Android Factory Resets Are Flawed, Allow User Data to Be Recovered: Study

Advertisement
By NDTV Correspondent | Updated: 25 May 2015 11:41 IST
Thinking of selling your old Android smartphone? Watch out, as its data may be retrievable even after wiping it, finds a Cambridge study.

User data is routinely retrievable from second-hand Android devices that have been wiped through a factory reset, the Cambridge study warned.

Most Android handsets offer no easily accessible way of deleting user data including access tokens, messages, images and other content, researchers said.

Advertisement

The factory-reset shortcomings uncovered by researchers at the Cambridge University affect an estimated 500 million Android handsets, and pose a problem for organisations that routinely resell such devices. These 500 million handsets may not properly sanitise the data partition where credentials and other user data is stores, while up to 630 million handsets may not properly sanitise the internal SD card where multimedia files are generally saved.

They examined 21 second-hand devices running Android versions 2.3 to 4.3 from five manufacturers that had been wiped using the operating system's built-in factory reset feature.

Advertisement

Researchers said the problems also exist with third-party data deletion applications, and pointed to a separate study on the same. Similar problems are likely to persist in newer versions of Android, the team said.

The team was able to recover data including multimedia files and login credentials from wiped phones, and many of the handsets yielded the master token used to access Google account data, such as Gmail. Both phone contact data and

Advertisement

Such data can be recovered even from handsets protected by full-disk encryption, researchers said, as the 'crypto footer' file that stores the decryption key isn't erased after a factory reset.

The problem results from multiple issues, including the inherent difficulty of fully deleting data from the flash memory used in smartphones, something due to the physical nature of such memory chips, according to the research. Other issues include vendors' failure to include necessary drivers to fully wipe flash memory used for non-volatile storage.

Advertisement

The researchers were able to recover the master token in a device and found that after reboot, it successfully re-synchronised contacts, emails and other data.

The master token, used to access Google accounts, was found to be retrievable in 80 percent of the devices that had a flawed factory reset mechanism.

Actual solutions for users are currently scarce. The team discussed a few ways to mitigate flawed factory resets, including filling up the partition of interest with random-byte files, in the hope of overwriting all unallocated space. This could be done third-party non-privileged apps after the built-in Factory Reset. This would require the app to be installed manually by users after a Factory Reset is performed. The drawback of this method is that it requires privileged (i.e. root) access to devices, and will therefore not be suitable for ordinary users. While the method does not provide thorough digital sanitisation, an attacker cannot recover data using public APIs exposed by the Linux kernel.

Another solution is enabling Full Disk Encryption (FDE) on first use of the device. Enabling FDE only before performing a Factory Reset may only provide logical sanitisation, not thorough digital sanitisation (plain-text data could still be present on the flash drive). The use of a complex user PIN longer than 6 digits is also recommended to prevent brute force attacks.

For vendors, the team recommended use of a recent eMMC with support for digital sanitisation, and to properly expose it in the Bootloader, Recovery and Android kernels.

Written with agency inputs

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Android, Google, Mobiles, Smartphones
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: 24, Band Melam, Nukkad Naatak, Prathichaya, and More
  2. Vivo Y6 5G Debuts With 7,200mAh Battery, 6.75-Inch Screen at This Price
  3. Instagram Launches Instants App With Disappearing Photos to Rival Snapchat
  4. Leaked Dummy Gives Us an Early Look at the Design of the iPhone 18 Pro Max
  5. Qualcomm Hints at Snapdragon Chips for Samsung Galaxy S27 Series
  6. Honor MagicPad 3 Pro 12.3 Debuts With 10,100mAh Battery, Slim 4.8mm Profile
  7. Detailed Oppo Find X9 Ultra Teardown Video Shows Us What's Inside
  8. Vivo X500 Series Screen Sizes Leaked, Could Arrive With 144Hz Displays
  9. Xiaomi Mix Fold 5 Might Be in Development With This In-House Chip
  1. Jio Youth and Gaming Plan With Snapchat+, FanCode and Gemini Pro Launched: Price, Benefits
  2. Infinix GT 50 Pro Launched With Dimensity 8400 Ultimate, HydroFlow Liquid Cooling, Shoulder Triggers: Price, Features
  3. Adobe Previews New Agentic AI Workflows for Marketing Tasks at Adobe Summit 2026
  4. Microsoft Gaming Rebrands to Xbox, Debuts New Logo as Xbox Chief Says Company Reevaluating Exclusive Games
  5. Instagram Launches Instants App With Disappearing Photos to Rival Snapchat, BeReal
  6. Prathichaya (2026) Now Streaming Online: What You Need to Know
  7. Vivo X500 Series Tipped to Launch With 144Hz Displays, Ultrasonic Fingerprint Scanners
  8. Kelp Exploit Aftermath: DeFi Protocols Join Hands to Restore rsETH Following $293 Million Hack
  9. Microsoft Makes Copilot’s Agentic Features in Word, Excel and PowerPoint Generally Available
  10. OnePlus Ace 6 Ultra Battery Capacity Revealed as Company Teases ‘Energy Concentration’ Chip
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.