Help an idiot, please - Security Discussion

I was not thinking and I sold my phone on Ebay, whats worse is that it was bought by someone out of the country. I didn't think much about the consequences until the nagging question of why someone would buy a phone that will only work on a carrier here in the states, US Cellular. Now I am very concerned. The buyer has already paid for the phone and for shipping. My number one option could be to just cancel the sale and refund the buyers money and eat the shipping. I have began researching how to securely wipe an Android phone and the best answer I have found is to encrypt the phone before I do a factory reset. The problem is that I have already factory reset the phone. In fact, the phone was rooted and rommed and I Oddined the stock recovery back onto the phone. Here are details about the phone. It is a SM-N900R4 US Cellular Samsung Galaxy Note 3. Since I bought the phone new from the carrier I have installed and wiped numerous Roms. I'm not looking for anyone to stick there neck out there and give me guarantees, I just want to know if there is anything I can do to be reasonably sure that the phone is secure. What about apps like IShredder, are they worth the effort. Any advice would be greatly appreciated. thanks

Update, its 5:00am, I encrypted the phone, installed ishredder, ran the app a couple of times. I rerooted the phone using cf autoroot, downloaded a simple data recovery app, and am finding old data Any advice would be appreciated, thanks.

danp12 said:
I was not thinking and I sold my phone on Ebay, whats worse is that it was bought by someone out of the country. I didn't think much about the consequences until the nagging question of why someone would buy a phone that will only work on a carrier here in the states, US Cellular. Now I am very concerned. The buyer has already paid for the phone and for shipping. My number one option could be to just cancel the sale and refund the buyers money and eat the shipping. I have began researching how to securely wipe an Android phone and the best answer I have found is to encrypt the phone before I do a factory reset. The problem is that I have already factory reset the phone. In fact, the phone was rooted and rommed and I Oddined the stock recovery back onto the phone. Here are details about the phone. It is a SM-N900R4 US Cellular Samsung Galaxy Note 3. Since I bought the phone new from the carrier I have installed and wiped numerous Roms. I'm not looking for anyone to stick there neck out there and give me guarantees, I just want to know if there is anything I can do to be reasonably sure that the phone is secure. What about apps like IShredder, are they worth the effort. Any advice would be greatly appreciated. thanks
Click to expand...
Click to collapse
I think a factory reset is quite enough, you can wipe the internal storage as well. Just use Odin to flash a stock firmware and recovery and you should be good to go

If you are extra paranoid
Fill the memory with data.
Data and cache partitions are the most important.
Fill it with anything, delete it and fill it again. Seven times.
That will make it as hard as possible to recover any info.
But unless your a giant ass that has annoyed thousands around the world, put all your personal info on your phone. Advertise that fact.
Then be silly enough to advertise to all your enemy's that your selling your phone on eBay...
The standard wipe will likely be enough.

So I made the decision to refund the money and cancel the sale. I am shocked at how easy it is to find pictures, contacts, documents etc. after I encrypted the phone, deleted the data, used iShredder and wrote the drive at least 20 times at 3 cycles per time. I run a simple app called Disk Digger and I can still find data on the phone. Unreal. I think the iShredder app is simply not writing data in all of the areas of the phones memory. In fact, the more times I run iShredder and the more times I run disk digger, the more data I find This phone is connected to so much info like Paypal, Amazon, email, Bank Accounts etc. What a shame, my recommendation for anyone is the first thing you do when you pull your android phone out of the box is to Encrypt the drive, that way down the road when you delete the keys your data is safe. I have unloaded phones in the past but I never really thought much about it until I just really felt like the person buying it was buying it for nefarious purposes.

danp12 said:
So I made the decision to refund the money and cancel the sale. I am shocked at how easy it is to find pictures, contacts, documents etc. after I encrypted the phone, deleted the data, used iShredder and wrote the drive at least 20 times at 3 cycles per time. I run a simple app called Disk Digger and I can still find data on the phone. Unreal. I think the iShredder app is simply not writing data in all of the areas of the phones memory. In fact, the more times I run iShredder and the more times I run disk digger, the more data I find This phone is connected to so much info like Paypal, Amazon, email, Bank Accounts etc. What a shame, my recommendation for anyone is the first thing you do when you pull your android phone out of the box is to Encrypt the drive, that way down the road when you delete the keys your data is safe. I have unloaded phones in the past but I never really thought much about it until I just really felt like the person buying it was buying it for nefarious purposes.
Click to expand...
Click to collapse
Nothing from apps is stored on the internal sd card.
It's all stored on the data and cache partitions in the internal memory.
Partitions you can't touch without root.
There will always be data of some type left in the memory.
That's just how the memory works.
I have yet to find anything that will wipe the entire device properly automatically..
It has to be done manually.

