Your secrets aren't safe if you sell your cell
Washington — Don't tell your cellphone any secrets. It might not keep them.
Second-hand phones purchased over the Internet surrendered credit card numbers, banking passwords, business secrets and even evidence of adultery.
One married man's girlfriend sent a text message to his cellphone: His wife was getting suspicious. Perhaps they should cool it for a few days.
“So,” she wrote, “I'll talk to u next week.”
“You want a break from me? Then fine,” he wrote back.
Later, the married man bought a new phone. He sold his old one on eBay for $290 (U.S.).
The guys who bought it now know his secret.
The married man had followed the directions in his phone's manual to erase all his information, including lurid exchanges with his lover. But it wasn't enough
Selling your old phone once you upgrade to a fancier model can be like handing over your diaries. All sorts of sensitive information pile up inside our cellphones, and deleting it may be more difficult than you think.
A popular practice among sellers, resetting the phone, often means sensitive information appears to have been erased. But it can be resurrected using specialized yet inexpensive software found on the Internet.
A company, Trust Digital of McLean, Va., bought 10 different phones on eBay this summer to test phone-security tools it sells for businesses. The phones all were fairly sophisticated models capable of working with corporate e-mail systems.
Curious software experts at Trust Digital resurrected information on nearly all the used phones, including the racy exchanges between guarded lovers.
The other phones contained:
—One company's plans to win a multimillion-dollar federal transportation contract.
—E-mails about another firm's $50,000 payment for a software license.
—Bank accounts and passwords.
—Details of prescriptions and receipts for one worker's utility payments.
The recovered information was equal to 27,000 pages — a stack of printouts 8 feet high.
“We found just a mountain of personal and corporate data,” said Nick Magliato, Trust Digital's chief executive officer.
Many of the phones were owned personally by the sellers but crammed with sensitive corporate information, underscoring the blurring of work and home. “They don't come with a warning label that says, 'Be careful.' The data on these phones is very important,” Mr. Magliato said.
One phone surrendered the secrets of a chief executive at a small technology company in Silicon Valley. It included details of a pending deal with Adobe Systems Inc., and e-mail proposals from a potential Japanese partner:
“If we want to be exclusive distributor in Japan, what kind of business terms you want?” asked the executive in Japan.
Trust Digital surmised that the U.S. chief executive officer gave his old phone to a former roommate, who used it briefly then sold it for $400 on eBay. Researchers found e-mails covering different periods for both men, who used the same address until recently.
Experts said giving away an old phone is commonplace. Consumers upgrade their cellphones on average about every 18 months.
“Most people toss their phones after they're done; a lot of them give their old phones to family members or friends,” said Miro Kazakoff, a researcher at Compete Inc. of Boston who follows mobile phone sales and trends. He said selling a used phone — which sometimes can fetch hundreds of dollars — is increasingly popular.
The 10 phones Trust Digital studied represented popular models from leading manufacturers. All the phones stored information on “flash” memory chips, the same technology found in digital cameras and some music players.
Flash memory is inexpensive and durable. But it is slow to erase information in ways that make it impossible to recover. So manufacturers compensate with methods that erase data less completely but don't make a phone seem sluggish.
Phone manufacturers usually provide instructions for safely deleting a customer's information, but it's not always convenient or easy to find. Research in Motion Ltd. has built into newer Blackberry phones an easy-to-use wipe program.
Palm Inc., which makes the popular Treo phones, puts directions deep within its Web site for what it calls a “zero out reset.” It involves holding down three buttons simultaneously while pressing a fourth tiny button on the back of the phone.
But it's so awkward to do that even Palm says it may take two people. A Palm executive, Joe Fabris, said the company made the process deliberately clumsy because it doesn't want customers accidentally erasing their information.
Trust Digital resurrected erased e-mails and other information from a used Treo phone after it was reset and appeared empty. Once the phone was reset using Palm's awkward “zero-out” technique, no information could be recovered. The Associated Press already used that technique to protect data on its reporters' phones.
“The tools are out there” for hackers and thieves to rummage through deleted data on used phones, Trust Digital's chief technology officer, Norm Laudermilch, said. “It definitely does not take a PhD”
Mr. Fabris, Palm's director of wireless solutions, said that the company may warn customers in an upcoming newsletter about the risks of selling their used phones. “It might behoove us to raise this issue,” Mr. Fabris said.
