shred file.txt # overwrite in place (3 passes by default), file remains
shred -u file.txt # overwrite, then delete
shred -vzn 1 file.txt # verbose, one random pass, plus a final zero pass
sudo shred -vzn 1 /dev/sdX # whole device (DESTRUCTIVE)
Limits (important)¶
shred assumes each overwrite lands on the same physical location as the original data. That is not true for:
- SSDs and flash (wear-levelling remaps writes elsewhere; old cells keep the data),
- copy-on-write and journaling filesystems (btrfs, ZFS, and ext3/4 journals in data-journaling mode),
- filesystems with snapshots, RAID, network storage, or files that have also been backed up or cached.
For these, use full-disk encryption from the start and destroy the key (dm-crypt luksErase), or use the drive's own secure-erase / blkdiscard command. See also scrub and wipefs.