Privacy of 500 million Android users at risk: Data on phones can’t be wiped

“Up to 500 million Andriod users who use or have used Android software could be at risk from having personal information shared after tests revealed it’s impossible to clear data from many devices,” James Dunn reports for The Daily Mail. “A report by Cambridge University showed that private text messages, images, videos and email details can be recovered, even after a total wipe – or factory reset – has been done. It means that people who have given away, sold or lost phones are now at risk from having their personal details and any private or sensitive information in messages or emails seen by whoever now has their old phone.”

“They could also access third party applications. Many phone users store financial information and do their banking through some of the most popular apps on tablets and phones such as Halifax and Nat West,” Dunn reports. “Researchers also recovered Google authentication tokens, allowing to access services which are synced across a number of devices, including Gmail, YouTube, and any images or videos stored using Google cloud services.”

“They also discovered that up to 630million phones may not wipe internal SD cards, which often store most of the images and videos on a phone,” Dunn reports. “Speaking to Ars Technica, Computer Scientist Kenn White said: ‘It’s a staggering number of devices out there that are exposed, and it’s not just somebody’s Gmail password. It’s images, photos, text, chat. It’s all these things that are private that you think if you’ve reset it you’ve reset it.'”

Read more in the full article here.

MacDailyNews Take: “Open.”

Now to be fair, this is only because Android is an inferior product peddled to tech illiterates who do not value their privacy and/or who are unable to recognize a half-assed knockoff from the revolutionary original.

Android is a BlackBerry clone that was hastily rejiggered to mimic iPhone at the last minute. Obviously, mistakes were made.

So, the Android rush-job is a security nightmare. It’s fragmented. It’s too many cooks in the kitchen. It’s crap-by-committee junk.

And anyone who rewards blatant thieves by settling for Android deserves their fate.

  1. Early versions of the iPhone didn’t encrypt storage. I can’t comprehend that current Android phones don’t have a secure envelope. Recover keys? That’s ridiculous. There should be a wipeable secure enclave for the key that accesses storage. This should have military wipe, unrecoverable keys…

    Really bad design. Don’t ever sell an Android, used. You now have to destroy them.. Preferably in acid or fire.

  2. It’s an indication that Android device makers ONLY care about the immediate sale. Can’t upgrade to the latest OS version and built-in software; we don’t care. Having problems with malware; we don’t care. And can’t fully wipe personal data from device before selling it; we don’t care…

    They don’t care, because Android devices are sold based on the current “best deal.” And that’s an immediate sale consideration, not long term support consideration. There’s “no money” for them in thinking about the existing customer AFTER the sale.

    In contrast, Apple can only thrive with customer loyalty. There are no “best deals,” only predictable and consistent deals. iPhone customers MUST return later to buy another one, or Apple ultimately fails. Therefore, Apple treats its customers as ONGOING customers, to promote loyalty.

    1. Sipping a delicious adult beverage in Apple’s Walled Garden is soooo relaxing.
      – Far better than drinking rainwater from a hoof print in Android’s Wild West.

    1. This is exactly right. Take any negative story about Samsung or Android and change it to Apple or iOS, and it’d be “Apple is Doomed!” all over.

  3. I don’t know if I believe that there are actually 500 million actual users of Android droppings, but even if there are, I don’t think a privacy breach for that crowd is any big deal since people like that don’t have much of a life to begin with.

  4. Those in the health care industry that deployed android based handsets and tablets may have the most at risk. I have no idea how their apps are written, or how must data is ever resident on the device but, I do know that much HIPAA protected data is collected using handsets and tablets.

    1. Except that the medical system’s “risk” is with all of OUR data, so even those of us who try to secure our lives with better quality products get screwed over by idiots going cheap!

  5. Expect to now see a small market for proper wiping Apps appear in Google Play and Amazon store.. Half the effort of solving a problem is identifying it first..

    So if you read between the lines, Android devices that use KitKat or above (Just under 50% of devices that access the Google Play store in the last 7 day period measured) wipe data properly,

  6. When I buy a new phone, most of the time I run my old one through a crusher for this exact reason.

    The one time I actually sold my old phone, on top of doing a factory wipe I also changed all my passwords to all the accounts I had on it.

    Because of the way flash storage works, this same thing could also be done on an iPhone if someone with a special hardware reader attached it directly to the chip on the board. Not as easy, mind you, but this is why I think that EVERYONE both Android and iPhone users alike should be mindful when getting rid of an older device.

