$2,000,000 Clean Room! - DriveSavers Data Recovery Tour - YouTube

Channel: unknown

[0]
You'd never know it from the outside
[1]
But in there through those doors is one of the world's oldest and most
[6]
advanced data recovery companies. Drive Savers headquarters here in Novato, California
[12]
features almost a hundred employees
[14]
Almost that many security certifications and a two
[19]
million dollar ISO five clean room and
[24]
they sponsored us down here to have a close look at how it is they take this and
[31]
Turn it in to this
[33]
So let's go inside
[37]
( Intro Music plays)
[45]
We're gonna kick things off in the museum
[48]
as
[50]
Long as our escort says that that's okay
[54]
Security is a huge
[55]
Deal at Drive Savers not just on the outside of the building, but also throughout it, so guests get these incredible
[63]
badges that actually change color over time
[66]
eventually turning red so that anyone who sees it will know to - kick me out or call the cops and
[73]
everything in here is on a need to access basis with biometric security on secure spots and
[80]
Annual background checks for all staff members So these guys have recovered data from pretty much
[87]
everything that you would normally think of - hard drives phones laptops SSDs and
[93]
From a lot of things that you probably wouldn't think of
[97]
defibrillators photocopy machines and even a TiVo so the museum here contains many of their biggest success stories both
[105]
in terms of the importance of the data
[107]
That was recovered, uh they once saved Twisted Sisters Christmas album and twelve episodes of The Simpsons
[114]
Including the conclusion of the who shot mr.. Burns cliffhanger during a national contest to guess who did it and
[121]
in terms of the difficulty so
[124]
run over by an 18-wheeler check, lit on fire
[127]
Check buried in a mudslide check that too - this one that you're looking at right now was actually pulled from a sunken
[135]
Cruise ship after sitting underwater for two days, it had the owner's memoirs
[141]
Successfully recovered from it now. Let's talk about how they do it
[146]
Consultation and in some cases even diagnosis with an analysis of what data they expect to get back is free
[153]
so you send in your drive, we're shipping sorts it into a colored bin according to the priority of the job and the uhh (cough)
[160]
Cleanliness of the drive or device and you might think to yourself ah come on. It's a hard drive
[166]
how dirty could it be, but they've actually had to obtain a Geiger counter to evaluate the
[173]
radioactivity of drives coming out of nuclear disasters
[177]
And through some of their forensics work
[178]
They've even seen devices come through here that were found on murder victims
[184]
One phone apparently had the camera element gouged out
[188]
Before being placed back on the victim's body in an apparent attempt, to get rid of the photos
[194]
So yeah drive savers got that **** back good work idiot
[199]
Hope prisons treating you well, from shipping your bin travels to one of a few different places
[203]
and we'll go through those in a minute, but
[206]
Everything will eventually get the cloning treatment and that starts here drive savers keeps a huge inventory of spare
[214]
Wiped donor drives because, you dramatically improve your chances of recovery if you're working with a bit 4-bit
[221]
Digital copy of your data set it gives you the time to analyze more than just what files were there and then dig into
[229]
Who accessed them when, what did they do?
[233]
These kinds of things can be particularly important in cases of corporate intellectual property protection for example
[239]
Where there might have been some attempt to destroy data or cover up a data access
[244]
The folks in this room also do the initial analysis of raid arrays using
[249]
Software tools like the one you're looking at here to rebuild the array logically and determine which drives are probably working fine
[257]
Versus which ones will likely need physical repairs before making a cloning attempt, and they've got the hardware for everything from
[265]
Reconstructing a - a four drive home Nazare to this over here. This is a 45 drive j baud
[271]
That's on standby waiting for I don't know maybe another
[276]
96 drive server that got gallons of water dumped on it due to a sprinkler system malfunction because, yeah
[282]
That was a thing that happened
[284]
but as you saw in the museum a
[286]
Lot of the hard drives that come through here need a lot more than a little bit of software rika jiggering so
[292]
Welcome to the clean-room!
[295]
Or strictly speaking. This is the inventory room and the cleaner was on the other side of the glass, but but this stuff's cool
[302]
Too in here, they've got basically every hard drive. You could imagine. They've got two and a half inch!
[309]
they've got three and a half inch!
