Daily Mail

Why your old phone is a THIEF’S PARADISE

From your bank account to private pictures and even passwords, a smartphone retains your most precious secrets — even when you think it’s been cleared, as HARRY WALLOP was horrified to discover

- By Harry Wallop

LIKE thousands of people, I was given a new phone for Christmas. But rather than just recycle my old phone, I thought I would sell it. My device was in good condition — a relatively sophistica­ted iPhone — and various websites suggested it would fetch £140.

I removed the SIM card, the little computer chip which contains my phone number and other key informatio­n, because this would go into the new phone, and deleted all the data, such as my photograph­s and emails, along with social media and messaging applicatio­ns like WhatsApp and Twitter. or, so I thought.

It turns out that buried in my old phone was a raft of personal informatio­n — all hugely valuable to any criminal, but catastroph­ic to me.

‘I could even work out where you live,’ James Smith tells me casually.

he is the man who — with my permission — hacked into my old phone, which I thought I had wiped completely clean.

head of penetratio­n testing at Bridewell Consulting, a digital security company, Smith spent a day seeing what he could retrieve from my device. ‘ It was relatively simple,’ he explains. ‘It didn’t require any particular bit of kit. This was using readily available tools that are either free or very cheap.’

And, boy, what he found was eye-opening. he was able to obtain the password I used for a chess-playing app, which — embarrassi­ngly for me — is the same password I use for various other, far more important, apps.

‘That’s the jackpot for a hacker. They will go through every online account, Facebook, Twitter, emails and “password spray”, seeing if that password works for any of them.

‘The moment you get access to your email account, you can get hold of all sorts of things, and start phishing your contacts.’

This is when a hacker would pose as me and retrieve, potentiall­y, the bank account details of my friends and family.

‘They’d be very easily able to impersonat­e you,’ says James. And it would be particular­ly easy in my case because all my contacts, along with their mobile phone numbers and emails, were accessible.

I had sent off my phone after a report published a fortnight ago by The national Cyber Security Centre — part of GCHQ — implored consumers to be aware of how much data was now stored on their phones and the ‘importance of erasing this before selling so that it does not inadverten­tly fall into the hands of criminals’.

I presumed this was a nannying piece of advice from a Government quango. Far from it.

Figures obtained by the Daily Mail suggest that a vast number of people are failing to adequately wipe their phones before selling them on the secondhand market.

research released yesterday by cyber security firm Kaspersky suggests that there are tens of thousands of phones for sale with private informatio­n still on them.

Kaspersky surveyed consumers across the UK and Germany. of those who have bought a second hand mobile device, 18 per cent said they had found photos, eight per cent had found login details and passwords, and seven per cent had found identifica­tion documents such as driver’s licence.

This was from a survey. It is conceivabl­e that some people were exaggerati­ng. But the security company also bought 185 random devices from the likes of eBay, Facebook Marketplac­e and Amazon, all of which are popular places to buy second-hand phones and laptops.

It found 16 per cent had ‘in plain sight’ data, such as photos or messages, easily accessible for anyone to see and read.

More worryingly, a further 73 per cent had data that was accessible to anyone with a bit of tech know-how.

Photograph­s of people posing with class-A drugs, nude pictures, scans of people’s driving licences and passports, tax documents, bank details and a wealth of incriminat­ing data was buried in these devices — if you knew how to find them. That means a mere 11 per cent were properly wiped clean of all their data.

‘I think the issue is laxity,’ explains David Emm, principal security researcher at Kaspersky. ‘ We still psychologi­cally approach a mobile phone in the same way that we did maybe ten years ago.

‘We call them phones, even though they’re actually computers. Although we don’t really use them just for making calls or sending texts — we do all of this other stuff on there — we somehow aren’t as careful when it comes to security.’

Selling unwanted mobile phones has become increasing­ly common. A decade ago, most old phones were pretty worthless but, as the sophistica­tion and price of smartphone­s has increased, many consumers have discovered they can make as much as £500 on a phone that is 18 months old, if it’s in good condition.

EY-PARTHENON, a consultanc­y firm that is part of Ernst & Young, estimates that 30 per cent of all smartphone­s are re- sold, totalling 8.1 million phones each year.

Also, according to the regulator ofcom, far more consumers now buy their phones separately from their monthly data contract — on what is known as a SIM- only deal, giving them the freedom to upgrade their phone often and sell their used one.

Back in 2014, just 15 per cent of customers did this; in 2019 it was 34 per cent (the most recent year we have figures for; it’s likely to be yet higher now).

As a result, a dozen specialist websites have sprung up on which you can sell your phone. The most reputable ones, such as musicMagpi­e, explain that you should wipe all your data — and explain how to do it.

Some sites, however, give no such instructio­ns.

Mark Payton is a former policeman and now forensics manager at Cyfor, a security company which mostly works for criminal defence solicitors. he says: ‘ There are lots of people who are not aware that phones have a factory reset button. So they will just go through the photo gallery and delete pictures and go into messages and delete all the messages, as opposed to doing a full factory reset of their phone.’

This is exactly what I did before sending my phone off to Smith at Bridewell. And it explains why he found it relatively easy to find a lot of my personal informatio­n — even though I thought I’d deleted it.

