Five billion phones are dead in drawers – carriers want to mine them
theregister.com
theregister.com
They don’t start so there’s no way to boot and wipe. And they are hard to disassemble and remove the storage.
So I do the calculation of getting like $2 off a new phone or the extremely low, but non-zero, probability of all my photos ending up somewhere not cool.
To help with this, right to repair also makes things more recyclable.
I've thought about how long I intend to do this, or, even if I let the battery stay disconnected, how long I will keep the phone. I suspect I'll keep the phone until I die myself but wonder if it would end up being some odd sort of family heirloom/relic 100 years from now.
(FWIW, I have captured to other devices her photos and such so that I am not reliant on the physical device for these memories.)
I found some old computers a while back, from the early 2000s. None of them booted. I couldn't get anything off even after pulling the HDs and connecting to them directly - everything was corrupted despite sitting in a fairly dry, clean, climate-controlled space.
My Dad died in 2021 and like the OP above I have his phone still connected to power and photos videos, calls etc. on it.
What you say is correct but I haven't the courage to look at the photos yet. Videos will be especially hard much more real than a picture.
But yes I have to act.
You can install something like Dropbox or Nextcloud and set them up to sync the entire photo album. Just checking the rough counts on either end should get you a decent indicator that you've got everything. (It's possible something gets missed but, trying to not let the perfect be the enemy of the good, it would certainly be a much safer position over where you are today.)
As much as anything, I'm just trying to give you a nudge. I can only imagine how much it would compound the heartbreak to lose all of that.
My sympathies for your loss.
Likely: time/date, and you will need to compile modern ssl and gnu tls. I've found that even if I'm doing a pure http request (no https), I can't fetch anything without a modern ssl/tls library. At least that's how it was on an old kindle
(I actually mean that, but I'm also attempting to be sorta funny)
Though it would be nice if they had a get the old data off that dead phone and return to you process. (Which reminds me, I need to setup backups on my latest phone
It's difficult to see this being profitable. Or even possible, given the meagre training most carriers' employees at physical stores seem to have.
Easier: a device that shreds the phone onsite, in front of the customer.
Training is one thing, but the primary issue is wages and career prospects. Nobody working in a customer-facing role at a mobile carrier is paid enough to give a shit to do proper data protection - in fact they might be paid more by a malicious actor (bribery) to intentionally compromise data protection, just like it happens with fraudulent SIM swaps.
A better play might be to liaise with phone repair shops both carrier-owned and independent, since they already do this as a matter of course, and it's quicker if you don't care what damage you do in the process. Lot of cats to herd, though, that would be.
Lithium-ion batteries can be safely shredded. You need to ensure they're discharged and/or shredded in an inert atmosphere [1].
[1] https://www.recovery-worldwide.com/en/artikel/efficient-and-...
Given that most phone these days have non-removable batteries, can one really shred them safely? And wouldn't it make it harder to recycle if you can't isolate the various components?
It's not too difficult to destructively open phones to remove the battery and destroy the motherboard, but that requires some tools and know-how.
My local PC repair shop has a hard-disk destroyer that you can use to destruct your own drives. It's basically a lever-operated vice-crusher with a four-foot lever that you use to close the jaws. As soon as I discovered it I was able to destroy the hard drives that I'd been keeping in a bucket in my garage. The shop keeps the bits and manages the e-waste disposal. Bonus: it gives you an upper-body work-out
Don’t hand in your phone when there is any chance that data can be recovered.
If your phone can boot, wipe it.
If your phone cannot boot, remove the battery and then smash everything else into tiny little pieces with a hammer.
Open phone, snap off the pink, recycle the rest.
Medium value stuff is shredded into a big pile and then they leach the gold off it with cyanide. It has a much higher concentration of gold then raw gold ore.
Low value stuff is shipped to poor countries where the copper is extracted by burning and picking through the ash. Very toxic process.
I don’t trust any carrier to do this honestly or competently. And I don’t have the time to audit their process.
I also don’t care enough to do a secure wipe but would gladly take out the storage card and destroy it. That way I’m certain.
It’s not that it’s not possible. It’s that I don’t think it’s worth the work for a negligible benefit.
Storage encryption, which most modern phones should utilize, also helps.
Although I suspect someone will think it a fun project to sift through old storage devices found in the dump to automatically scan for photos of interest. Given the high interest in pornography, I expect the motivation of “found nudes” will lead to some discoveries no one ever thought possible.
Nobody is getting the data off at my house. I assume nobody will go through the dump looking for old phones, but someone did go through the dump and found the ET cartridges, so there's prescedent. Also, I feel a little bad about putting phones directly in the dump.
If it goes to a carrier program, there's a good chance it goes into a repair process where the battery is replaced and maybe it works again. If it works again, I expect it to get the least intensive wipe required so that the user can get into the home screen, and then sold. That might mean the new user can get access to my data.
