Slashdot Mirror


Wiping a Smartphone Still Leaves Data Behind

KindMind writes "To probably no one's surprise, wiping a smartphone by standard methods doesn't get all the data erased. From an article at Wired: 'Problem is, even if you do everything right, there can still be lots of personal data left behind. Simply restoring a phone to its factory settings won't completely clear it of data. Even if you use the built-in tools to wipe it, when you go to sell your phone on Craigslist you may be selling all sorts of things along with it that are far more valuable — your name, birth date, Social Security number and home address, for example. ... [On a wiped iPhone 3G, mobile forensics specialist Lee Reiber] found a large amount of deleted personal data that he recovered because it had not been overwritten. He was able to find hundreds of phone numbers from a contacts database. Worse, he found a list of nearly every Wi-Fi and cellular access point the phone had ever come across — 68,390 Wi-Fi points and 61,202 cell sites. (This was the same location data tracking that landed Apple in a privacy flap a few years ago, and caused it to change its collection methods.) Even if the phone had never connected to any of the Wi-Fi access points, iOS was still logging them, and Reiber was able to grab them and piece together a trail of where the phone had been turned on.'"

3 of 155 comments (clear)

  1. This is old news, and no longer correct for iPhone by kallisti · · Score: 5, Informative

    The key line: "On a wiped iPhone 3G"

    Starting with the iPhone3GS, iOS encrypts everything with a random AES256 key. When you say to wipe the device, it erases that key rendering everything else unusable. This is mentioned in the article, but downplayed. It's been a long time since you could even buy an iPhone 3G, so it seems alarmist to bring it up now.

    http://blog.itsecurityexpert.co.uk/2011/10/securely-wiping-your-personal-data-from.html

  2. A contrived test: old phone, old operating system? by perpenso · · Score: 5, Informative

    Did the previous owner use the "erase all content and settings" feature of that phone? Or just restore it. That would have been using the built in tool and would have overwrote the data. http://support.apple.com/kb/ht2110

    The author used the last iPhone (3G) running the last iOS version (4) that would exhibit such behavior. It seems a contrived test.

    An upgrade to iOS 5 would fix the problem on the 3G. On newer phones the encryption key needed to access the data is destroyed, so the problem never would have occurred.

  3. Re:doesn't sound like built in wipe was used by icebike · · Score: 5, Informative

    When you do read TFA you find out this:

    Take the two Motorola devices(android). Both were wiped, and neither had much to speak of stored in their built-in memory, just some application data with no personally identifiable fingerprints.

    But one user left his micro SD card in the phone. Although the contents of the card were deleted, the card had not been formatted. This, apparently, meant the files were recoverable. And because Android cached application data to this SD card, Reiber could recover e-mail data as well — enough that we could positively identify the phone’s owner via his e-mail address. But the real treasure trove was the photos and documents. The photos still had metadata, including the dates, times and locations in which the photos were shot. And while the documents were benign, if the phone’s owner had stored sensitive information on his phone — think a tax return with a Social Security number, or a .pdf bank statement — we would have had that, too.

    So other than USER Stupidity of leaving his SD card in the device he recycled, this once again is an Apple story pinned to a model long out of production dating to a problem long since fixed by Apple.

    Not that it changes much, if the police who buy these forensic tools happen to get your phone they pretty much have everything they need to know everything about you. How does "AccessData" get around violations of the DMCA by building tools to circumvent encryption?

    --
    Sig Battery depleted. Reverting to safe mode.