Feeds

Giving your old Tesco Hudl to Auntie June? READ THIS FIRST

You can never wipe supermarket slab clean enough

  • alert
  • submit to reddit

Secure remote control for conventional and virtual desktops

UK supermarket Tesco’s Hudl tablet will offer up data from past users – even if it’s been factory reset.

The Register spoke to Ken Munro from security firm Pen Test Partners, who said he'd bought 17 Hudls and AllWinner tablets from eBay and found that not only does the reset process not wipe all the data, it’s possible to retrieve account details and login information.

Monro told El Reg: "The factory data reset doesn’t appear to zero all sectors on the disc; it’s simply too quick a reset process to do so."

He went on to confirm the suspicions: "So then we bought a few Tesco refurbished Hudls from the Tesco Outlet Store on eBay. Whilst two of them had been correctly zeroed using a wiping product, one was not. From this we recovered some of the previous owners personal data, again including social media and mail profiles."

He does, however, suspect this might be a one-off as Tesco has told him it does use erasing software, and it looked as though a partial wipe had been attempted.

Google’s advice is to run encryption software before resetting but Munro points out that this doesn’t work with Android 4.2.2 (Jellybean), which runs on the Hudl. There's no option in the menus and Munro points to the Rockchip CPU which powers the Hudl as that doesn't handle encryption of the user data partition.

One area which particularly worries Munro is that tablets are often put on eBay with broken screens and that these will not have been wiped at all. He points out that cheap tablets are often bought for children and by selling on a tablet which has the child’s social network data, the parent might be unwittingly aiding a stalker who could use the identity of the child to stalk other children.

Munro's fears go beyond that: "It also helps the stalker avoid a police sting – a copper would not be using a cheap tablet to sting a stalker with! They would be using a carefully managed and secured PC in a police building somewhere."

Munro is now working with Tesco, but the general advice is to use a third party tool to wipe any device before sale. ®

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Fujitsu CTO: We'll be 3D-printing tech execs in 15 years
Fleshy techie disses network neutrality, helmet-less motorcyclists
Space Commanders rebel as Elite:Dangerous kills offline mode
Frontier cops an epic kicking in its own forums ahead of December revival
Intel's LAME DUCK mobile chips gobbled by CASH COW
Chipzilla won't have money-losing mobe unit to kick about anymore
First in line to order a Nexus 6? AT&T has a BRICK for you
Black Screen of Death plagues early Google-mobe batch
Ford's B-Max: Fiesta-based runaround that goes THUNK
... when you close the slidey doors, that is ...
Disturbance in the force lets phones detect gestures with Wi-Fi
These are the movement detection devices you're looking for
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Designing and building an open ITOA architecture
Learn about a new IT data taxonomy defined by the four data sources of IT visibility: wire, machine, agent, and synthetic data sets.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?