Two-Thirds of Second-Hand Memory Cards Contain Data From Previous Owners (bleepingcomputer.com)
Catalin Cimpanu, writing for BleepingComputer: A recent study conducted by academics from the University of Hertfordshire in the UK has revealed that almost two-thirds of second-hand memory cards still contain remnants of personal data from previous owners. For their study, researchers analyzed 100 second-hand SD and micro SD memory cards purchased from eBay, conventional auctions, second-hand shops, and other sources over a four-month period. All in all, researchers say the memory cards they recovered were previously used in smartphones and tablets, but some cards were also used cameras, SatNav systems, and even drones. The research team says the analysis process consisted of creating a bit-by-bit image of the card and then using freely available software to see if they could recover any data from the card. Their efforts were successful and worrisome at the same time, as the team says it managed to recover data from the memory cards, including intimate photos, selfies, passport copies, contact lists, navigation files, pornography, resumes, browsing history, identification numbers, and other personal documents.
...that it's ONLY 2/3rds. Who remembers / bothers to erase that data, anyway? For my cameras and GPSs, I doubt that I'd bother. Info available is immensely non-useful to anyone else. A PC memory I would erase, and spend time writing 1's, 0's, and then random #'s to it, but the other hardware I really wouldn't care about.
And who is SELLING these memory cards, anyway? That's not how you get rid of 'em. You get rid of 'em by losing them. Everybody knows that.
I always wonder how these kinds of "studies" pass for academics. Who proposes such a study and then who approves it? Are these the kind of studies Universities should be pursuing?
That's the first damn thing on my mind whenever such a device is leaving my control.
WTF is wrong with you people? Bell curve, that's what.
Who the heck sells a memory card? They are as cheap as a McDonald's burger, and by the time you exit the store there are already larger ones on sale.
My first program:
Hell Segmentation fault
The only problem is that taxpayers are funding it.
There should be a separation of Education and State.
My secret past-time is buying up old memory cards, finding the goodies, and then blackmailing the former owners, committing industrial espionage, and generally being amused. Now you all have gone and ruined it by warning everyone!
Oh, wait, people are still lazy? Don't care about security? Wouldn't know how to wipe a card even if they did care? Well, then, I guess I'm all set.
disclaimer: this post is in jest
Or it didn't happen
It must be. Or Cimpanu hadda write SOMETHING to get his check this week...
I could not find the link to the actual report in the summary or the linked article (unless I missed it). But some googling located it.
https://cdn.comparitech.com/static/docs/survey-data-remaining-second-hand-memory-cards-uk.pdf
It is linked in the story of the company that commissioned the research in the first place: https://www.comparitech.com/blog/vpn-privacy/secondhand-memory-card-study/
Contain genetic material from previous owners.
You are all cows. Cows say moo. MOOOOOOO! MOOOOOOO! Moo cows MOOOOOO! Moo say the cows. YOU DBAN-NEEDING COWS!!
See subject: "Imitation = sincerest form of flattery" PROVING you WISH you were ME but poor imitation = you.
* I don't post on my work in topics that don't fit it (unless you of "moron kind" bring it up 1st), hence, you giving yourself away you're impersonating me...
APK
P.S.=> What are you trying (& failing) to accomplish? Trying to "make me look bad"?? I have to ask as it's EXTREMELY DIFFICULT for me to "think like 'your kind'" (no-mind do-NOTHING "ne'er-do-wells" that can't think, lol) to even TRY to understand your "mental processes" (none obviously that are up to any good)... apk
but alas SD cards don't seem to support it.
Why is this so "surprising" - most people don't understand how a FAT file system works when you delete something, fuck, most PROGRAMMERS don't understand how FAT works, so why is it surprising most people think that simply deleting files is the same as erasing the card? Some might go the extra mile and format it, but all that does is reset the FAT table.
P.S. The only reason I know so much about FAT is I tried to write a boot sector virus in assembler in school. Yeah, it didn't work as expected and I ended up erasing my own boot sector.
There are three kinds of falsehood: the first is a 'fib,' the second is a downright lie, and the third is statistics.
Why is it shocking that you can recover unsecured data from a used memory card again? Especially when you're using recovery software to do the job? This one falls into the "no duh," category.
This signature has Super Cow Powers
It's true. Smart people tend to be kinky.
See subject: "Imitation = sincerest form of flattery" PROVING you WISH you were ME & poor imitation = you.
* I don't post on my work in topics that don't fit it (unless you of "moron kind" bring it up 1st)
OR
Harassing others that didn't harass me (most of all, 1st - Megol didn't afaik @ least recently).
(Hence, you give yourself away you're impersonating me!)
APK
P.S.=> What are you trying (& failing) to accomplish? Trying to "make me look bad"?? I have to ask as it's EXTREMELY DIFFICULT for me to "think like 'your kind'" (no-mind do-NOTHING "ne'er-do-wells" that can't think, lol) to even TRY to understand your "mental processes" (none obviously that are up to any good)... apk
See subject & how YOU make sockpuppets to stalk & troll me https://slashdot.org/comments....
