← all articles

How to securely wipe a device before it leaves your hands

Why this matters before the device is even out the door

Every time you sell a phone, hand a laptop down to a family member, return a work computer, or drop an old hard drive off at an e-waste bin, you’re making a bet. The bet is that whoever touches that device next either can’t or won’t go looking for what used to be on it. Most of the time that bet pays off, because most people who buy a used phone off a marketplace app just want a working phone. But “most people” isn’t the whole threat model. Some buyers flip devices for parts and pull drives first. Some refurbishers image drives before wiping them, intentionally or by mistake. Some drives end up in a pile at a recycler for months before they’re actually destroyed. None of that requires a sophisticated attacker. It just requires someone with a little patience and a USB adapter.

The goal here isn’t to make you paranoid about every used-phone sale. It’s to explain what “securely wipe a device” actually means at the level of the hardware, so you can tell the difference between a wipe that works and one that only looks like it worked.

Deleting a file is not the same as wiping a device

This is the part that trips people up because the file system lies to you, gently. When you delete a file and empty the trash, the operating system doesn’t reach out and erase the bits that made up that file. It removes the file’s entry from the index that says “this file lives at these blocks” and marks those blocks as free space, available to be overwritten by something else in the future. Until something else actually writes over those blocks, the old data is still sitting there, physically. Basic recovery software can walk the drive looking for content that looks like an intact file and pull it back, often with no special access at all.

This is true whether the file is a spreadsheet, a browser history database, or a folder of photos. “I deleted it” and “it’s gone” are different claims, and a lot of casual advice conflates them.

SSDs and hard drives don’t erase the same way

On an old-fashioned spinning hard drive, overwriting works pretty much how you’d picture it: the drive head writes to the same physical location every time you tell it to write to a given logical block. Overwrite that block with zeros or random data a few times and the original content is gone in any practical sense.

Solid-state drives complicate this. SSD controllers use wear leveling, which spreads writes around the physical flash cells so no single cell wears out faster than the rest. When you tell an SSD to overwrite a logical block, the controller often writes the new data to a different physical location and marks the old one as stale, to be cleaned up later by garbage collection. That means a file-shredding tool that overwrites files at the file-system level can leave the original data intact in flash cells that the controller has quietly retired from active use. This is why software-level “secure delete” tools built for hard drives are not a reliable way to wipe an SSD.

SSDs have their own dedicated mechanism instead: commands like ATA Secure Erase or NVMe Sanitize, issued to the drive’s own firmware. The firmware, not the operating system, decides what physical cells hold what data, so it’s the only thing actually positioned to guarantee every cell gets cleared, including the ones garbage collection hasn’t gotten to yet.

The trick modern phones and laptops actually use: crypto-erase

Here’s the good news: you rarely need to think about any of the above on a modern phone or laptop, because the operating system already solved it a different way. iPhones, most current Android phones, Macs with a T2 chip or Apple silicon, and Windows machines with BitLocker or device encryption turned on all encrypt the entire storage volume by default, using a key that’s generated on the device and never leaves it in usable form.

When you do a real factory reset on one of these, the device usually doesn’t bother overwriting the whole drive at all. It just destroys the encryption key. Every bit of your data is still physically sitting on the flash chips, but without the key it’s indistinguishable from random noise. This is called crypto-erase, and it’s both faster and, when it works correctly, more thorough than trying to overwrite a modern SSD block by block. The catch is that it only works if encryption was actually on before you wiped, and if the reset process actually completes the key destruction rather than getting interrupted. That’s why “erase all content and settings” on an iPhone or “reset this PC” on Windows with the “clean the drive” option selected are meaningfully different from just deleting your files and handing the device over.

What the reset needs to actually do

  • Phones (iOS and Android): use the built-in “erase all content and settings” or “factory reset” option from system settings, not a manual folder-by-folder delete. Let it finish uninterrupted, and don’t skip the setup screen check afterward, that’s your confirmation it actually reset rather than getting stuck.
  • Windows: use “reset this PC,” choose “remove everything,” and pick the option to fully clean the drive rather than the quick version, especially if you’re not sure the drive was encrypted the whole time you owned it.
  • Mac: on recent macOS versions, “erase all content and settings” from System Settings handles the crypto-erase automatically. On older machines without a T2 or Apple silicon chip, a full reinstall with disk erase is the more reliable path since there’s no guaranteed hardware-backed key to destroy.
  • Standalone SSD or old hard drive going into a new machine: for an SSD, use a secure erase utility that talks to the drive’s own firmware rather than a file shredder. For a spinning hard drive, a single full overwrite pass is generally accepted as sufficient by current guidance, the old advice about needing seven or more passes came from a much older, narrower threat model and isn’t necessary for a typical resale or recycling scenario.

Things people forget: SD cards, SIM cards, and paired accounts

Wiping the main device doesn’t touch anything you popped out of it. SD cards and SIM cards need to be wiped or physically removed separately, they aren’t automatically cleared by a phone’s factory reset. And a factory reset doesn’t undo the fact that the device was, until a minute ago, an authenticated member of your accounts. Before you hand something over, sign out of iCloud or your Google account on the device itself, remove it from Find My or Find My Device’s list of trusted devices, unpair it from your car’s Bluetooth and any smart home hub, and check whether it’s listed as an authorized device on any streaming or password manager account. A wiped phone that’s still listed as a trusted device somewhere is a smaller problem than a phone with your files on it, but it’s still loose end worth closing.

When a wipe isn’t the right tool

If a drive doesn’t need to hold resale value, physical destruction is a legitimate and simple option: a hard drive with its platters bent or drilled through, or flash memory that’s been physically shredded, doesn’t need a secure erase step at all because there’s nothing left to read. Degaussing works on magnetic hard drives but does nothing to flash-based storage, since SSDs don’t store data magnetically. This trades away any resale or reuse value, so it makes the most sense for drives that failed, that held especially sensitive material you don’t trust a software wipe to handle, or that are old enough you were going to recycle them anyway.

Trade-ins and disposal services

If you’re using a manufacturer trade-in program, a carrier buyback, or a third-party electronics recycler, most reputable ones do run a wipe as part of intake, but you’re trusting their process rather than verifying it yourself. Doing your own reset before the device leaves your hands means you’re not depending on that trust. It also protects you in the ordinary case where the “recycler” is really a reseller, or where a device sits in a warehouse for weeks before anyone gets to it.

A short checklist before it leaves your hands

  • Confirm encryption was on for the life of the device, if it’s a phone or a modern laptop this is usually the default.
  • Run the actual built-in reset option and let it finish, don’t just delete files.
  • Remove and separately wipe or keep any SD card and SIM.
  • Sign out of accounts, remove from Find My/Find My Device, unpair Bluetooth and smart home links.
  • For a bare SSD you’re not resetting through an OS, use a firmware-level secure erase, not a file shredder.
  • For a spinning hard drive, one full overwrite pass or physical destruction if it’s not going to be reused.

None of this makes a device untraceable or guarantees nobody could ever recover anything under any circumstances. What it does is close the gap between “I deleted my stuff” and “my stuff is actually gone,” which is the gap that catches almost everyone who skips this and later wishes they hadn’t.

Want more explainers like this one, written the same way, threat model first and no magic-bullet advice? Head back to the home page for the rest of what we cover on The Privacy Wire.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →