Feeds

Giving your old Tesco Hudl to Auntie June? READ THIS FIRST

You can never wipe supermarket slab clean enough

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

UK supermarket Tesco’s Hudl tablet will offer up data from past users – even if it’s been factory reset.

The Register spoke to Ken Munro from security firm Pen Test Partners, who said he'd bought 17 Hudls and AllWinner tablets from eBay and found that not only does the reset process not wipe all the data, it’s possible to retrieve account details and login information.

Monro told El Reg: "The factory data reset doesn’t appear to zero all sectors on the disc; it’s simply too quick a reset process to do so."

He went on to confirm the suspicions: "So then we bought a few Tesco refurbished Hudls from the Tesco Outlet Store on eBay. Whilst two of them had been correctly zeroed using a wiping product, one was not. From this we recovered some of the previous owners personal data, again including social media and mail profiles."

He does, however, suspect this might be a one-off as Tesco has told him it does use erasing software, and it looked as though a partial wipe had been attempted.

Google’s advice is to run encryption software before resetting but Munro points out that this doesn’t work with Android 4.2.2 (Jellybean), which runs on the Hudl. There's no option in the menus and Munro points to the Rockchip CPU which powers the Hudl as that doesn't handle encryption of the user data partition.

One area which particularly worries Munro is that tablets are often put on eBay with broken screens and that these will not have been wiped at all. He points out that cheap tablets are often bought for children and by selling on a tablet which has the child’s social network data, the parent might be unwittingly aiding a stalker who could use the identity of the child to stalk other children.

Munro's fears go beyond that: "It also helps the stalker avoid a police sting – a copper would not be using a cheap tablet to sting a stalker with! They would be using a carefully managed and secured PC in a police building somewhere."

Munro is now working with Tesco, but the general advice is to use a third party tool to wipe any device before sale. ®

Website security in corporate America

More from The Register

next story
Bono: Apple will sort out monetising music where the labels failed
Remastered so hard it would be difficult or impossible to master it again
Oi, Tim Cook. Apple Watch. I DARE you to tell me, IN PERSON, that it's secure
State attorney demands Apple CEO bows the knee to him
Your chance to WIN the WORLD'S ONLY HANDHELD ZX SPECTRUM
Reg staff not allowed to enter, god dammit
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Monitors monitor's monitoring finds touch screens have 0.4% market share
Not four. Point four. Count yer booty again, Microsoft
Getting to the BOTTOM of the great office seating debate
Belay that toil, me hearty, and park your scurvy backside
Hey, Mac fanbois. HGST wants you drooling over its HUGE desktop RACK
What vast digital media repository could possibly need 64 TERABYTES?
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.