3 ms·
I'd be much more interested in this attack if they could get the keys from a phone with a locked bootloader. I'd assume, encrypted or not, physical access to a
by blakes 11y ago
I'd be much more interested in this attack if they could get the keys from a phone with a locked bootloader.
I'd assume, encrypted or not, physical access to a phone with an unlocked bootloader means it's owned.
- dacox 11y agoDoes android by default lock the bootloader when encryption is enabled?
- stormcloud 11y agoThe bootloader is locked by default on most (maybe all?) android phones, so unless the user has explicitly unlocked it, they'll be safe
- Orangeair 11y agoMost recent phones lock the bootloader by default, regardless of whether or not decryption is enabled. Some phones, such as the Nexus series, allow it to be unlocked relatively easily. Others, such as those made by Motorola, require the user to go online and get a unique unlock code for their device. And some, such as LG, don't allow the bootloader to be unlocked at all. In practical terms, the only people who would ever unlock their bootloaders are those who wish to perform modifications (ie. rooting and customs ROMs), and they typically accept a somewhat lessened amount of security anyway.
- awqrre 11y agoLocked bootloader should not have anything to do with encrypted user data being accessible or not... With a locked bootloader on Android devices, it can be difficult to flash a Custom ROM but your password won't help in that case... your password/pin should be used to decrypt your data.
- stormcloud 11y agoIt does, because they can't retrieve the keys from memory otherwise - Unlocking the bootloader is essentially opening the phone up to malicious code execution by anyone with physical access.
- gherkin0 11y agoIt would be more difficult and model-specific, but couldn't they attach a device to read the RAM chips directly? To perform this on most modern phones, they have to disassemble it anyway to be able to toggle the power quickly enough (since there's no user-replaceable battery).
- baobrien 11y agoThey probably wouldn't be able to attach anything to the ram directly, as the ram chips on modern phones are soldered down BGAs. To get at the pins, they'd have to de-solder them, which would heat up the chips in the process. It might be possible to get at the ram over JTAG or some other debug bus in some devices, though.
- prutschman 11y agoThis is probably in the realm of "if you're subject to this level of attack you have bigger problems", but, I wonder if it would be possible to laser drill after-the-fact micro vias through the PCB to get at all the BGA pads with absurdly small probes.
- blakes 11y agoYour right, it doesn't have anything to do with user data being accessible, but an unlocked bootloader will mean the barrier to finding a vulnerability is much lower than otherwise. A locked bootloader is an essential line of defense.
- spiznnx 11y agoUnlocking the bootloader - a prequisite for loading the ram dumping software - causes the data partitions and cache to be wiped. This might not clear the keys from ram, but now the attacker has to find a way to dump the data from flash before unlocking the bootloader for the keys to be of use.
- asuffield 11y agoThere are a couple more dimensions on recent (more recent than this article) models running M. There's a TEE (~android TPM equivalent) chip involved in encrypting user data, it knows whether your bootloader is locked or not, and it will not yield the keys to locked user data when running in unlocked mode.
- deleted 11y ago[deleted]