Journalism of Courage
Advertisement
Premium

Factory-reset on Android of no use, data can still be retrieved: Cambridge study

A new Cambridge study has found that user data is retrievable from second-hand Android devices

2 min read
Akhilesh Yadav, 2017 assembly polls, mobile app, samajwadi party mobile app, Samajwadi Party, lucknow news, indian express

Are you planning to junk your smartphone in the second-hand device market for the sake of a new one? Beware as your data can be retrieved from your old phone.

A new Cambridge study has found that user data is retrievable from second-hand Android devices that have been wiped via a factory reset, techweekeurope.co.uk reported. Such data can be recovered even from handsets protected by full-disk encryption, the researchers said.

Most Android handsets offer no easily accessible way of deleting user data, including access tokens, messages, images and other content, the study said.

Experts have been airing their concerns for some time now that the smartphones are extraordinarily difficult to clear of user data.

The study examined 21 second-hand devices running Android versions from five manufacturers that had been wiped using the operating system’s built-in factory reset feature.

But the problems also exist with third-party data deletion applications, such as those offered by antivirus vendors, the researchers said.

The team was able to recover data including multimedia files and login credentials from wiped phones, and many of the handsets yielded the master token used to access Google account data, such as Gmail and Google Calendar.

Story continues below this ad

The problem results from multiple issues, including the inherent difficulty of fully deleting data from the flash memory used in smartphones, something due to the physical nature of such memory chips, according to the research.

Other issues include vendors’ failure to include necessary drivers or failures introduced by their modifications of Android for individual devices.

As a proof-of-concept, the researchers recovered the master token in a device and found that after reboot, it successfully re-synchronised contacts, emails and other data.

The master token, used to access Google accounts, was found to be retrievable in 80 percent of the devices that had a flawed factory reset mechanism.

Story continues below this ad

Devices protected with encryption can still be accessed, because the file storing the decryption key is not erased, making it accessible to cracking, the study said.

Technology on smartphone reviews, in-depth reports on privacy and security, AI, and more. We aim to simplify the most complex developments and make them succinct and accessible for tech enthusiasts and all readers. Stay updated with our daily news stories, monthly gadget roundups, and special reports and features that explore the vast possibilities of AI, consumer tech, quantum computing, etc.on smartphone reviews, in-depth reports on privacy and security, AI, and more. We aim to simplify the most complex developments and make them succinct and accessible for tech enthusiasts and all readers. Stay updated with our daily news stories, monthly gadget roundups, and special reports and features that explore the vast possibilities of AI, consumer tech, quantum computing, etc.

Tags:
  • Android
Edition
Install the Express App for
a better experience
Featured
Trending Topics
News
Multimedia
Follow Us
Trump’s gamble in IranImplications for the US, its allies, and a weakened Tehran
X