Android Factory Data Reset Doesn't Wipe Data Completely; Login Keys And Data Intact

biostud

Lifer
Feb 27, 2003
19,847
6,937
136
Researchers at the Cambridge University recently discovered that the factory data reset feature on Android doesn't work as well as advertised. If you thought that simply hitting the factory data reset button on your Android device did the job, you're about to find your worst fears come true.

The researchers found that even with full-disk encryption enabled, they were able to recover the file that stored encryption keys even after performing a factory reset. They then proceeded to recover the "crypto footer", using which they decrypted the device using a brute-force method to find the user's PIN.


http://www.nextpowerup.com/news/212...e-data-completely-login-keys-and-data-intact/
 

KeithP

Diamond Member
Jun 15, 2000
5,664
202
106
The research experiment was conducted on 2nd-hand Android devices bought through eBay, running OSes between Android 2.2 Froyo and Android 4.3 Jelly Bean.

It seems really odd to me that they didn't try to acquire any 4.4 or 5.0 phones to see if they have the same problem.

-KeithP
 

Brian Stirling

Diamond Member
Feb 7, 2010
3,964
2
0
Flash storage is an issue and I think we need a better storage wipe feature to more completely and reliably wipe the storage.


Brian