Securely Wiping Drives on Linux: shred, SSD Secure Erase, and NVMe Sanitize

Securely Wiping Drives on Linux: shred, SSD Secure Erase, and NVMe Sanitize

You are selling a laptop, returning a leased server, recycling an old drive, or retiring a disk that held customer data. Deleting files or reformatting is not enough: the data remains on the disk. This guide covers how to erase drives properly on Linux, and why the right method depends entirely on whether it is a hard drive or an SSD.

Every command here destroys data permanently. Double-check the device name with lsblk before running anything, and make sure you have backups of anything you want to keep.

lsblk -o NAME,SIZE,MODEL,SERIAL,TYPE,MOUNTPOINTS

Hard drives vs SSDs

Hard drives (HDDs) store data at fixed physical locations. Overwriting a sector really does replace what was there, so overwriting the whole device works.

SSDs do not. To spread wear evenly, the drive’s controller remaps every write to a fresh physical cell and keeps the old one around until it is reclaimed. They also have over-provisioned space the operating system cannot see. Overwriting from the outside can leave old data in cells you cannot address. The only reliable way to erase an SSD is to ask the drive itself to do it.

DriveMethod
HDDOne full overwrite (shred or dd)
SATA SSDATA Secure Erase (hdparm)
NVMe SSDnvme sanitize or nvme format with secure erase
Any fully encrypted driveDestroy the key (cryptographic erase)

Hard drives: one pass is enough

sudo shred -v -n 1 -z /dev/sdX
  • -n 1: one pass of random data
  • -z: a final pass of zeros, so the drive looks blank
  • -v: show progress

Or with dd:

sudo dd if=/dev/zero of=/dev/sdX bs=4M status=progress conv=fsync

One pass is enough on modern hard drives. The famous 35-pass Gutmann method was designed for encoding schemes from decades ago and is pointless today. On a multi-terabyte drive, a single pass already takes hours. Our dd guide covers the flags.

SATA SSDs: ATA Secure Erase

SATA SSDs implement the ATA Secure Erase command, which tells the controller to erase every cell, including remapped and over-provisioned ones.

sudo hdparm -I /dev/sdX | grep -A8 -i security

Look for supported and not frozen. If it says frozen, the firmware locked security commands at boot. Suspend and resume the machine (systemctl suspend), then check again; that usually unfreezes it.

Then set a temporary password and erase (the password is required by the ATA standard and is cleared by the erase):

sudo hdparm --user-master u --security-set-pass tmp /dev/sdX
sudo hdparm --user-master u --security-erase tmp /dev/sdX

Use --security-erase-enhanced if hdparm -I reports enhanced erase support; it also clears reallocated sectors.

Do this on a desktop with the drive connected directly to SATA, not through a USB adapter, which usually blocks these commands. And do not interrupt it.

NVMe SSDs: sanitize or format

NVMe drives have their own commands, available through nvme-cli:

sudo apt install nvme-cli
sudo nvme id-ctrl /dev/nvme0 -H | grep -iE 'sanitize|format|crypt'

Sanitize (preferred)

Sanitize erases the entire drive, including caches and unallocated areas, and resumes automatically after a power loss:

sudo nvme sanitize /dev/nvme0 --sanact=2     # block erase
# or --sanact=4 for crypto erase, if supported
sudo nvme sanitize-log /dev/nvme0             # check progress

Format with secure erase

If sanitize is not supported, a format with a secure erase setting works on the namespace:

sudo nvme format /dev/nvme0n1 --ses=1     # user data erase
sudo nvme format /dev/nvme0n1 --ses=2     # cryptographic erase, if supported

Our nvme-cli guide covers the drive’s capabilities and health information.

blkdiscard

blkdiscard tells the drive to discard every block. It is quick and works on most SSDs, but whether discarded cells are actually erased immediately is up to the firmware. Treat it as a good first step, not a guaranteed sanitise:

sudo blkdiscard -f /dev/nvme0n1

The best method: encrypt from the start

If the drive was fully encrypted from the day it was set up, erasing it is trivial and reliable: destroy the key, and everything on it becomes random noise.

With LUKS:

sudo cryptsetup luksErase /dev/nvme0n1p3

That wipes every keyslot in the LUKS header. Without a header backup, the data is unrecoverable. (If you kept a LUKS header backup somewhere, destroy that too.)

This is why full-disk encryption is worth setting up even on machines that never leave the house: when the drive is retired, failed, or sent back under warranty, the data on it is already safe. See LUKS disk encryption.

What about single files?

shred file.txt overwrites a file in place, but on modern systems it is not reliable:

  • SSDs remap the writes, as above
  • Journaling filesystems like ext4 may keep copies in the journal
  • Copy-on-write filesystems like Btrfs and ZFS write new data elsewhere by design
  • Snapshots and backups keep old versions

Treat single-file secure deletion as unreliable, and rely on disk encryption instead.

Check your work

After erasing, read a sample of the drive; it should be zeros or random data:

sudo hexdump -C /dev/sdX | head
sudo dd if=/dev/sdX bs=1M count=100 skip=10000 | hexdump -C | head

And check the drive’s health before reusing or selling it with smartctl.

Frequently Asked Questions

Does shred work on SSDs?

No, not reliably. SSDs remap writes to different physical cells for wear levelling, so overwriting a file or even the whole visible drive can leave old data in cells the operating system cannot address. Use the drive’s built-in secure erase or sanitize command instead.

How many passes are needed to wipe a hard drive?

One pass of zeros or random data is enough for modern hard drives. The multi-pass methods from the 1990s were designed for much older recording technology. A single full overwrite of the whole device makes data unrecoverable by software and practical lab methods.

What is the difference between NVMe format and sanitize?

Format with a secure erase setting erases the namespace, either by erasing user data or by destroying the encryption key. Sanitize is a more thorough command that applies to the whole drive, including caches and over-provisioned areas, and continues even if interrupted by a power loss. Use sanitize when the drive supports it.

Why does hdparm say the drive is frozen?

Many BIOSes put SATA drives in a security frozen state at boot to prevent malware from issuing secure erase commands. Suspending the computer and waking it, or hot-plugging the drive after boot, usually unfreezes it so the erase can proceed.

Can I securely delete a single file?

Only on hard drives with traditional filesystems, and even then journaling can leave copies. On SSDs, copy-on-write filesystems like Btrfs and ZFS, or anything with snapshots, single-file secure deletion is not reliable. Encrypting the whole disk from the start is the practical solution.

What is cryptographic erasure?

If a drive is fully encrypted, destroying the encryption key makes all data unreadable instantly. Self-encrypting drives do this in their secure erase commands, and with LUKS you can destroy all keyslots with cryptsetup luksErase. It is fast and reliable, provided the encryption was in place from the start.