Dean Olmstead of Fresno, Calif., sold his Treo phone on eBay after using it six months. He didn't know about Palm's instructions to delete safely all his personal information. Now, he's worried.
“I probably should have done that,” Mr. Olmstead said. “Folks need to know this. I'm hoping my phone goes to a nice person.”
Guy Martin of Albuquerque, N.M., wasn't as concerned someone will snoop on his secrets. He also sold his Treo phone on eBay and didn't delete his information completely.
“I'm not that kind of valuable person, so I'm not really worried,” said Mr. Martin. “I guarantee that three-quarters of the people who buy these phones don't think about this.”
Trust Digital found no evidence that thieves or corporate spies are routinely buying used phones to mine them for secrets, Mr. Magliato said. “I don't think the bad guys have figured this out yet.”
U.S. President George W. Bush's former cybersecurity adviser, Howard Schmidt, carried up to four phones and e-mail devices — and said he was always careful with them. To sanitize his older Blackberry devices, Mr. Schmidt would deliberately type his password incorrectly 11 times, which caused data on them to self-destruct.
“People are just not aware how much they're exposing themselves,” Mr. Schmidt said. “This is more than something you pick up and talk on. This is your identity. There are people really looking to exploit this.”
Peiter “Mudge” Zatko, a respected computer security expert, said phone owners should decide whether to auction their used equipment for a few hundred dollars — and risk revealing their secrets — or effectively toss their old phones under a large truck to dispose of them.
What about a case like the Lothario whose affair Trust Digital discovered?
“I'd run over the phone,” Mr. Zatko said. “Maybe give it an acid bath.”
+ Reply to Thread
Results 1 to 9 of 9
09-01-2006, 03:25 AM #1
- Join Date
- Oct 2002
What you didn't know about cell phones"In Tempore"
09-01-2006, 03:31 AM #2
- Join Date
- May 2005
Another use for a nice hammer!Warm Regards,
09-01-2006, 03:54 AM #3
- Join Date
- Aug 2006
I used to work for the American Embassy in Belgium...they use the hammer frequently, al old electronics are smashed to bits before they go in the dumpster, even CPU's and RAM from old pc's.
09-01-2006, 09:06 AM #4
Usually my phone is completely inop before I get rid of it. I'm cheap so I use it until it is no longer possible. And by that point, I hate the thing so much I smash to pieces.Even the burger-flippers at McDonald's probably have some McWackers.
09-01-2006, 09:25 AM #5
- Join Date
- Mar 2006
Guess my old phone is going in the next fire....
09-01-2006, 04:23 PM #6
Same with computer hard drives, I usually send mine off with a couple of 4 inch nails through them.Psychiatrists state 1 in 4 people has a mental illness.
Look at three of your friends, if they are ok, your it.
09-02-2006, 12:29 AM #7
- Join Date
- Oct 2005
Arc welders do a nicer job.
Even NSA can't reconstruct data from a blob of aluminium.
And it's an even cooler toy to buy than a pneumatic nail gun.
09-05-2006, 04:13 PM #8
- Join Date
- Mar 2004
- Memphis Tn,USA-now
I'm too cheap to buy a "real"cell phone and have used the prepaid Tracfones for the past 6 years.
So far,only one has survived my lifestyle with the other 4 being smashed by dropping,getting soaked,run over by a pumper and my ex girlfriend's car.
Though I send the bits and parts back to be recycled,if anyone can get my information off of one of them,more power to them.I think you'd have a better chance at reconstructing the book"War and Peace"if you only had every other letter to guide you.
09-06-2006, 10:57 AM #9
- Join Date
- Jan 2004
- New Mexico, U.S.A.
Stored in the Brain.
My old one is sliding back and forth in the glovebox of car. I hate texting because my fingers are to big for the iddy bitty buttons. I deleted the numbers. I didn't put any other info in it. That's what the noggin is for.09.11.01--Never Forgotten
"Darn those pesky flaming mice."
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
By jester12 in forum Firefighters ForumReplies: 28Last Post: 01-11-2004, 03:51 AM
By leadlo in forum Firefighters ForumReplies: 20Last Post: 07-22-2003, 09:26 AM
By ramseycl in forum Emergency Services DispatcherReplies: 2Last Post: 03-07-2003, 12:07 PM
By Fireman Ry in forum TerrorismReplies: 4Last Post: 04-05-2000, 11:19 AM