[311]
They've got Todd the latest helium sealed drives and all the way from the latest to look at these
[317]
Clunkers, I mean look at this, this is called a mini scribe
[322]
I guess you know relative to this guy
[327]
It is pretty mini, but basically the point is
[331]
Whatever the text on the other side of the glass inside that is o5 cleanroom so that is less than 100
[339]
Thousand point one micron particles per cubic meter ten thousand times cleaner than a normal room, whatever they need
[346]
They put a request onto this little cart. It comes out here. We load it up
[350]
We fire it back in there and whether it's a brand new driver an ancient one they start the process of
[356]
Rebuilding one working drive from the donor and the recipient
[362]
Now they did put away some of the proprietary equipment that they use, uh for example
[366]
They found a way to work on helium sealed drives, which won't function at all in regular air
[372]
That's seven times more dense and so they wouldn't show us like I don't know how they either
[378]
Reseal them or put them in a helium chamber or something, but this place is still
[384]
incredible, so thanks to the
[386]
34 filtered fans air is circulated in here so quickly that it's not only clean
[393]
But they can actually do soldering work
[396]
Anywhere in this room without disrupting anyone else's sensitive recovery operation
[402]
incredible, and an
[405]
operation it is
[406]
They actually agreed to let us do an actuator swap so
[410]
Stay tuned for that video because I'm super stoked for you guys to see it. Anyway for now let's continue our journey so then
[416]
With the drive physically working, I mean it's copying data. They can just ,send it back to you, right
[423]
wrong so this guy right here is
[427]
Working, but it is not reliable drive savers wouldn't be able to keep their warranty approved service status with
[435]
Every major hard drive vendor for very long if they pulled that kind of a stunt so the next step, then is
[442]
Logical recovery where, maybe not all but some of the data should be recoverable even in cases of severe physical
[450]
Damage, like we saw downstairs in the museum, and we're going to head over there
[454]
But first we need to make a quick stopover in flash memory town now hard drive recovery is complicated
[462]
Flash memory hoho well, that's a whole other ballgame son.
[467]
So what you're looking at here is raw ones and zeros off a flash chip
[472]
So you can think of it kind of like a QR code?
[475]
except that there is no app for your phone to read it and
[479]
Making matters even more difficult this middle spare area part right here
[484]
Well, that contains information about where the block numbers are where your ECC belongs etc. It's such a really good stuff except
[491]
Oh wait
[492]
That gets intentionally scrambled in many cases as a security measure
[497]
So figuring out which bytes are bad and getting the whole thing to turn green
[502]
Takes a lot of knowledge and then to do it quickly takes years of
[507]
Experience and even getting it to that point isn't trivial in many cases flash memory chips require
[513]
proprietary not to mention expensive readers and
[517]
They come from devices, but don't always want to give them up easily including everything from
[522]
standard Apple or MDOT 2 to SSDs and computers to, camcorders
[528]
Mp3 players like what year is it?
[530]
I know right. and even bear flash chips that are soldered on to the motherboard like in some of the latest Mac books
[537]
THANK YOU APPLE and the craziest part is coming back to device security again on a
[544]
Device with a security module, like an iPhone for example, so you can see in this footage
[550]
They're taking apart and iPhone 10 for us that might later
[553]
Be used as a known good for a customer recovery attempt. You could actually need at least
[560]
FOUR components to even hope to pull data off of it the NAN flash itself, which needs to be de
[567]
solder from the board and
[570]
The baseband I see the controller which you can actually see from this disassembled A8 chip
[576]
actually sits under the RAM with contacts on the top and bottom and
[581]
The ROM. So four parts, which means that if you were to hope to pull data from a badly damaged, one of these
[588]
You would need to desolder, clean, reball, and resolder all of these four components
[596]
successfully to a donor phone and did I mention by the way that even the couple generations old A8 processor already had
[604]
eleven-hundred contact points, so they apparently haven't attempted an operation like this with the ten YET
[610]
But they think that it might be possible (#MIND BLOWN LINUS)
[617]
Finally we're in
[618]
Logical land now stuff without any physical damage to the hard drive itself may end up coming straight here like
[626]
Let's say for example
[627]
You plug the wrong power supply into your external drive enclosure like this and it released all of its magic blue smoke
[636]
Tella he actually sent this drive to drive savers four years ago
[640]
But ended up opting not to go forward with the recovery service
[644]
So as you can see from what we pulled off of this drive. It's clear that for some people
[649]
It's not necessarily going to make sense necessarily
[653]
to pay for data recovery if all you've got that's
[657]
Not backed up somewhere is
[659]
Clips from a Cheech and Chong live concert. With that said, even around here at Drive savers where their bread and butter is
[667]
failed or corrupted devices, they still absolutely
[672]
preach the principles of data
[675]
backup, because
[677]
the cold hard truth is even if you are an extremely skilled data recovery
[683]
engineer there are still things that can take out your storage
[688]
permanently. So I think a perfect example of that is our host today, Mike, ended up losing
[694]
pretty much all of his data in the Santa Rosa fires. So even though he's an executive here at DriveSavers
[701]
there was nothing he would have been able to do about that if he hadn't had an
[706]
off-site backup. So at the end of the day, that's the takeaway guys.
[712]
Make backups of your data; the three-two-one principle should never be ignored
[717]
But in the event that something goes terribly wrong
[721]
Drive savers has got your back. I want to thank them for making this video possible
[725]
I want to thank you guys for watching and you can check out the link to drive savers in the video description (bloopers time!)
[732]
Yeah, no no. No I think I can I think I can do it no problem this time. OK OK (SUBSCRIBE FOR MORE AWSOME CONTENT)