Twenty-six years ago I was consulting for the Massachusetts DEP, a couple years removed from being Deputy Division Director, having passed up the Director's chair for a weirder and more interesting assignment: getting the state ready for a wave of cathode ray tubes nobody in government had really priced out yet.
The wave had a birth certificate. The Telecommunications Act of 1996 didn't just deregulate your phone company — it set in motion the reclaiming of analog broadcast spectrum for the wireless industry, which meant every television station in America eventually had to go digital, which meant every television in America was, sooner or later, going to look like a brick next to a flat panel. Add computer monitors following the same LCD gravity, and you had what I'd call an elective upgrade cycle — nothing was actually broken — about to dump tens of millions of perfectly functional CRT TVs and monitors onto a secondary market that had never seen anything like it. It made possible the critical mass of users who paid for TV broadcasts and internet cable for billions of consumers in the "good enough" or Emerging Market.
"It was Twenty Years Ago Today"
Perfectly functional is the part that got lost. Because a glut of good used electronics is bad news for a specific set of industries: the Planned Obsolescence crowd, who need you buying new; the Big Shred outfits, who get paid by the pound to turn a working monitor into commodity glass and copper; the Haz Waste Disposal industry, which had built permitting and liability empires around leaded glass; and what Peter Buffett labels the charitable-industrial complex, which discovered that "toxic dumping in Africa" made a better fundraising letter than "we shredded a working TV that a family in Lagos would have paid for." Between them, they wrote the overseas dumping narrative — the idea that a container of tested, working CRTs bound for a reuse market overseas was actually poison being smuggled onto a beach. It wasn't nothing — there was real e-waste and real bad actors — but the ratio got inflated by people with a direct financial interest in inflating it, and that ratio became the story.
I bring this up now because the ITAD industry — IT Asset Disposition, the people who take your company's old laptops away — is running a version of the same play today, just with data instead of lead glass. The current bogeyman isn't a container ship, it's the "dark web," and the pitch is the same shape it was in 1999: something terrifying is happening to your stuff after it leaves your hands, and the only responsible answer is destruction, certified, billed by the pound.
Which brings me back to the actual thesis, because this isn't the first time this play has been run, and it wasn't invented for the dark web. It was invented — or at least perfected — for HIPAA.
After your hard drive is shredded to little pieces, how do you verify the serial number? Was that 50 hard drives in the shredded pile? Or was is 49? My industry is increasingly charging you fees to keep that old hard drive info off of the "Dark Web", and we charge $5-15 for a "certificate" for each drive destroyed. And we have rules on HOW we are allowed to destroy it.
FEAR OF RISK FOR SALE. Multiple auditors have pointed to our company's pile of hand-disassembled hard drives, the older ones with neodymium magnets, which we take apart by hand... taking them apart by hand recovers valuable gold-bearing circuit boards, platinum platters, and the magnets and aluminum husks, and creates a safe job for differently abled staff we employ from the Counseling Service. And the serial numbers can be accounted for, still printed on the aluminum backings (unlike a shredded drive). But this "method" wasn't listed by NAID or R2 or whoever, whose standards were transcribed by Blanko or Kobra or Iron Mountain. Multiple auditors point to the platters pictured below, saying that maybe someone will find all the parts and re-assemble these to find out if they were wiped, and sell the data on the Dark Web.
This is like pumping my stomach to put oysters back in their shells and release them back into the wild. I'd need a really heavy dose of something to believe that's a risk.
HIPAA passed in 1996, the same year as the Telecom Act, and somewhere in its long afterlife it got repurposed as the legal justification for destroying old hard drives, on the theory that deleted health records could be resurrected and sold. That was the story, anyway. The story that didn't get told nearly as loudly was that a wiped hard drive sitting in a ten-year-old PC was also sitting on top of a legitimate Windows license, and often a licensed copy of Intuit, QuickBooks, or MS Office — hundreds of dollars of software the original vendors very much did not want circulating for free on the secondary market. Data destruction as a service solved two problems for two different industries at once, and only one of them had anything to do with your health records.
So here's the question I don't think anyone in the ITAD world wants asked out loud: is there an actual market of people buying decade-old PCs off Goodwill shelves, on the off chance the previous owner forgot to wipe a drive, hoping to find a *.doc file mentioning a diagnosis, so they can resell it on the dark web? Or is the dark web, functionally, 100% populated by data stolen while it was still in active use — phished, breached, skimmed, scraped from a live database — because that's simply where the value is?
I'd put money on the second. Your credit card number is far more likely to walk out the door with a crack-addicted waiter who ran it through a skimmer last Tuesday than with someone who paid forty dollars for your Dell Optiplex at a thrift store and spent a weekend running recovery software on the off chance. But "destroy it anyway, just in case" has been a good business since at least 1996 — first for glass, now for data — and good businesses don't correct their own founding myths.
So here's the question I don't think anyone in the ITAD world wants asked out loud: is there an actual market of people buying decade-old PCs off Goodwill shelves, on the off chance the previous owner forgot to wipe a drive, hoping to find a *.doc file mentioning a diagnosis, so they can resell it on the dark web? Or is the dark web, functionally, 100% populated by data stolen while it was still in active use — phished, breached, skimmed, scraped from a live database — because that's simply where the value is?
I'd put money on the second. Your credit card number is far more likely to walk out the door with a crack-addicted waiter who ran it through a skimmer last Tuesday than with someone who paid forty dollars for your Dell Optiplex at a thrift store and spent a weekend running recovery software on the off chance. But "destroy it anyway, just in case" has been a good business since at least 1996 — first for glass, now for data — and good businesses don't correct their own founding myths.
Hard drive magnets, for sale to the dark web thieves who rebuild obsolete hard drives.
What were three big movies released in 1996, while the Telecommunications Act and HIPAA Laws were being written? One about a botched kidnapping inside job, one about drug addiction, and one about patient data (copied from Quora).
- Fargo by Coen Brothers, 1996: Jerry Lundegaard's inept crime falls apart due to his and his henchmen's bungling and the persistent police work of the quite pregnant Marge Gunderson.
- Trainspotting by Danny Boyle, 1996: Renton, deeply immersed in the Edinburgh drug scene, tries to clean up and get out, despite the allure of the drugs and influence of friends.
- The English Patient by Anthony Minghella, 1996: At the close of WWII, a young nurse tends to a badly-burned plane crash victim. His past is shown in flashbacks, revealing an involvement in a fateful love affair.


No comments:
Post a Comment