Safe to sell used Android-phone without doing factory reset

I’ve got an Android One-unit with Android 10. However it refuses to boot and I’ve decided to get rid of it and I think I get get some money by selling a broken phone online. However since it refuses to boot I can not perform a factory reset or similair procedures. Is is safe to sell it or can personal data get in the wrong hands?

Some information:

  • I have not changed the encryption settings, so I think it’s encrypted by default
  • I got two factor authentication turned on on my Google account and removed the device from my “trusted devices”
  • I have screen-lock turned on with pattern needed to unlock it.

Can I sell a supplement that references non-SRD Cleric Domains?

I am creating a completely unique setting for Dungeons & Dragons 5th Edition, and really pouring my heart and soul into it. Under Wizards of the Coast’s OGL (Open Gaming License), I am hoping to sell this setting as a supplement book (probably a downloadable PDF through DriveThruRPG).

However, I’m a little bit fuzzy on the differences between the OGL, and the SRD, and what I’m allowed to use vs. what I’m not in the context of a commercial product. Specifically, I was thinking of referencing some non-SRD cleric domains (the only SRD cleric domain, as far as I know, is Life), such as, say, the ones from the Player’s Handbook, in the context of locations that are tied to particular Domains. Would that be permissible? I don’t know if I’m allowed to use non-SRD domains in a commercial work. I wouldn’t be reproducing the actual Domains, in their specific mechanics, just referencing their existence.

Can I safely sell a used keyboard without risk of new owner recovering previous inputs?

As far as of my knowledge goes, keyboard don’t store keystrokes in their memory by default (excluding those bundled with keyloggers). The thing that comes to my mind though is that some keyboards do have some built-in memory for storing user’s preferences (e.g. gaming keyboards). Can this be somehow reprogrammed to store other data than just LEDs color combo?

Can I sell my keyboard without worrying that new owner might recover previous input in some way?

Cheers, Dominic

Can I sell starting gear in Adventurers League play?

I’m starting a new AL game (as a player) and I have a question that’s not addressed in the AL material.

According to Adventurers League Player’s Guide (page 4)

When you create your D&D Adventurers League character for the current season, take starting equipment as determined by your class and background. You cannot roll for your starting wealth.

Meaning I can’t start with whatever I want. However, I am playing a ranged-focused fighter, so the second gear option is of no use to me:

  • (a) a martial weapon and a shield or (b) two martial weapons

Can I choose any two martial weapons and sell them for half price to use for purchasing other gear before play? And is there a restriction on how much gold I can get?

For example, two hand crossbows (martial ranged weapons) can net me 75 gp when sold, or two greatswords nets me 50 gp when sold.

How do I sell critical vulnerability info to private company?

Here is the story. There is a private company, that has some software product that is used by thousands of its customers. After spending few sleepless nights on reverse engineering that product, I identified a critical flaw in it. The reason I explored this product was pure sport – reverse engineering is my hobby and nothing more.

But during my exploration I identified a very serious flaw that I did not expect. Exploiting it will mean extracting big money from the users of that software (customers of the company).

Now I’m not going to exercise that idea to steal money from other people, that’s way beyond my moral principles. Though somebody not really bound with such principles could make “big” money, permanently (for months or years), without trace.

I think it makes sense to mention, that this is the company that makes money when its customers lose money, basically. Imagine financial trading, money lending, gambling, etc. that type of industry. So nobody really “loves” them (incl. their customers), and they know it, and they’re ok with it.

I think it would be fair, that I could sell this vulnerability info to the company for a large sum, but I’m not sure how (if at all) this can be done. Just revealing the exploit to the public, even proving (without revealing the details) that such a vulnerability exists (and has always been existing!) would be a HUGE blow to the company, as they will probably lose big portion of the customers. Nevertheless, (and even considering that company makes millions of dollars per annum) I’m almost sure they won’t be willing to pay me anything unless I provide 100% proof.

The dilemma is – how to explain them the magnitude of that vulnerability, without disclosing hints about where to search for it. If I disclose the software product, and what kind of action contains what kind of vulnerability, I’m pretty sure they will try to investigate the particular possibility in a particular use-case, and eventually find the vulnerability themselves. On the other hand, if I’ll be vague (“I found something in one of your products, that can be used to steal money from your customers”), I’m pretty sure they won’t believe and won’t pay anything.

If I disclose the info to them without demanding anything, i.e. for a bona fide reward, I’m sure they won’t issue any reward. They’re just that kind of company – they don’t care about bona fide security researchers. They will fix it even without replying with a “thank you” mail.

Any kind of advice will be greatly appreciated. Is it not fair to expect some sort of payment from the company in such a situation? I’ve never dealt with such a situation before (as I mentioned, RCE is just a hobby for me).


“If you can prove it and they still will not pay, what will you do? The answer to that will determine if this is blackmail.”

I will not, under any circumstances:

  • Use the exploit myself to benefit.
  • Reveal the vulnerability details to the public (without giving opportunity to the company to fix it), so that other people can exploit it.

What I could do (and I’m still not sure whether this is a good or bad thing), is to tell public about the mere existence of such a vulnerability. Something like a video demonstrating that such thing is doable. As I mentioned, such an action would result in company losing many customers, but if they do not bother to care, if they say “we don’t want to pay for that info”, would it be morally wrong or right thing to do?

I don’t care about the company. They make millions by exploiting their customers, so they don’t deserve any respect from me. I did some work (spent some significant hours), and if the company wants to benefit from my work, it makes sense for them to pay for it, doesn’t it? OTOH, you might say that I have responsibility about their customers to warn/protect them, but I fail to understand why I am obliged to do it for free(?) I.e. even doctors don’t cure you unless they get paid, right? Medicine for cancer treatment cost big money, because somebody spent their life researching it and now demands/deserves to be paid. In this light, I don’t understand why some comments are hinting I should do this for free. Could you please elaborate, am I really wrong to seek financial benefit for my work?