Admittedly, much of what he found was fairly mundane: old shopping lists, photos of my children, and a list of all the websites I had visited. But some was deeply alarming — not just my most used password.

Even though my SIM had been removed, my phone number was visible. All my contacts were accessible along with their emails and phone numbers. Distressin­gly, there was also an old message I’d sent to someone that included my bank account details so that they could pay me.

MOST worrying of all, perhaps, he could work out where I lived. ‘You can do this from exit data.’ Smith explains: ‘ This is now on all cameras, tagging the photograph with what device it was taken on, the mode it was in, along with the longitude and latitude of where you were. This is designed to help you find all the photos, for instance, you took in France.’

But you can also zoom into where you most often take photograph­s — invariably your home address. Smith tells me he can work out within about three houses my address on a row of terrace houses in London, just by using this exit data on my photograph­s.

Then, by cross-referencin­g these houses to all the wifi addresses I had connected to, he could pinpoint an exact address. ‘I can put two and two together and work out where you live. It is easy to find out where a wifi address is registered to.’

But how could he do this, even though I thought I had deleted all the apps, photos and informatio­n from my phone?

Mark Payton explains why deleting apps is not good enough — even when they invariably flash up a warning saying ‘deleting this app will also delete its data’.

‘An app is often the front- end to the data that is stored in the phone,’ he says. ‘ If you take WhatsApp, for instance, it has a back- end database within the phone where all messages are stored. If you delete the app, most of the time the back- end database doesn’t get deleted off the phone.’

David Emm says that deleting photos or messages doesn’t mean they have left your phone. he explains that when you delete something, ‘all that the system does is to flag up in the index this area is available for new files’.

The deleted message just sits in the background, still able to be retrieved, until you run out of space and need to write over the top of it.

he compares it to old VhS tapes of TV shows — deleting them just means you move the tape into the ‘ready to be reused pile’. The data isn’t gone until you use the tape to record a new show.

Smith says hacking into my phone and recovering passwords that I had used was relatively simple. First of all, he plugged my phone into his computer and then downloaded a piece of software called Dr.Fone.

The premium version costs £72 and helps crack open the ‘backend’ of the phone. This popular piece of software is used to help people recover data they have lost or deleted

by accident. it can even unlock a phone if you have forgotten the screen lock code.

‘it’s really pretty simple to find all the deleted stuff,’ smith says. the next step, however, required a bit more know-how. ‘all the data i collected, i put into a tool called autopsy. this is free software. it indexes every bit of informatio­n into a database, then you search for strings [of code]. the first thing i searched for was strings containing the word “password”.

‘and it wasn’t too long before i found one. a hacker could spend hours and probably find far more passwords.’

when he reads back to me over the phone the password he’s found, i’m ashen-faced at how many things he could have unlocked with it.

payton adds that, even if you weren’t a tech expert, you could probably find some old passwords or deleted data from a secondhand phone that hadn’t been wiped properly. ‘on the internet there are plenty of forums, such as on reddit, where people can talk you through how to do this.’

all the experts point out that more recent phones that have been launched within the past couple of years, tend to be more secure. so, too, are the most recent apps — which sometimes require what’s known as twofactor authentica­tion.

this is when you are sent a code to your phone or email to gain access to Facebook, for instance. But if you have skilfully cracked into someone’s email, that may be of little use.

there is another concern with secondhand phones. and that is for the buyer, not the seller. if you purchase an older model, there is a strong chance that it will no longer be supported by the manufactur­er.

this is important, because if a model is no longer supported, it means the likes of apple or samsung no longer send security updates — potentiall­y leaving the new owner of the phone vulnerable to being hacked.

WHICH? — the consumer organisati­on — investigat­ed this issue last summer and discovered that 31 per cent of phones on sale at the leading secondhand sites were no longer supported by the manufactur­er.

anything older than an iphone 6, for instance, is now obsolete and would leave any user vulnerable to being hacked. on Facebook Marketplac­e this week, there were still plenty of iphone 5s for sale.

kate Bevan, editor of which? Computing, says: ‘as the secondary and refurbishe­d market continues to grow for tech products, manufactur­ers must be more transparen­t about the lifespan of devices and how long they’ll provide security updates for, so people can make clear decisions and aren’t at risk of buying unsupporte­d devices.’

Facebook did not want to comment directly, but said it supplied tips to consumers buying from and selling on its marketplac­e. these tips amount to, ‘if possible, make sure to thoroughly inspect or test the item before buying it’.

Ebay says: ‘ when selling a mobile phone, whether online or offline, sellers are advised to take the responsibl­e steps to protect their own data by wiping all content and settings and securing their devices.’

of course, if i had sold my ‘wiped’ phone on the internet and it had fallen into the wrong hands, i possibly wouldn’t know, until some money mysterious­ly left my account or someone posted pictures of me and my children on the internet.

payton urges the hundreds of thousands of people who will be selling their phones in a new year clear out to wipe them properly.

‘Doing a factory reset is the gold standard. it makes it very difficult — and sometimes impossible — to extract any data from the phone once that has happened. But a lot of people don’t know that is possible to do. it’s buried in about four different menu options.’

if you want to avoid a potential catastroph­e, follow his advice.

 ??  ??

Newspapers in English

Newspapers from United Kingdom