A Phone That Lies for You: An Android Hack Allows Users to Put Decoy Data on a Smartphone

An Android hack allows users to put decoy data on a smartphone

Join Our Community of Science Lovers!

Local police confiscate a suspected drug dealer's phone—only to find that he has called his mother and no one else. Meanwhile a journalist's phone is examined by airport security. But when officials look to see what is on it, they find that she has spent all her time at the beach. The drug dealer and the journalist are free to go. Minutes later the names, numbers and GPS data that the police were looking for reappear.

A new programming technique could bring these scenarios to life. Computer scientist Karl-Johan Karlsson has reprogrammed a phone to lie. By modifying the operating system of an Android-based smartphone, he was able to put decoy data on it—innocent numbers, for example—so that the real data escape forensics. He presented the hack in January at the Hawaii International Conference on System Sciences.

Karlsson tested his hack on two forensics tools commonly used by police departments. Both can retrieve call logs, location data and even passwords. When he ran his modified system, the tools picked up the false information that he programmed into the phone and missed the real contents.


On supporting science journalism

If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.


Even though his hack was successful, Karlsson says it is not going to stop a sophisticated analysis by the FBI or the NSA. Such a hack, however, could make it difficult to try some criminal cases. A phone that tells two stories complicates things.

Mikko Hypponen, a prominent computer-security expert, says Karlsson's modification is another stage in the arms race among spies, law enforcement and users. It also highlights the effort to find ways to protect legitimate needs for privacy. “This kind of tool,” he says, “can be used for good or bad.”

It’s Time to Stand Up for Science

If you enjoyed this article, I’d like to ask for your support. Scientific American has served as an advocate for science and industry for 180 years, and right now may be the most critical moment in that two-century history.

I’ve been a Scientific American subscriber since I was 12 years old, and it helped shape the way I look at the world. SciAm always educates and delights me, and inspires a sense of awe for our vast, beautiful universe. I hope it does that for you, too.

If you subscribe to Scientific American, you help ensure that our coverage is centered on meaningful research and discovery; that we have the resources to report on the decisions that threaten labs across the U.S.; and that we support both budding and working scientists at a time when the value of science itself too often goes unrecognized.

In return, you get essential news, captivating podcasts, brilliant infographics, can't-miss newsletters, must-watch videos, challenging games, and the science world's best writing and reporting. You can even gift someone a subscription.

There has never been a more important time for us to stand up and show why science matters. I hope you’ll support us in that mission.

Thank you,

David M. Ewalt, Editor in Chief, Scientific American

Subscribe