Story time: my spouse had an Amazon Fire phone for quite some time; when she was done with it, my dad needed a phone, but FireOS was a really poor choice, so I flashed it with a 3rd party Android build. Several years later, he ran it all the way out of battery, and when he got it charged up, somehow it booted up into FireOS instead and had my spouse's accounts and what not. Whoops. No big deal, we got him a new phone and got the Fire Phone back (and I tried to wipe it again, but better) and now it lives in a drawer and won't power on.
Story time: I was a contractor a few decades ago and I got a “new pc.” Theoretically it was imaged with a developer setup. Reality is the local user accounts were removed and a new account created for me.
The previous user was an HR analyst who kept all their data in c:\employee_salary and didn’t get wiped. So it had layoff analysis of every employee, their salary, their layoff priority. Comically, sadly, the HR analyst was layed off despite being listed as high priority.
I tried reporting the data and my contractor manager squashed it for fear that I would be rolled off the project.
My lesson is that unless I destroy the data, assume others will see it.
Updte: hmm. Not full disk encryption. Does this mean that its up to the app to encrypt?
https://source.android.com/docs/security/features/encryption
Thankfully with Android I can just plug in a mouse! On my Samsung phones I can plug in a full display + mouse. It's a bit of a risk leaving thr gate open like this, but occasionally I've also setup dying phones to auto switch to ADB, so when they do go, I can still access them.
The main barrier I have is that some phones have bad usb micro ports. With that, I'm hosed. Thankfully haven't seen a single usb-c device with a bad port; loving it.
Ideally we should be able to trust on-disk encryption on our phones. Alas with pin codes, there's not enough entropy to do a for real job of encrypting, but it'll ward off casual snooping. I'm honestly not sure when the changeover was where users ought to be able to expect this fundamental builtin protection.
I've had various old phones, laptops speakers etc. that became bloated in storage because an internal lithium ion cell was halfway ruptured.
And once you do that it's usually trivial to pop out and destroy the motherboard or storage device, especially as you don't care about doing so destructively. Then you can recycle the rest.
But yeah, preemptively removing batteries for safety is a good move.
Let's say that you were able to magically disassemble a cellphone battery into its constituent elements and compounds, made rods out of each, and then sealed each rod in a zip-lock bag in a vacuum chamber.
The resulting collection of zip-lock bags is still something you wouldn't want to keep on a shelf somewhere, e.g. https://youtu.be/Vxqe_ZOwsHs shows how elemental lithium reacts.
I have an original iPhone in my drawer. It was decent 15 years ago, but not safe now.
AFAIK Android has always used dm-crypt (should be familiar to any Linux user) with AES, which I'm pretty sure is still safe.
Back then I think maybe it used CBC mode, whereas now it defaults to XTR, but again AFAIK, CBC is still safe, it's just that XTR performs better for block devices or something.
Someone please correct me if I'm wrong.
The purpose of encryption is not to keep secrets eternally. The purpose of it is to keep secrets long enough that by the time they're revealed, they aren't worth anything.
I can maybe see someone repairing phones to boot them and grab unencrypted data. But no one is holding on to them for 20 years to decrypt them.
I think that’s what concerns people. And makes random phones of interest to bored people. A decent percent of phones probably have nudes. And I think that data stays sensitive.
- Charge to ~.25%
- Phone automatically powers on
- The boot process takes more power than the charger can provide, so it drains the battery
- Automatically powers off because battery is back to 0%
I've had them on the charger for a few hours and watched this process repeat over and over. Short of disassembling and swapping the batteries I've tried everything I can think of to get them to power up
- booting into recovery -- find out which key combo might trigger that at power-on
- booting into an OEM download mode -- "" - probably a cable insert + key combo
- triggering the Qualcomm download mode -- ""
That would load a different boot setup (maybe kernel, or just ramdisk, and whatever tools they added on top from that particular OEM), and that may allow you to charge. That can work sometimes.
Apart from slowing down ever so slightly the oncoming scarcity of resources.
A. Make a stronger password, time to crack it increases exponentially.
B. Change password regularly, including after getting new equipment.
The user response is to choose a new password that is similar to the previous password to avoid loosing access due to forgetting. This means that an attackers best way to find the users current password, is to know their old password. NIST has recognized this, and advises against these policies: “Reset—Required only if the password is compromised or forgotten.” [1].
Best mitigation I see for systems that exclusively take password input is to use a user pin plus a PKI card or RSA key.
[1] https://www.isaca.org/resources/isaca-journal/issues/2019/vo...
Mathematically, imagine it is raining (stochastically speaking, evenly distributed on the interval, with replacement). Are you more or less likely to get hit by a rain drop if you dance around or stand still? Nope, odds are the same. (Although technically by moving around a lot you are sweeping space and thereby increasing the surface area for rain to impact + amount of rain, so actually you are increasing the odds.)
Ok, try this instead. Flip a coin and guess whether it's heads or tails. Does it matter whether I guess heads every time, alternate heads/tails, or flip another coin? No, it does not.
