PhantomWipe · Future work
Sensitive files deserve a considered ending.
We’re developing a deletion approach shaped by modern Mac storage, including a protected workspace with an independently revocable key for each managed file.
Planned approach
-
Protected workspace
Encrypt managed files before their content is first written to storage.
-
Separate file keys
Give each managed file its own key.
-
Deliberate key removal
Revoke a file’s key as part of a controlled deletion operation.
The storage
Start with how the storage works
On an SSD, rewriting a file does not guarantee that every old physical copy has been overwritten. Modern filesystems can also retain earlier data through snapshots, clones and backups. A progress bar or a pass count cannot establish that all those copies are gone.
That is why PhantomWipe’s direction includes clear result reporting and methods matched to the storage involved.
The planned workspace
Protect the file from its first write
The planned Protected Workspace would encrypt managed files before their content is first written to storage, with a separate key for each file. Deleting a managed file would revoke its key as part of a controlled operation, allowing other files in the workspace to remain accessible.
This approach depends on the file being managed inside that workspace. It cannot retroactively protect an earlier unencrypted copy or erase copies held in backups, previews, application caches or other locations. Recoverable keys also affect what deletion can guarantee.
The intended experience
Make the result understandable
The intended experience tells you what completed, what remains and what the system could verify. Skipping the Trash is only one part of the workflow. Open files, recovery and interrupted operations need their own handling.
The launch list
Follow the wider PhantomSecure build
Get occasional development notes about PhantomProtect and the products planned to follow it.
PhantomProtect is in development. No public release date has been announced.