Call us — 01223 655015
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Trust, Practice & Honest Limits · Say No Before Charging

An Erase That Discards the Encryption Key Cannot Be Reversed by Anyone

This enquiry asks a question and deserves a direct answer rather than an assessment. A factory reset performed deliberately on a laptop, followed by the realisation that "my photos were not backed up as I thought", and the question of "whether there was any point in performing a data recovery." On this generation of machine there is not, and saying so now costs him nothing while an assessment would cost him time.

MediaLaptop of a generation with hardware-backed storage encryption — factory erase performed deliberately; encryption key discarded as part of that operation
Reported situationFactory erase performed on a laptop by the owner · operation completed as intended · photographic content subsequently found not to have been backed up · possibility of recovery queried before any work was commissioned
Fault classCryptographic erase completed — content mathematically inaccessible with the key destroyed; no device fault present and no recovery route available
Equipment usedErase mechanism established before any assessment was proposed · no charge raised for a case with no viable route · alternative sources of the same photographs identified for the owner · position stated in writing rather than deferred to an assessment

The decode: what the erase did, and where else to look

Why an erase on these machines is instantaneous: it does not overwrite anything. Content is stored encrypted at all times, so erasing means discarding the key rather than clearing the memory.

Why that design exists: speed and thoroughness. Wiping a large drive properly takes hours; discarding a key takes moments and is more complete, which is why it became standard.

What it means for recovery: the content is still physically present and permanently unreadable. Every byte remains in the memory as encrypted data that nothing can interpret.

Why no technique changes that: the key was not stored anywhere else. It was held in a hardware component and destroyed by the operation, and there is nothing to derive it from.

Why an assessment would not alter the answer: nothing about this device is faulty. The machine works and did exactly what it was asked to do, so there is nothing to diagnose.

Why saying so plainly is the right response: he asked whether there is any point. Charging for an assessment that ends here would be taking money to confirm what is already known.

What is genuinely worth pursuing instead, and it may be a great deal: the photographs may exist elsewhere. Content synchronised to an account before the erase remains in the account regardless of what happened to the machine.

Why that is worth checking even though he believed it was not backed up: his belief was wrong once already. Partial synchronisation is common, and signing in from a browser costs nothing to establish.

What else to look at: any machine the laptop was backed up to, any external drive used with it, and photographs shared with others. Messages and shared albums frequently hold copies of exactly the material people most regret.

What the durable lesson is, stated once: verify a backup before erasing, by opening files from it rather than by checking that it exists. The belief that something is backed up is what makes an erase feel safe.

On the bench

The erase mechanism was established before any assessment was proposed — storage on these machines being encrypted at all times so that a factory erase discards the key rather than overwriting content, which is why the operation is instantaneous. Content remains physically present and permanently uninterpretable, the key having been held in a hardware component and destroyed. No device fault exists to diagnose. No charge was raised for a case with no viable route.

The outcome

The erase mechanism established before any assessment was proposed, no charge raised where no route exists, and alternative sources identified. Free assessment and one fixed written figure including VAT where work is possible — and here it is not, which is said now rather than after a fee. The decode: the erase discarded the key rather than the content. Every byte is still there and permanently unreadable — so check the account, any backup drive, and anyone you shared photographs with.

After a factory erase you now regret

Don't pay for an assessment on the machine — on this generation an erase discards the encryption key rather than overwriting anything, so the content remains physically present and permanently unreadable, and there's no fault to diagnose. Look elsewhere instead, and check even though you believe it wasn't backed up: sign in to the associated account from a browser, since partial synchronisation is common; check any drive or machine you backed up to; and look through messages and shared albums, which often hold exactly the photographs people most regret.

Erased a machine and then realised?
Check the account first — call Cambridge Data Recovery on 01223 655015; erase mechanism established before any assessment, no charge where no route exists, alternative sources identified for you.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.