shred is the tool everyone reaches for, but it’s far from the only one — and on modern SSDs and journaling filesystems, it’s often the wrong one. This post covers the alternatives: secure-delete, wipe, blkdiscard, hdparm, nvme-cli, and the macOS equivalents — plus why full-disk encryption is now the recommended approach for serious data hygiene.

The Uncomfortable Truth First

Before listing tools, accept what they cannot do:

  • SSDs use wear leveling. When you “overwrite” a logical block, the controller writes to a fresh physical cell and remaps. The original cell still holds your data until garbage collection (or never, if it lives in over-provisioned space). Tools like shred and srm were designed for spinning rust and offer little to no guarantee on SSDs.
  • Journaling filesystems (ext4, xfs, btrfs, APFS, ZFS) keep copies. Snapshots, journals, and copy-on-write metadata can preserve data your “secure delete” tool never touches.
  • Backups, swap, RAM, and TRIM caches are out of scope for any per-file tool.

The two reliable approaches are:

  1. Cryptographic erase — encrypt the disk from day one (LUKS, FileVault, dm-crypt). To “delete” the data, destroy the key. This is the modern recommendation.
  2. Whole-device wipe via the controller — hdparm --security-erase (SATA), nvme sanitize (NVMe), or blkdiscard (TRIM). These talk to the drive firmware directly.

Per-file overwriting still has its uses (HDDs, USB sticks, compliance checkboxes), so let’s go through the tools.

Linux: Per-File Tools

secure-delete

The secure-delete package bundles four utilities. On Debian/Ubuntu:

sudo apt install secure-delete
ToolPurpose
srmSecurely delete a file or directory
sfillWipe free space on a mounted filesystem
sswapWipe a swap partition
sdmemWipe RAM (called smem historically)

srm follows the Gutmann-inspired scheme: 1 pass of 0xff, 5 random passes from /dev/urandom, 27 special-pattern passes, 5 more random passes, then rename and truncate. Files are opened O_SYNC with fsync() between passes.

# Secure delete a single file (38 passes — slow)
srm -v sensitive.pdf

# Faster: single random pass (still better than rm)
srm -v -l sensitive.pdf

# Two passes (random + 0x00)
srm -v -l -l sensitive.pdf

# Recursive
srm -v -r ~/old-project/

Caveats: secure-delete hasn’t seen meaningful upstream development in years, and the Gutmann algorithm is overkill for any drive made after ~2001. The tool still works fine for HDDs.

wipe

A leaner alternative, also for magnetic media:

sudo apt install wipe

wipe -rf ~/old-project/      # recursive, force
wipe -q sensitive.pdf        # quick mode (4 random passes)

wipe is more actively packaged than secure-delete on most distros and has saner defaults.

shred (for completeness)

Comes preinstalled with coreutils. Useful for whole HDD partitions, less so for individual files on a journaling FS:

shred -vzu -n 3 sensitive.pdf   # 3 random passes + zero, then unlink
shred -vzn 1 /dev/sdX1          # wipe a partition (HDD only)

Don’t use shred on SSDs — it just wears them out without a guarantee.

Linux: Whole-Drive Wipes (the Reliable Path)

blkdiscard (SSDs with TRIM)

Tells the SSD controller to mark every block as unused. The controller does the physical erase on its own schedule (or immediately, if you ask):

# Verify TRIM support
lsblk --discard

# Dry-run friendly — this is destructive!
sudo blkdiscard -v /dev/sdX

# Force a "secure" discard if the drive supports it
sudo blkdiscard -s /dev/sdX

Fast (seconds, not hours) but trusts the controller to honor the request.

hdparm –security-erase (SATA SSDs and HDDs)

Issues the ATA Secure Erase command. The drive firmware wipes everything, including over-provisioned cells:

# Check if the drive is "frozen" by BIOS
sudo hdparm -I /dev/sdX | grep -i security

# If frozen: suspend & resume the laptop, then retry
# Set a temporary password (required by the spec)
sudo hdparm --user-master u --security-set-pass PWD /dev/sdX

