Use shred Safely: Overwrite, Verify and Remove Files
You will finish with a controlled way to overwrite a file with GNU shred, decide whether to remove its directory entry, and recognise when the result cannot be trusted as secure erasure. The examples match GNU coreutils 9.4, installed here as package coreutils 9.4-3ubuntu6.3.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about fifteen minutes for a single small file, plus longer if you test the storage limitations. You need a shell and a file you are authorised to destroy. Most examples need no elevated privileges. Do not use a real secret for the first test.
Warning
Overwriting and removing a file are destructive. There is no undo command for data that has been overwritten. Confirm the path before pressing Enter and keep a separate backup if recovery might be required.
1. Check the installed command
First confirm which implementation and version will run. This is read-only and does not need sudo:
$ command -v shred
/usr/bin/shred
$ shred --version
shred (GNU coreutils) 9.4
$ dpkg-query -W -f='${Package} ${Version}\n' coreutils
coreutils 9.4-3ubuntu6.3
The command accepts one or more file paths. A missing -u or --remove matters: by default, shred overwrites the file but leaves the directory entry in place. That default is intentional because the command can also target device files, which should not be removed as a side effect.
Checkpoint
You have identified GNU coreutils 9.4 and know that a normal run does not delete the named file.
2. Make a disposable test file
Use a private temporary directory and an unmistakable file name. The commands below create state, but only inside the temporary directory:
$ work_dir=$(mktemp -d /tmp/shred-test.XXXXXX)
$ printf '%s\n' 'not a real secret' > "$work_dir/sample.txt"
$ ls -l "$work_dir/sample.txt"
-rw-r--r-- 1 you you 18 Sep 27 10:00 /tmp/shred-test.A1b2C3/sample.txt
$ wc -c < "$work_dir/sample.txt"
18
The random suffix in the directory name and the timestamp in the listing will differ. Check the path yourself. A shell variable does not make a typo safe, and an unquoted path can be split by whitespace or interpreted as shell syntax.
3. Overwrite without removing
Run one random pass followed by a zero pass for this disposable test. -n 1 keeps the demonstration quick; the installed default is three overwrite iterations. -z adds a final pass of zero bytes, which hides the fact that the file was shredded from a casual inspection.
$ shred --iterations=1 --zero --verbose "$work_dir/sample.txt"
shred: /tmp/shred-test.A1b2C3/sample.txt: pass 1/2 (random)...
shred: /tmp/shred-test.A1b2C3/sample.txt: pass 2/2 (000000)...
$ test -e "$work_dir/sample.txt" && echo 'directory entry remains'
directory entry remains
$ wc -c < "$work_dir/sample.txt"
4096
The progress text and final size are implementation and filesystem details, so do not script against the exact wording or assume a small file will retain its original length. The useful checks here are that the command exited successfully and the path still exists.
For a normal operational run, omit -n 1 unless you have deliberately chosen a different pass count:
$ shred --zero --verbose -- /path/to/file
The -- marks the end of options. It is a useful habit when a file name might begin with a hyphen. Do not use a wildcard until you have inspected exactly which paths it expands to.
4. Remove the file only after checking the path
If the file must disappear as well as being overwritten, use --remove or its short form -u. This is irreversible:
$ printf 'remove this test file\n' > "$work_dir/remove-me.txt"
$ shred --iterations=1 --zero --remove --verbose -- "$work_dir/remove-me.txt"
shred: /tmp/shred-test.A1b2C3/remove-me.txt: removed
$ test ! -e "$work_dir/remove-me.txt" && echo 'removed'
removed
Recent GNU versions use the wipesync removal mode by default. The optional forms are --remove=unlink, --remove=wipe and --remove=wipesync. The latter can be expensive because it synchronises each obfuscated name byte to the device. Use the default unless you have a reason to choose another documented mode.
There is no recovery command after this step. If you removed the wrong file, stop writing to that filesystem and use an approved backup or specialist recovery process. Do not recreate a file with the same name and assume it restores the old contents.
5. Apply the right scope and permissions
shred operates on file contents, not on a directory tree. To process several explicitly selected files, list them after the options:
$ shred --zero --remove -- \
/srv/export/customer-report.csv \
/srv/export/customer-report.csv.sig
You need write permission on each target. The --force option can change permissions to allow writing when necessary, so treat it as a security-sensitive exception and inspect the file metadata first. If the target belongs to another account or protected directory, use the least privilege required by your system policy. Do not make a whole directory world-writable and do not use sudo simply to bypass an uncertain path.
Use --size=N when you intentionally want to overwrite only a defined number of bytes, with suffixes such as K, M and G. That is not a safe default for a complete file: a partial overwrite can leave old content behind. The --exact option prevents rounding file sizes up to the next full block; it is the default for non-regular files.
6. Understand when shred cannot guarantee erasure
The command assumes the filesystem and hardware overwrite the original data in place. That assumption can fail. Copy-on-write filesystems, snapshots, journalling behaviour, RAID layers, flash storage and filesystem compression can preserve older blocks elsewhere. Backups, replicas and cloud sync services can also contain copies that shred cannot reach.
Consequently, a successful exit status means that the requested operation completed according to the local command and filesystem. It does not prove that every historical copy is unrecoverable. On SSDs and other wear-levelled media, use the storage vendor's sanitisation procedure or an approved whole-device encryption and key-destruction process when the threat model requires it. Do not test this claim by shredding a live system file or a mounted device.
Also remember that deleting a file is different from securely erasing its contents. If the data was copied before this guide was run, find and handle those copies separately. A text editor, shell history, log, backup job or temporary export may have created one.
7. Clean up the test directory
After checking the examples, remove the now-empty temporary directory. This final command changes only the directory created in step 2:
$ rmdir "$work_dir"
$ test ! -e "$work_dir" && echo 'test directory removed'
test directory removed
If rmdir reports that the directory is not empty, list it before taking any further action. Do not replace it with a recursive deletion command until you have inspected every remaining name.
Done means
- You confirmed the installed GNU coreutils version and the exact target path.
- You know that the default is three overwrite iterations and no removal.
- You used
--zeroonly when hiding the overwrite pattern was useful. - You used
--removeonly after an explicit path check and accepted that it has no undo. - You distinguished a successful local overwrite from a guarantee about backups, snapshots or flash media.
- You verified the disposable example and removed its temporary directory.