Sending me threatening postcards https://slashdot.org/comments....
Your "watch your mailbox" THREAT & you "going postal" (pun intended) that way w/ MORE 'warnings' from you (wow).
Take your meds mentalcase https://slashdot.org/comments.... & You're a druggie too https://slashdot.org/comments....
* You're a butthurt loon freak, plain & simple - you did it to yourself, loser... see below for proof.
APK
P.S.=> Still trying to live down how I shot you to pieces in the art & science of computing Mr. Butthurt https://slashdot.org/comments.... ?
How about proving hosts & my program that builds them are useless too https://slashdot.org/comments.... ? ... apk
The problem is that we keep using concept, that simply does not exist for computers: Deletion.
Computers only know reading and writing. "Deletion" is merely faked via overwriting the pointer to the data and writing "unused" into the free space table... so forgetting where it was put. While it's of course still there.
We havr only ourselves to blame, for using that word when we write software.
"Move" needs to go too. ... and the different rules that apply as a result. (Like no-cost duplication and hence infinite abundance and hence worthlessness.)
And maybe, just maybe, some day, people will know that ownership is a concept not applicable to information, due to the fundamental difference between physical matter/energy, and information, which is merely the way that matter is arranged.
Unlike magnetic media, it is very difficult to wipe an SD clean. The typical overwrite process that works well on magnetic media (hard drives) won't work on SD cards because of something called 'wear leveling'. The new data is actually put somewhere else to keep from overusing individual segments.
https://en.wikipedia.org/wiki/Wear_leveling
Also, given that flash cards have a limited number of erase/write cycles, doing a proper erase would reduce the lifespan of the card significantly (at least compared to a hard drive).
Support Right To Repair Legislation.
Any software available that Just Worksâ, or some easy steps that can be taken on the command line?
Aren't operating systems supposed to trim a card if you quick-format it, so that you could put a single zero-filled file occupying the whole card, and then quick-formatting to effectively wipe and trim?
The number of "erase/write cycles" is pretty large.
On top of that, we're talking about deleting data from devices that end up on the market; there's no way 2/3 devices are stolen. That's ONE erase/write cyce; there's no need for multiple rounds, or even for writing random data. Just zero that shit out, or issue an "erase everything" command if the device supports it.
Arstechnica = losers who stalked me (as you do now anonymously unidentifiably) to NTCompatible.com & Windows IT Pro magazine forums to their public dismay in Jeremy Reimer & Jay Little + Jarrett DeAngelis (who posts here on /. until I drove his ass off too) when their websites were REMOVED by their hosting providers in Shaw Canada & CrystalTech (for both email harassing me caught on a tracking ticket + stalking me & posting lies about me on them AFTER I destroyed them both PUBLICLY @ Windows IT Pro on Exchange Servers memory being freed UNHALTING them (which tells you Exchange is HEAVILY POINTER ORIENTED linked list driven, which leads to memory fragmentation that CAN halt a serverware)).
Jay Little the "self-proclaimed 'EXCHANGE EXPERT'" HAD TO CONCEDE IT from MICROSOFT'S OWN DOCUMENTATION proving it FOR me there (where they as usual stalked me AS YOU ARE NOW AS YOU'RE OBVIOUSLY ONE OF THOSE IDIOTS TOO ) & they can't "ban me" ANYMORE than I can be "banned" here on /. - as nothing stops ME, but me!
I just left their site after a VERY BRIEF visit in 2001 (finding they are UNDEREDUCATED DO-NOTHING LAZY WANNABE "Fake it Till you Make It" types - shams & "ne'er-do-wells").
Lastly - I own my own home (decade++ now) I'm quite proud of (do you? PROVE it)...
APK
P.S.=> They also EDITED posts of mine & impersonated me (everyone KNOWS how lame & weak they are worldwide) - put it THIS way: Ask PeterB/Dr.Pizza (Peter Bright) how I ran them off their OWN IRC server & cleared out their 'scheming nest' there in minutes, lol (ole' GOITERMAN frogchin will like the memory, lol (I do))... apk
This is nothing new. Several years ago, a local electronics junk store got in a bunch of Blackberries of various models (probably a company going out of business) and were selling them for something like $5 apiece. Daughter was a major texter at the time, and liked the retro look and superior keyboard, so we bought several different models so she could switch between them as her mood took her.
We discovered that all but one of them had not been wiped. Appointments, phone numbers, baby pictures, still intact. No sexting, fortunately, but probably only because these phones had been corporate owned. (Which isn't a guarantee, now that I think about it. Maybe we got lucky.) [1]
People either don't understand or don't care about wiping their data. Even the ones that do make an effort often don't understand that deleting the files just deletes the directory entries, not the data itself. Utilities that truly wipe the data from cards (and drives and anything else that potentially holds personal data) are known to tech geeks and privacy geeks but not to Fred and Ethyl User.