Related

Selling my FUZE - need advice

Hey,
My wife listed my FUZE for me on eBay along with a couple other windows phones I've been told to get rid of...
I've never sold a smartphone before, what steps past a hard reset should I take to sell it safely?
Thanks
Link:
http://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=180472314891&ssPageName=STRK:MEWAX:IT:p:p
Assuming you are not leaving an SD card installed ...
I'd say the simplest way to zap everything is to do what you have done - a hard reset. If you really want to be sure, fill up the free space with rubbish files, then delete them when the phone is full.

Broken rooted captivate and Insurance claim

So I sadly had my Captivate caught in my car door as i closed it. Screen cracked, just slivers of light coming out. Speaker probably broken.
I made an insurance claim on the phone and paid the 125 deductible (really? X10 is only 50). So tomorrow is the last day I can return it.
Now I rooted my phone and put Cognition mod 2.3b7 on the phone. Is there a way for ATT to determine this and thus charge more for the phone upon return? If there is, is there any way I can wipe it off when I cant even see the screen? Thanks guys!
You do not really need to see the screen when using one-click Odin since it just basically reflashes your phone to stock. So what you can do, assuming that the phone still works (not the screen or speaker but basic boot up and such), just reflash using one-click. There is no guarantee that the phone will flash correctly but it is better than doing nothing.
All you gotta do is assume it went to the download screen before you plugged in the USB cable. From there, Odin can tell you if it sees your device in download mode. Click on start and watch the status bar. If the status bar hits 100%, there's a very good chance that you have reflashed back to stock and that you are safe.
In the future, just report that the phone was lost or stolen and they would not ask you to return it....since you cant! You will have to pay the $125 deductible anyway so you might was well say its lost and not have to deal with shipping it back.
Bane99 said:
So I sadly had my Captivate caught in my car door as i closed it. Screen cracked, just slivers of light coming out. Speaker probably broken.
I made an insurance claim on the phone and paid the 125 deductible (really? X10 is only 50). So tomorrow is the last day I can return it.
Now I rooted my phone and put Cognition mod 2.3b7 on the phone. Is there a way for ATT to determine this and thus charge more for the phone upon return? If there is, is there any way I can wipe it off when I cant even see the screen? Thanks guys!
Click to expand...
Click to collapse
You might consider just bricking it so it won't be obvious if/when they replace the screen and power it up. *IF* you choose to do so, you can put the phone in Download mode, start an Odin flash and then pull the cable. I'd imagine that standard procedure is likely to just use a jig and reflash it and not even look at what is on it.
When I go to training sessions with a particular St. Louis-based company I used a laptop for the training. Then 2 weeks later I had something else with them and by chance got the exact same laptop and they did not so much as delete the user profile since I had my server addresses coming up in Remote Desktop and MRU data was still in Explorer from looking at data on servers over VPN sessions. I helped them make sure that it got reinstalled by removing a handful of key Windows components so the system would not boot. This is the reason that I would recommend doing the same with your phone.
The problem is that when you return you phone, as I did with mine, you are giving AT$T everything on your internal SD card. In my case that included SMS backups, Titanium Backup files (including WiFi passwords and Google account settings), and all of the rest of your sensitive data on that chip. My new policy is to put all sensitive data on the external SD and just media on the internal.
While I can't take any responsibility for what you choose to do, if you have any other questions regarding this, feel free to ask or PM me. Good luck!
Well, the phone isn't being recognized by the computer anymore
Is there another way to erase the memory? I feel it vibrate when it turns on though.
They Probably Don't Care
Yes and No, they can but probably will just refurbish it to stock the same way we do, FLASH They have new phones to sell, Money in the Bank Frank
gormander said:
In the future, just report that the phone was lost or stolen and they would not ask you to return it....since you cant! You will have to pay the $125 deductible anyway so you might was well say its lost and not have to deal with shipping it back.
Click to expand...
Click to collapse
If you report your phone as "lost or stolen" but really did not lose it or have it stolen from you, you are committing insurance fraud. Do not do this. Its probably not the best idea to suggest this, either.
So, flashing the custom ROM and bricking it is not covered by the insurance? $125 to pay that deductible? Wow, higher than $50 for my older phone that got damaged by water.
If your phone automatically goes into Debug mode with USB cable, couldn't you just use adb to wipe it? That's IF....of course....Using Odin one-click like previously mentioned is probably the best idea. Easy to get into D/L mode.
Why not just send it in? Will they not cover a phone which has been rooted? It is my understanding that insurance has no limitations (It's not a warranty issue).
fatbas202 said:
You (snip) My new policy is to put all sensitive data on the external SD and just media on the internal.
While I can't take any responsibility for what you choose to do, if you have any other questions regarding this, feel free to ask or PM me. Good luck!
Click to expand...
Click to collapse
How do you put account info and program settings, such as ctedit card app username/pwd on the external sd card?
Sent from my SAMSUNG-SGH-I897 using XDA App
ScottyNuttz said:
Why not just send it in? Will they not cover a phone which has been rooted? It is my understanding that insurance has no limitations (It's not a warranty issue).
Click to expand...
Click to collapse
Exactly. If it's insurance it doesn't matter how they get it in. I personally don't send them anything by saying it got lost during insurance claims. i'm paying a deductible and a monthly fee, why should you salvage what you can when I have already payed you for a phone. Warranty is a different beast, then you would have to odin
Sent from my SAMSUNG-SGH-I897 using XDA App

