Refurbished iPhones are an excellent source of previous users' data
It looks like you might have to think twice before flipping that old iPhone on eBay when the 3G version finally hits -- it appears that restoring the phone doesn't actually erase the contents of the flash, meaning that your data is available to anyone with the proper tools until it's overwritten. Making matters worse, it appears that Apple doesn't do a low-level format when refurbishing iPhones either -- an Oregon State Police detective was able to use forensic software to pull files, emails, and screenshots off an out-of-the-box refurbished iPhone. This actually shouldn't be surprising to anyone -- we've seen several utilities that access "deleted" portions of storage -- but since Apple doesn't provide users direct access to the iPhone's filesystem, it's basically impossible to clear your personal data off the device short of restoring and filling the disk with junk data. Hopefully iPhone 2.0's Exchange-based "remote wipe" feature is a bit more secure, eh?
[Via TUAW]
[Via TUAW]













Reader Comments (Page 1 of 1)
Konceptz @ May 20th 2008 4:47PM
pwnd.
frankpreyes @ May 20th 2008 5:28PM
ALL YOUR IPHONES ARE BELONG TO US!
oliver hart @ May 20th 2008 5:49PM
wow, i didnt know apple made mistakes. my whole perception of reality is now thrown into question...
Shadow08 @ May 20th 2008 7:50PM
Yeah I know. If this was Microsoft we would never hear the end of how poorly designed and insecure their products are. Are Windows Mobile phones even at risk?
tc1uscg @ May 20th 2008 10:22PM
Please say your kidding. Just the notion that you think this way of apple (that they can do no wrong) is what's wrong with this world today. BLIND ACCEPTANCE BECAUSE OF THE NAME. If you do, then your a idiot. If your kidding.. good one.
slamEVIL @ May 20th 2008 6:34PM
but i'm sure apple and the freakin' iphone are still soooooo perfect and can do no wrong.
Chris Cox @ May 20th 2008 7:44PM
Ummmmmm how is this news? I don't know of ANY ... ANY smartphone that does a proper wipe of data. Why are people talking like APPLE did wrong? I want someone to give me an example of a smartphone that does a proper NSA 3 pass wipe to ensure data cannot be recovered. NAME ONE. If they don't (and none of the phones do), then it is certain your data can be recovered. Blaming this on Apple only shows your ignorance.
Shadow08 @ May 20th 2008 11:22PM
Well, apparently it's news every time Windows has a zero-day attack even though every OS and software has it's holes and problems.
I'm not a MS fanboy by any means, but the bias that's always in Apple's favor really annoys me.
slamEVIL @ May 20th 2008 8:12PM
i think the point here is, this dude bought it directly from apple. apple didn't erase the data correctly. soooooo yes, apple did wrong.
itsTooEasy @ May 20th 2008 8:24PM
BlackBerry (page 67):
http://na.blackberry.com/eng/deliverables/799/BlackBerry_Enterprise_Solution_Security_Technical_Overview%5B1%5D.pdf
carlo2 @ May 20th 2008 8:39PM
This is what happens when you have to hack your phone to get it to do things that so many other phones already do. If people weren't looking for ways to provide functionality for the phones, and were satisfied with it, there wouldn't be half as many people chopping it apart to get at what they want...
Is the iPhone the most hacked phone ever?
tc1uscg @ May 20th 2008 10:21PM
Do you really thing the idiot whyphone users care about this. But hey, the phone is "cool" to "play" with.
adage @ May 20th 2008 11:00PM
People are jumping all over this because if this had been a Microsoft product, Apple fanboys would jump all over it and claim Microsoft as producing crappy products. But when Apple makes a mistakes, the Apple fanboys are all "well Microsoft does this all the time" and "well why is it a big deal if Apple makes a mistake?".
tekdroid @ May 20th 2008 11:37PM
i hear if you make a mashing jumble swirling motion on the touchscreen that activates secure delete.
;)
kashif @ May 21st 2008 12:30AM
Where's that "Will it Blend" video for this.... I see lots of relevance.
roberto @ May 21st 2008 5:49AM
3G iphone on june the 9th!
http://jack.tiscali.it/news/08/05/20_05_iphone_3g.html