Linux shred Command: Overwrite File Data and Understand Its Limits

This guide explains how to Linux shred overwrites file data, which options control its passes and removal, and why SSDs, snapshots, backups, and modern filesystems limit its guarantees. It focuses on practical Linux usage, predictable automation, and the cases where a seemingly small path or option mistake can change the result.

The examples use GNU Coreutils behavior. Check shred --help, man shred, and your distribution documentation when portability or a version-specific option matters.

What Is the shred Command?

shred repeatedly writes patterns over a file or device to make previous data harder to recover. Its assumptions do not hold reliably on SSDs, copy-on-write filesystems, snapshots, backups, RAID layers, or storage that remaps blocks, so it cannot promise removal of every copy.

Basic Syntax

shred [OPTION]... FILE...

Quote paths that contain spaces. When supported, place -- before operands that begin with a hyphen so they are not interpreted as options.

Basic shred Usage

Overwrite a file

The default operation overwrites data but leaves the directory entry. Test behavior on disposable data before using it on an important path.

shred secret.txt

Overwrite and remove the file

Add -u to remove the file after the overwrite passes. This still does not erase copies in other storage layers.

shred -u secret.txt

Display progress

Use -v for progress information when processing a large file or a carefully identified device.

shred -v -n 3 disk-image.raw

Distinguishing between completion messages and actual deletion guarantees

shred shows progress depending on the options, but finishing without errors does not guarantee that all copies on physical storage media have been erased. The following applies only to test files created directly.

printf 'demo\n' > disposable-demo.txt
shred -u disposable-demo.txt
test ! -e disposable-demo.txt
echo $?

Example output 0 only confirms that the file name has disappeared. Data remaining on SSDs, snapshots, journaling filesystems, or backups must be considered separately.

Key Options

Option Purpose
-n N Set the number of random-data passes.
-u Remove the file after overwriting.
-z Add a final zero-filled pass.
-v Report progress.
-s SIZE Overwrite only the specified byte count.
-x Do not round the file up to a full block.
-f Change permissions if needed to allow writing.
--random-source=FILE Choose the random-byte source.

Long options often make reviewed scripts easier to understand. When a script must run on non-GNU systems, verify every non-POSIX option on the target platform.

Practical Examples

Use a limited pass count

More passes increase time, but modern storage behavior matters more than a large pass count. Define the storage model and threat before choosing this tool.

shred -v -n 1 -z -u confidential.bin

Identify a block device first

An incorrect device path can destroy another disk. Unmount the target and confirm size, model, serial number, and mount relationships using more than one check.

lsblk -o NAME,SIZE,MODEL,SERIAL,FSTYPE,MOUNTPOINTS
findmnt

Consider cryptographic erasure

When full-disk encryption was used from the start, securely destroying the encryption key can be an important disposal method. Also consider vendor secure erase, organizational policy, and physical destruction requirements.

cryptsetup status encrypted-volume

shred and Related Commands

Command or method Primary role Best fit
rm Remove a filename and release space Ordinary deletion
shred Attempt repeated writes to the same logical data Limited compatible storage cases
Device secure erase Use firmware-level erase or key destruction Supported SSD or NVMe disposal
Physical destruction Destroy the storage medium High-assurance regulated disposal

Important Cautions

SSD writes may reach different physical cells

Wear leveling and spare blocks mean that rewriting a logical address may not overwrite the cell that held the old data.

Other filesystem copies can remain

Journals, snapshots, copy-on-write extents, RAID, synchronization, and backups may retain data beyond the named file.

A device path mistake is destructive

Shredding a block device can erase an entire filesystem. Confirm identity, mount state, backups, and authorization before proceeding.

FAQ

Does shred -u guarantee that recovery is impossible?

No. Storage remapping, filesystems, snapshots, and backups can retain other copies.

Should I shred individual files on an SSD?

Individual overwrites are unreliable because of wear leveling. Prefer encryption and a supported device sanitization procedure.

Does -z make deletion more secure?

It adds a final zero pass but does not remove copies elsewhere or guarantee sanitization.

Should ordinary deletion use rm or shred?

Use rm for ordinary deletion. Use shred only after evaluating the storage technology and threat model.

Related Resources

More in This Category
Linux bzip2 Command: Compress a File in bzip2 Format

Linux bzip2 Command: Compress a File in bzip2 Format

Learn how to compress a File in bzip2 Format with the Linux bzip2 command, including practical examples, key options, and important precautions.

Linux sort Command: Sort Text Lines

Linux sort Command: Sort Text Lines

Learn how to sort text lines with the Linux sort command, including practical examples, key options, and important precautions.

Linux kill Command: Send a Signal to a Process ID

Linux kill Command: Send a Signal to a Process ID

Learn how to send a Signal to a Process ID with the Linux kill command, including practical examples, key options, and important precautions.

Linux nc Command: Test TCP and UDP Connections

Linux nc Command: Test TCP and UDP Connections

Learn how to test TCP and UDP Connections with the Linux nc command, including practical examples, key options, and important precautions.

Linux tee Command: Display and Save Pipeline Output

Linux tee Command: Display and Save Pipeline Output

Learn how to display and Save Pipeline Output with the Linux tee command, including practical examples, key options, and important precautions.

Linux sudo Command: Run Commands with Elevated or Another User's Privileges

Linux sudo Command: Run Commands with Elevated or Another User's Privileges

Learn how to use the Linux sudo command to run approved commands with elevated privileges or as another user, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux mkdir Command: Create Directories and Parent Paths

Linux mkdir Command: Create Directories and Parent Paths

Learn how to create directories with Linux mkdir, build missing parent paths, set permissions, understand umask behavior, and verify results in scripts.

Linux gunzip Command: Decompress gzip Files

Linux gunzip Command: Decompress gzip Files

Learn how to decompress gzip Files with the Linux gunzip command, including practical examples, key options, and important precautions.

Linux lsblk Command: Inspect Disks, Partitions, and Mounts

Linux lsblk Command: Inspect Disks, Partitions, and Mounts

Learn how to inspect Disks, Partitions, and Mounts with the Linux lsblk command, including practical examples, key options, and important precautions.

Linux fdisk Command: Inspect and Edit Disk Partitions

Linux fdisk Command: Inspect and Edit Disk Partitions

Learn how to inspect and Edit Disk Partitions with the Linux fdisk command, including practical examples, key options, and important precautions.