Flawed Android factory reset leaves crypto and login keys ripe for picking

Clocks

Well-known member
Aug 27, 2010
2,009
18
0
Flawed Android factory reset leaves crypto and login keys ripe for picking | Ars Technica

TLDR:
Data is easy to recover from previously used phones even after a factory reset. Even if your device was encrypted all that is needed is the encryption password to regain access even after a factory reset. A short password can be cracked in a few hours.

The big takeaway is before you sell your phone:
1) encrypt the device with a very long password (11+ characters) of letters and numbers
2) then do a factory reset
 
Thanks, good PSA. This whole issue is a big facepalm!:-\

It's worth pointing out that the study included only phones up to 4.3, so hopefully Kitkat and Lollipop are more secure.
 

Latest posts

Trending Posts

Forum statistics

Threads
963,719
Messages
6,993,976
Members
3,165,111
Latest member
gautamsingww