Now in the case of people who re-use passwords... in the longer term we'll find out whether the propensity to be one or the other produces an evolutionary signal or whether people are impossibly bad at "random" in any case.
Finally, imagine someone cracking passwords: this is your adversary, and there is only one. Are they going to start with the hardest, most difficult to compute / type / memorize / come up with in the first place passwords? Let's encourage them to do that, and start with passwords which you'd never be able to enumerate starting from null before the heat death of the universe. Ok, so maybe that won't work, they're going to start with the easy ones first. So in this case, the optimal strategy would be to pick a really difficult password, and then at some point in time switch to one of the easy ones since it's already been checked.
How's your migraine now?
(ssa.gov generates printable one-time pads if you're masochistic enough to request one.)
Same would actually be useful with the screens, just have a few standardized physical rectangular screen sizes and make them swappable between phones so if one breaks you can re-use the one from your previous phone... (supporting different resolutions should be trivial for the OS)
I wish these batteries could just slide in and out of an electric car so you’re not having batteries sit around doing nothing.
Maybe usb-d can solve all this!
Of course, now that nobody wants to make a reasonable phone with a removable back, it's not that helpful. One hopes the EU regulations push us back on course.
Eg higher resolution screens that are being experimented on for VR but need a market to support.
A standard sized battery would also affect on the screen sizes to choose from for designers.
I am absolutely grateful that my plumbing and electrical fittings are standardized. I'm grateful that most (old-school) electrical devices use the same four kinds of batteries, and get really frustrated at the coin-batteries that come in 20 something different sizes, because I almost never have the right size around. And I'm grateful that we charge almost all of our devices by a small number of USB connectors. Because standardization is also a boon to innovation, or rather, a lack of standardization can get in the way of innovating, especially at the level of interoperating services and hardware.
Look at PC monitors: you can attach all kinds of monitors with different resolutions to PC's, and there exist some pretty exotic ones with eye trackers etc... too, and of course also various VR headsets can be connected too.
- A clear benefit from turning the device in (money, phone will be used to build electric cars).
- A clear instructions on how to do a factory reset on all devices to promote data privacy
- A consistent, well advertised, clearly marked place to turn devices in
- confidence that turning in the device will lead to the outcomes advertised. If you advertise money, and consumers end up getting a rebate form for a check that never come in the mail, or if they see a news report that their phones were thrown in the garbage and not actually recycled, no one will turn in their phone again.
This should be unnecessary and is likely a large part of why people don't. There are loads of reasons it is not possible to wipe a device. I have one which reboots before any point it will accept input.
Sometimes this triggers a chain reaction where the person I gifted the phone ends up gifting the phone they're replacing to someone else (usually someone switching from Android, or someone with an even older iPhone).
Technically each pass down of the used phone is causing another phone to come out of service (and/or gifted again), but from an environmental standpoint this helps reduce demand for new phones since the people who received the gifted phones probably won't buy a new one for at least a couple additional years.
By the time I replace my backup phone with my new old phone the battery is long gone and I'd get nothing if I sell it.
So yes, phones continue to accumulate in my drawer.
Of course it's a bit more involved for a device that wasn't intended to have a user-replaceable battery, but it's almost always possible.
Alternatively, even with a dead battery, you can probably plug it into the wall to boot it up and wipe all your data, and then sell it for maybe $30 to $40 on eBay. There's lots of folks out there who will buy phones cheap and either refurbish them themselves, or else just use them tethered for software development, IoT projects, etc.
I don't think there was much left of the original by then...
(and, if I'm reading that correctly, all those disposable vapes that should not be in landfill)
(lithium battery explosions are a lot rarer than accidental cigarette/clothing/hair fires used to be)
iPhones are very long lasting devices, pretty useful even after many years but would have been even better if Apple let you unlock these things. Facetime can autoanswer only on the selfie camera and I would prefer a solution which would do this on the main camera but unfortunately that's not possible under current access level to the device.
It can be more useful to re-purpose those device instead of mining them for metals?
This guy made a 4k projector out of one. Particularly intriguing is that he hardwired power, replacing the battery - doesn't seem _that_ hard.
https://www.youtube.com/watch?v=YfvTjQ9MCwY
The OS/software side is messiest side for me. Obviously running an old Android that's connected to the internet is potentially a bad idea, but the install of open source backfill replacements isn't great either. I've bricked phones in the past following (fairly complex) instructions carefully, and the need to trust 3rd party binary builds and/or tools isn't fantastic. If Right To Repair can mandate that phones be open enough to easily replace the firmware (sufficiently easy so that, say, your Mom could do it) then maybe reuse of phones becomes a more viable proposition.
Reduces the impact of my main phone being stolen/lost whilst on the road.
Pull the chips and the device is safe to recycle.
We are surrounded by fairly powerful general-purpose aarch64 computers that are rendered useless by draconian userspace barriers.
https://boinc.berkeley.edu/download_all.php?platform=android
But the question is how much.
There is literally no way that it is worth it at $1 of gold per phone. Not even close.