www.unuudur.com » Security Analysis of Android Factory Resets

Security Analysis of Android Factory Resets

[Нийтэлсэн: 17:35 27.05.2015 ]

www.cl.cam.ac.uk

With hundreds of millions of devices expected to be traded by 20181 , flaws in smartphone sanitisation functions could be a serious problem. Trade press reports2 have already raised doubts about the effectiveness of Android “Factory Reset”, but this paper presents the first comprehensive study of the issue. We study the implementation of Factory Reset on 21 Android smartphones from 5 vendors running Android versions v2.3.x to v4.3. We estimate that up to 500 million devices may not properly sanitise their data partition where credentials and other sensitive data are stored, and up to 630M may not properly sanitise the internal SD card where multimedia files are generally saved. We found we could recover Google credentials on all devices presenting a flawed Factory Reset. Full-disk encryption has the potential to mitigate the problem, but we found that a flawed Factory Reset leaves behind enough data for the encryption key to be recovered. We discuss practical improvements for Google and vendors to mitigate these risks in the future.

For more:

http://www.cl.cam.ac.uk/~rja14/Papers/fr_most15.pdf



Шинээр

Mongolia Bows to Pressure From IMF, Mining Majors
[Нийтэлсэн: 25.05.2017 ]
[Эх сурвалж: ]
China successfully mines flammable ice from the South Sea
[Нийтэлсэн: 19.05.2017 ]
[Эх сурвалж: ]
Nationalist politician enters race for Mongolian presidency
[Нийтэлсэн: 19.05.2017 ]
[Эх сурвалж: ]
Scaling up, 6,000 miles from New York City
[Нийтэлсэн: 18.05.2017 ]
[Эх сурвалж: ]
Turquoise Hill revenue surprise lifts shares 6%
[Нийтэлсэн: 17.05.2017 ]
[Эх сурвалж: ]
Mongolia says it grows 4.2 pct y/y in Q1, lifted by higher coal prices
[Нийтэлсэн: 17.05.2017 ]
[Эх сурвалж: ]
Nuurstei project mine development funding update
[Нийтэлсэн: 12.05.2017 ]
[Эх сурвалж: ]

Get Flash to see this player.