Encrypt whole phone, considerations

Hi!
I'm very satisfied with the latest (1 March) 6.01 stock rom with cata mod on top of it.
I have never encrypted whole phone, I need to hear some pros and cons.
For example, if I encrypt it, I couldn't use any more swipe to unlock, only pin, that's OK. If I loose the phone, I will have less worries if it was encrypted, that's OK.
But what about speed, will I loose some speed (in everyday work, boot time) if enc?
Most important, will I be able to perform backup and restore from TWRP?
If I choose to enc, what is the procedure, I understand internal sdcard will also be encrypted?
Thanks in advance.
I have only Nexus devices (5 & 6), so I can't answer your SD card question.
I have used a N5 & N6 both encrypted and unencrypted, and I've read the report saying that there is a 50% performance hit (or whatever the figure is - it's supposed to be enormous in statistical terms) but in real-world usage there is no difference whatsoever that I can see. No stuttering, no lagging, no slow startup, absolutely nothing. If it takes an extra second to boot, I can't see it.
On the other hand, my wife lost her unencrypted Galaxy S2 a couple of months ago, so some slimy scumbag somewhere has access to our photos. No big deal, nothing embarrassing, but nevertheless I don't like the idea of some filthy lowlife creep looking at our personal family photos.
I tried Android N for a few days and didn't like the many apps that didn't work (including root, now resolved with SuperSU v2.70), so I restored my TWRP M backup. No problems whatsoever.
Go for it. I unreservedly encourage everybody to encrypt their devices. An imperceptible 5% hit is nothing to pay for peace of mind.
dahawthorne said:
Go for it. I unreservedly encourage everybody to encrypt their devices. An imperceptible 5% hit is nothing to pay for peace of mind.
Click to expand...
Click to collapse
Very useful experience, thank you. By internal sdcard, i meant internal storage, not sdcard actually.
Ah, in that case, yes. I wasn't thinking...
Since the internal sdcard *is* the phone's data repository, it wouldn't make sense to leave it unencrypted...

i9300 repair or retrieving internal storage if phone is not detected from computer?

HI
My wife's phone (i9300 galaxy S3) has gone wrong and it went off without battery.
I found a new battery, but it lasted only one day. I thus decided to take it for repair,
as I think that this is the charge connector that is broken, but actually, the tech told me that it was probably the motherboard,
as when it used a tool to plug it to the direct charge ports on the side, the phone only bootlooped.
Thing is:
My wife's phone wasn't using cloud or external SD,
it was not rooted.
I tried some android toolkits to connect it, but odin or adb don't detect it, so I have no chance to try and put some new kernel on it.
It has no recovery mode, and when in download mode (1st screen), it actually doesn't last long before it reboots anyway.
Choosing some option will also make it reboot.
So I think it is failed beyond software repair.
But if you have suggestion for this (the tech was at a small street stall and I don't expect him to be high level, no offense, but he seemed to only perform two repairs, screen and charge flex boards, so not much more able than me if he can't go beyond this), feel free?
So my second question is :
Does anyone know how to retrieve the internal storage of the phone without breaking it, and reinstall it in a working way on a new motherboard?
Or alternatively, on an emmc reader such as those used for raspberry cards and so on? (I don't want to put some link, I don't want my message to be filtered)
The photos on this chip are priceless for us, and I would even pay professional to retrieve these (I would prefer not having to, because money doesn't exactly come cheap to me, but I guess I won't be able to make it alone.
So if you know some repair service in Europe that would be able to perform such task, I would be grateful for your sharing of such knowledge.
I saw an alternative in malaysia, but it feels a little too far for being able to do something in case of problem.
Thanks for your attention and time.