# Erase
sudo hdparm --user-master u --security-erase PWD /dev/sdX

This is the correct way to wipe a SATA SSD before resale or disposal.

nvme-cli (NVMe drives)

NVMe drives don’t speak ATA, so use nvme-cli:

sudo apt install nvme-cli

# Sanitize is preferred when supported (NVMe 1.3+)
sudo nvme sanitize /dev/nvme0n1 --sanact=2   # block erase

# Otherwise, format with crypto erase
sudo nvme format /dev/nvme0n1 --ses=2        # cryptographic erase
sudo nvme format /dev/nvme0n1 --ses=1        # user-data erase

sanitize is the modern, standardized method; format --ses is the fallback.

Cryptographic Erase (the Lazy Win)

If the drive was encrypted with LUKS from the start, you don’t need any of the above. Just shred the keyslot:

sudo cryptsetup erase /dev/sdX

Done. The data is now ciphertext with no recoverable key.

macOS: What Apple Removed and What’s Left

macOS used to ship srm, an Empty Trash Securely menu item, and rm -P. Apple has progressively removed all of them:

  • srm was removed in macOS 10.12 Sierra (2016) because it gave a false sense of security on SSDs.
  • Secure Empty Trash was removed in OS X 10.11 El Capitan.
  • rm -P still exists on some versions but is documented as ineffective on SSDs and APFS.

What to use instead

1. FileVault (the official answer). Every modern Mac ships with hardware-encrypted storage; FileVault adds a user-controlled key. To “securely delete” a Mac, erase the volume — the encryption key is destroyed and the data becomes unrecoverable:

# Check FileVault status
fdesetup status

2. diskutil secureErase for whole volumes / free space. Still works on HDDs and external media:

# Erase free space on a mounted volume (level 0–4)
# 0 = single-pass zero, 1 = random, 2 = 7-pass DoE, 3 = 35-pass Gutmann, 4 = 3-pass DoD
diskutil secureErase freespace 1 /Volumes/ExternalHDD

# Erase a whole disk (HDD only — Apple discourages this on SSDs)
diskutil secureErase 1 disk2

Apple’s docs explicitly say: don’t use this on SSDs — it wears the drive without improving security. Use FileVault and erase the volume instead.

3. Install GNU coreutils for shred (HDDs / external drives only):

brew install coreutils
gshred -vzu -n 3 sensitive.pdf

4. Install wipe via Homebrew:

brew install wipe
wipe -q sensitive.pdf

5. The “erase free space” workflow for FileVault Macs. With FileVault on, deleted file blocks are still ciphertext. Trimming them clears the mapping; the underlying key remains protected:

# Trigger TRIM on the boot volume (APFS handles this automatically)
sudo fsck -fy

In practice, on a FileVault-protected APFS volume you don’t need a per-file shredder at all.

A Decision Tree

  • Single HDD, single file you want gone? → wipe or srm.
  • SSD or NVMe, single file? → You probably can’t. Encrypt the volume going forward; for the existing file, the next garbage-collection / TRIM cycle is your best bet.
  • Wiping a whole SATA SSD before disposal? → hdparm --security-erase.
  • Wiping a whole NVMe before disposal? → nvme sanitize (or nvme format --ses=2).
  • The drive was already LUKS-encrypted? → cryptsetup erase and stop worrying.
  • macOS, individual files? → Don’t bother per-file; rely on FileVault. To wipe a whole external HDD: diskutil secureErase.
  • macOS, whole Mac before sale? → System Settings → “Erase All Content and Settings” (destroys the FileVault key).

TL;DR

The era of multi-pass overwriters is over for any drive made in the last decade. Use secure-delete or wipe only on HDDs and external media; use blkdiscard, hdparm, or nvme sanitize to wipe whole SSDs; and encrypt your disks from day one so that “secure deletion” reduces to throwing away a key.

Sources