefore take a shortcut: when a file is deleted, only its address entry is marked as free. The space it occupied is then shown to the user as empty, even though the actual contents are still physically present on the device. Nothing has been wiped; the system has merely lost its official pointer to the data and declared that region reusable.

Data recovery

This shortcut is exactly what makes recovery possible. If data has been deleted accidentally or has become corrupted, it can still be retrieved — but only as long as the memory space marked as deleted has not yet been overwritten by some other data. Once new data lands on those locations, the old contents are genuinely gone.

Data recovery is the process of retrieving deleted, corrupted and lost data from secondary storage devices.

The two security concerns around data

Data faces two opposite kinds of danger, and each has its own safeguards.

1. Unauthorised deletion. Someone — a person or a software — who should not have access to the data may delete it. The defences are:

  • limiting access to the computer system itself;
  • using passwords for user accounts and for individual files wherever possible;
  • encrypting files, which also protects them from unwanted modification. …