1.8 KiB
EP Eraser
EP Eraser is a small Debian Live image for securely retiring SATA/NVMe SSDs and rotational HDDs. It boots into a text console inspired by DBAN, but uses device-specific erase methods instead of overwriting every disk indiscriminately.
Safety model
- The tool requires an exact device name and a typed
ERASEconfirmation. - It refuses mounted devices, the live boot device, read-only devices, and devices with mounted descendants.
- SSDs use
blkdiscard --securewhere supported, with NVMe sanitize as an option. - HDDs use a three-pass
shredoverwrite followed by a device-state/status check. - Every operation is logged to
/var/log/ep-eraser.logand a summary is written to the target's parent device metadata only when supported.
No software can guarantee recovery resistance for every controller, reserved area, remapped sector, or damaged drive. For high-assurance disposal, combine this image with the drive vendor's sanitize command or physical destruction according to your organization's policy.
Build
Build from Debian/Ubuntu, WSL, or Docker. The builder must run as root because live-build creates a chroot.
sudo ./build.sh
The output is build/ep-eraser-amd64.hybrid.iso. Write it to a USB drive with a tool such as Rufus or dd. Verify the output checksum before deployment.
To build without installing packages on the host, use Docker from Linux or WSL:
docker build -t ep-eraser-builder .
docker run --rm -v "$PWD:/work" ep-eraser-builder
Use
Boot the target machine from the image, inspect the disk list, and choose the exact device path. The program detects rotational media and presents the appropriate operation. Reboot after completion; do not remove the USB device until the result is shown.
This project intentionally does not include an automatic wipe-all mode.