Naked selfies extracted from 'factory reset' phones

I guess your personal data is never safe & someone can always extract from old devices.

BBC News - Naked selfies extracted from ‘factory reset’ phones

Thousands of pictures including “naked selfies” have been extracted from factory-wiped phones by a Czech Republic-based security firm.

The firm, called Avast, used publicly available forensic security tools to extract the images from second-hand phones bought on eBay.

Other data extracted included emails, text messages and Google searches.

Experts have warned that the only way to completely delete data is to “destroy your phone”.

Most smartphones come with a “factory reset” option, which is designed to wipe and reset the device, returning it to its original system state.

However, Avast has discovered that some older smartphones only erase the indexing of the data and not the data itself, which means pictures, emails and text messages can be recovered relatively easily by using standard forensic tools that anyone can buy and download.

The company claims that of 40,000 stored photos extracted from 20 phones purchased from eBay, more than 750 were of women in various stages of undress, along with 250 selfies of “what appears to be the previous owner’s manhood”.

There was an additional 1,500 family photos of children, 1,000 Google searches, 750 emails and text messages and 250 contact names and email addresses.

The company said: “Deleting files from your Android phone before selling it or giving it away is not enough. You need to overwrite your files, making them irretrievable.”

It was not made clear by Avast whether they extracted data from all 20 phones.

Destroy the phone
Google responded that Avast used outdated smartphones and that their research did not “reflect the security protections in Android versions that are used by the vast majority of users”.

It was recommended by Google that all users enable encryption on their devices before applying a factory reset to ensure files cannot be accessed.

This feature, said Google, has been available for three years, although it is not enabled by default, which could leave less tech-savvy users open to attack.

Apple has had built-in encryption for its hardware and firmware since the release of the iPhone 3GS.

The hardware encryption is permanently enabled and users cannot turn it off.

Additional file data protection is available, but must be turned on in the settings menu.

Independent computer security analyst Graham Cluley said that if a user is serious about privacy and security they should make sure their device is always “protected with a PIN or passphrase, and that the data on it is encrypted”.

However, Alan Calder, founder of cybersecurity and risk management firm IT Governance, told the BBC that erasing data, even after it has been encrypted, will not be enough to completely protect your device.

“Google’s recommended routine for protecting the data only makes it harder for someone to recover the data - it does not make it impossible,” he said.

“If you don’t want your data recovered, destroy the phone - and that has been standard security advice, in relation to telephones and computer drives, for a number of years. Any other ‘solution’ simply postpones the point at which someone is able to access your confidential data.”

Re: Naked selfies extracted from 'factory reset' phones

This is old news with a new spin, though very interesting. Corporate espionage has long depended on recovering discarded hard drives from companies and spinning them to find out whatever 'deleted' data can be found on them :)

Re: Naked selfies extracted from 'factory reset' phones

^^^ FBI has been doing it for long time, but it is kind of scary b/c if you sell your device to anyone online everything can be extracted included your financial (credit cards/ bank accounts, etc) and medical information.

Re: Naked selfies extracted from 'factory reset' phones

Good thing i'm a device hog and I don't ever sell anything forward :p

Re: Naked selfies extracted from 'factory reset' phones

That's why you overwrite, overwrite, overwrite. At least that's waht you do with computer HDs. I wonder if there is such a program for cell phones. There should be one
@Cheegum no one would wanna buy my cell phones either =/ No camera/broken/unworking beyond words.

Re: Naked selfies extracted from 'factory reset' phones

It's easy to stop this from ever happening if you sell your phone, as it states in the article. Just "Encrypt" your phone, so that everytime you switch it on you'll need to enter a pin. Than do a factory reset, do another encryption, another factory reset. You're good to sell it. Even experienced hackers using brute force would find it hard to get through 2 encyptions. It wouldn't even be worth their time and considering 99.9% of humans are n00bs. You're pretty safe following these steps.

Re: Naked selfies extracted from 'factory reset' phones

I think there are programs out there that would limit the ability to recover deleted data from HD. I usually keep all my personal data on the SD card.

Naked selfies extracted from 'factory reset' phones

Holly crap! I've been using avast free version on my personal laptops I just hope they don't extract it from there. I guess a price to pay for being cheap

Re: Naked selfies extracted from 'factory reset' phones

Dude, no one wants to see you naked, m kay ?

Much simpler option would be not to take pictures of your manhood.

Re: Naked selfies extracted from 'factory reset' phones

with this new info, the sale of 'used' phones will go up exponentially! :D

Re: Naked selfies extracted from 'factory reset' phones

This is a publicity stunt by avast, nothing new, its been like that always, computers/smartphones usually don't literally delete the data when you click the delete button, it just mark that space as free for new data to be written. Resetting after encrypting is a better option (or always encrypt your phones and hard disks)

Re: Naked selfies extracted from ‘factory reset’ phones

Android is a looser AGAIN ! :smokin:

Re: Naked selfies extracted from 'factory reset' phones

Yep. Avast wants to sell their stuff.

Not difficult to turn on encryption.