[1] Thinking further about it, the last time I "participated" in a layoff, a bunch of us were called to a meeting and told to surrender our badges and phones immediately. I have no idea whether whomever was in charge wiped the phones. Or just sold them on ebay.
Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
See subject & RoTfLmAo "reminiscing" seeing "'great' (not) ARSEHOLETECHNICA" routed by "yours truly" https://it.slashdot.org/commen... on SEVERAL FRONTS, lol!
* Hohohohohohoho....
APK
P.S.=> ... lol, + you're STILL "butthurt" after such MASSIVE worldwide-SCALE fail vs. me too... apk
That links hasn't worked in 4 years.
APK is mad that someone is doing a good job of impersonating him and it makes him look bad. Unfortunately he does not understand that he just looks bad all the time. The reason he has such a hard time thinking like our kind is that he can only grasp simplistic ineffective pseudo security solutions that became obsolete in about 1992. APK, have you figured out what false negatives are yet or how all your efforts can be defeated with less than a dozen lines of code?
Maybe APK can whine about being downmodded, or call everyone ne'er-do-wells. Instead he could try to demand that people prove they can do work equivalent to an intro to some programming language course. Better yet he could go off on one of his antisemitic rants since one of those hasn't shown up lately. In reality he will probably just rage out against Zontar The Mindless, Khyber, Coren22, Ol Olsoc, arth1, Brockmire, or Whipslash for a few days.
--
Stupid people are like glow sticks. I want to snap them and shake the shit out of them until the light comes on.
"Imitation=sincerest form of flattery" you ADMIT now PROVING u WISH u were ME & poor imitation = u. I don't post on hosts in topics that don't fit it (unless you of "moron kind" bring it up 1st)
(Hence, you give yourself away you're impersonating me!)
* I don't know WHO u are but I know WHAT "your kind" & you are - see subject JEALOUS "Lil' Jowie" (you of the "ne'er-do-well" DO NOTHING low swine online).
APK
P.S.=> What are you trying (& failing) to accomplish? Trying to "make me look bad"?? I have to ask as it's EXTREMELY DIFFICULT for me to "think like 'your kind'" (no-mind do-NOTHING "ne'er-do-wells" that can't think, lol) to even TRY to understand your "mental processes" (none obviously that are up to any good)... apk
It would cost a bit more but maybe it's time for camera-cards, USB sticks, and the like to routinely use strong encryption with a non-secret-by-default key stored on a the medium itself.
To the end user, it would "just work" except there would be a "quick erase" mode that would scramble the key then either do a normal operating-system-level "long" or "quick" format using the new key.
Even a "quick format" by the OS would be good enough since the left-over data would be encrypted with a now-deleted key.
Now, the key itself would need to be stored on a different part of the device than the rest, one that does not have "wear leveling" applied to it.
It would also require a device that had its own intelligence, but that's a very low bar these days.
As an option, manufacturers could have a volatile and non-volatile copy of the key and allow the host device to read and write the volatile copy (with or without write-back to the non-volatile copy), allowing the device to behave both as a "normal" memory stick or camera card or, optionally, as an "encrypted" data stick or camera card where the host device held the key when power was not supplied to the device.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
Time to see you SQUIRM "lil' JOWIE" (lol) YES or NO here "JOWIE" (hahaha) https://it.slashdot.org/commen...
* Yes, I know that others WILL agree it's FUN to see "Jealous JOWIES" that STALK ME by UNIDENTIFIABLE fake name posts SQUIRM!
(Like the WORMS you are beneath MY BOOT!)
Toxic?
Freak - get a clue - you're f'ing STALKING me HIDING in fear of me too behind UNIDENTIFIABLE fake name posts (worms like you HAVE to fear guys like me & yes, that IS fear, you hiding).
APK
P.S.=> Every SINGLE time you give me SUCH A LAUGH as I box you into THIS VERY CORNER & you SQUIRM, worm, hahahaha... apk
It's a tell: no bf/gf
Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017
Your premise that hostfiles are a good way to deal with advertising and malvertising is quite valid - by JazzLad April 20, 2016
his hosts program is actually pretty good by xenotransplant August 10 2015
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg September 25 2015
I like your host file system by Karmashock September 09 2015
that APK guy, I use his host file by rogoshen1 Tuesday March 03, 2015
I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017
* Best part = Linux 64-bit model's faster/more efficient (2x work in 1/2 the time)
APK
P.S.=> See subject & ANSWER that question w/ proof YOU have you JEALOUS "Lil' Jowie" (lol) puny "ne'er-do-well DO-NOTHING zero... apk
Fill the card with goatse then delete and sell the card on Ebay.
Are selling the cards you forget to take out!
So sad.
Some enterprise-grade copiers effectively wipe all copies other than those that are intentionally stored in the copier's "library" during boot-up.
Presumably they do this by encrypting the files and either wiping the keys or never storing them on-disk in the first place.