3 ms·
Full disk encryption isn't really that much of a big deal for the average user on a lot of modern mobile SoCs. The messaging of this is a lot worse than the sec
by edderly 11y ago
Full disk encryption isn't really that much of a big deal for the average user on a lot of modern mobile SoCs. The messaging of this is a lot worse than the security implication in practice.
Full disk encryption doesn't protect you against most 'normal' security attacks like privilege escalation, because once an attacker has gained that privilege they can read any data off the mounted encrypted file-system.
The way FDE works is that you're encrypting the blocks stored on the physical storage eMMC[1], so if someone gets their hands on your device and physically tampers with it, in theory, with enough skill and fiddly soldering and wiring to an SD card adapter you could access the data.
However, many SoCs stack the eMMC on top of the application processor directly, look up package on package or "POP". This means you can't even access any pins to wire up an adapter without "extremely" specialized equipment. We're talking about slicing a layer off the chip package without damaging it.
[1]I've left out physical SDcards because until recently there was no facility to encrypt you data in a cross platform compatible way on these devices. Android treats SDcards as plain unencryted FAT/exFAT storage by default anyway.