AfterDawn: Tech news

Android reset flaw affects 500 million+ devices

Written by James Delahunty @ 24 May 2015 5:13 User comments (3)

Android reset flaw affects 500 million+ devices The factory reset option in the Android mobile operating system may not be as reliable as you'd think, according to new research.
Using the factory reset is common when giving away / selling an old smartphone or tablet, clearing out personal information so the new owner can start afresh, and the previous owner can rest assured that all personal information is wiped.

But.. what if the data is not wiped properly? A study from Cambridge University has raised doubts about the reliability of this function across Android hardware. It focused on tests performed on 21 devices from five manufacturers, running different versions of the popular operating system.

Unfortunately, the researchers could successfully recover partial data after the factory reset was carried out. Even with Full Disk Encryption, some data recovery was still achieved.

In 80 percent of the devices, the researchers could recover the master token required to access Google services. They could also recover login information for other services, as well as images, videos, contacts and so on.



There are a variety of reasons for the problem, with one being manufacturers failing to include adequate drivers that would be needed to properly erase the internal memory, or removable flash memory of a device.

This flaw could affect more than half a billion devices.


Sources and Recommended Reading:
Security Analysis of Android Factory Resets (PDF): www.cl.cam.ac.uk

Tags: Android
Previous Next  

3 user comments

124.5.2015 22:52

Here you are dealing with feasibility. Now how many recipients of such devices would have the knowledge or resources to retrieve such data? Secondly how many people who store critical data on their Android devices would actually give away their device?

There are some very basic steps one can take to prevent this. Like on phones with "Redial last dialed number". After one finished a call he \/she only needs to dial some fake numbers a few times. On Android device just create a new email id that is not linked to your phone number and pass on that information to the recipient / buyer.

226.5.2015 01:26

Yet another reason why I have advocated against Android for a couple years now. It's slow(over time) and insecure ........PERIOD

Android blows chunks!

This message has been edited since its posting. Latest edit was made on 26 May 2015 @ 1:26

326.5.2015 13:47

Originally posted by hearme0:
Yet another reason why I have advocated against Android for a couple years now. It's slow(over time) and insecure ........PERIOD

Android blows chunks!

Fine. Now, tell us of the alternative that YOU endorse.

Comments have been disabled for this article.

Latest news

VLC hits milestone: over 5 billion downloads VLC hits milestone: over 5 billion downloads (16 Mar 2024 4:31)
VLC Media Player, the versatile video-software powerhouse, has achieved a remarkable feat: it has been downloaded over 5 billion times.
2 user comments
Sideloading apps to Android gets easier, as Google settles its lawsuit Sideloading apps to Android gets easier, as Google settles its lawsuit (19 Dec 2023 11:09)
Google settled its lawsuit in September 2023, and one of the settlement terms was that the way applications are installed on Android from outside the Google Play Store must become simpler. In the future, installing APK files will be easier.
8 user comments
Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets Roomba Combo j7+ review - Clever trick allows robot vacuum finally to tackle home with rugs and carpets (06 Jun 2023 9:19)
Roomba Combo j7+ is the very first Roomba model to combine robot vacuum with mopping features. And Roomba Combo j7+ does all that with a very clever trick, which tackles the problem with mopping and carpets. But is it any good? We found out.
Neato, the robot vacuum company, ends its operations Neato, the robot vacuum company, ends its operations (02 May 2023 3:38)
Neato Robotics has ceased its operations. American robot vacuum pioneer founded in 2005 has finally called it quits and company will cease its operations and sales. Only a skeleton crew will remain who will keep the servers running until 2028.
5 user comments
How to Send Messages to Yourself on WhatsApp How to Send Messages to Yourself on WhatsApp (20 Mar 2023 1:25)
The world's most popular messaging platform, Meta-owned WhatsApp has enabled sending messages to yourself. While at first, this might seem like an odd feature, it can be very useful in a lot of situations. ....
18 user comments

News archive