Android 's factory reset feature has been found to be ineffective in completely erasing user data and information.
A research paper titled “Security Analysis of Android Factory Resets” (PDF) by researchers at the University of Cambridge revealed some very interesting information regarding privacy on Android devices.
The factory reset feature, which is supposed to be the last step before selling an old device, was found to fail in tests conducted by researchers on 21 devices from five different manufacturers.
The devices used for the research were rather old and ran versions of Android below version 4.4, but the researchers are confident that the security issues they discovered still exist in newer versions of the operating system.
According to the research paper, the devices tested after the reset retained SMS data, emails, contacts, authorized accounts, and information from various apps like Facebook and WhatsApp.
Digging deeper, the researchers were able to recover the Google master token used to authenticate apps like the device's calendar and contacts.
The researchers say that the drivers required to completely erase the device's data may not have been installed by manufacturers, who generally tend to customize only the necessary (for them) operating system features, implying that it's not just Google.
Researchers recommend that users who want to get rid of their old data encrypt it before using the factory reset.
Source: iguru