htc u11 water damaged

hello,
please i want a solution to get my data from htc u11 after water damaged,
the sea water entered the phone before one month and i sent it to service center but they said it didn't work, after one month i plug the charger and it worked just on the boot screen and stuck there and the buttons are not working , and all the pictures were taken in the service center,
please help me to get the data
Hello there my friend. Sorry to hear that you lost your data. May be its a good lesson and you back it up now to the cloud, and specially when you wet your phone (not waiting a month to it). THERE IS NO PHONE THAT IS 100% WATER SUBMERSIBLE, most of cases is half an hour on non deep normal water.
Not sure in what country you are but that paper seems not to be from HTC. You should send the phone to HTC, and for sure U11 its pretty new, it should be under warranty still.
Back to your main problem. If the phone doesn't boot up, its complicated since the internal memory is encrypted, and you don't have a easy way to access to it not even having your buttons working. Sorry. Easeus (company that make great software for recovery and cloning), has an app for HTC for recovering data, may be you can give it a try: https://www.easeus.com/data-recovery/mobile-device-recovery/htc-data-recovery.htm
From now, try to use free services like google photos or if you have amazon prime the amazon drive that will give you unlimited space for photos backup. Saving photos to SD its better than internal, but if you lose the phone you lose the SD too. Crossed fingers that may be the app can recover something for you.
Assuming the USB port works but the buttons and touchscreen do not, if you can somehow get back to download mode you could try to unlock the bootloader and temp boot a special TWRP pack to dump the data(it would have your encryption password so you'll need to pack it yourself). I'm suggesting unlock and TWRP because it seems like the current ROM is not booting. Most service centers would wipe data before working though, hopefully you aren't that unlucky.
In all honesty it looks to me like the camera board is knackered, which contains the nfc chip and camera hardware.
The fact the phone can get as far as it can is almost promising. You must try to select download mode if your buttons still work. If not then you're stuck. If they do work then try flashing the stock firmware zip from an external sdcard. If it takes then it might boot. Reflashing the same firmware doesn't wipe any data. It just resets the firmware as stock, leaving your apps etc intact.
I believe it is running marshmallow august update, previous to nougat so your internal memory may not be encrypted, as previously stated, unless you encrypted it yourself. You will need the full Marshmallow 2gb update ruu zip, rename to 0pja10000.zip, copy to a class 10 microsd, place in phone and boot to download mode and flash it.
You might get somewhere, you might not. If it fails to flash then the phone is finished. If it flashes but doesn't boot its finished, if it boots BONUS!. There is also the possibility that the phone has been wiped in the store. If so your data may be gone forever BUT.. THERE'S AN APP FOR THAT!!.
Im not specifically promoting this app in any way its just that it is the only one I know of that does this and actually works, "Diskdigger". Its worth trying but it may not have any data to recover and if it does have an sd card in that is 64gb or more.
Only USA and Taiwan have "uh oh protection". A one time unconditional swap for another phone within, i think, 12 months.
Hope this helps.
deftoner said:
Hello there my friend. Sorry to hear that you lost your data. May be its a good lesson and you back it up now to the cloud, and specially when you wet your phone (not waiting a month to it). THERE IS NO PHONE THAT IS 100% WATER SUBMERSIBLE, most of cases is half an hour on non deep normal water.
Not sure in what country you are but that paper seems not to be from HTC. You should send the phone to HTC, and for sure U11 its pretty new, it should be under warranty still.
Back to your main problem. If the phone doesn't boot up, its complicated since the internal memory is encrypted, and you don't have a easy way to access to it not even having your buttons working. Sorry. Easeus (company that make great software for recovery and cloning), has an app for HTC for recovering data, may be you can give it a try: https://www.easeus.com/data-recovery/mobile-device-recovery/htc-data-recovery.htm
From now, try to use free services like google photos or if you have amazon prime the amazon drive that will give you unlimited space for photos backup. Saving photos to SD its better than internal, but if you lose the phone you lose the SD too. Crossed fingers that may be the app can recover something for you.
Click to expand...
Click to collapse
I think comtel is the authorized service provider for HTC phones in the emirates.
deftoner said:
Hello there my friend. Sorry to hear that you lost your data. May be its a good lesson and you back it up now to the cloud, and specially when you wet your phone (not waiting a month to it). THERE IS NO PHONE THAT IS 100% WATER SUBMERSIBLE, most of cases is half an hour on non deep normal water.
Not sure in what country you are but that paper seems not to be from HTC. You should send the phone to HTC, and for sure U11 its pretty new, it should be under warranty still.
Back to your main problem. If the phone doesn't boot up, its complicated since the internal memory is encrypted, and you don't have a easy way to access to it not even having your buttons working. Sorry. Easeus (company that make great software for recovery and cloning), has an app for HTC for recovering data, may be you can give it a try: https://www.easeus.com/data-recovery/mobile-device-recovery/htc-data-recovery.htm
From now, try to use free services like google photos or if you have amazon prime the amazon drive that will give you unlimited space for photos backup. Saving photos to SD its better than internal, but if you lose the phone you lose the SD too. Crossed fingers that may be the app can recover something for you.
Click to expand...
Click to collapse
Thank you
But i sent it to service center htc asked me to send it there

Categories

Resources