4 ms·
It doesn't really break the encryption, as long as the password is strong enough to prevent brute forcing. Relying on a weak password and a "trusted computing"
by devit 10y ago
It doesn't really break the encryption, as long as the password is strong enough to prevent brute forcing.
Relying on a weak password and a "trusted computing" mechanism like this one from Qualcomm to prevent an attacker with physical access from brute forcing it is not really advisable.
Using such a mechanism at all has downsides since it means that you lose the data if the mechanism or the entire device stops working, while otherwise you could simply move the SSD/flash/storage unit to a new identical device and have it just work as long as you type the correct password.
- lxgr 10y agoBut how many Android users do you know that actually have a strong password? (Speaking of which: Google's decision to not allow strong encryption passwords together with short screen unlock PINs/patterns is not helping here. It's actually possible, but they don't expose the user interface to change them separately, probably for usability reasons.) Also, while I would agree as far as PCs are concerned, moving the eMMC to a new phone's mainboard is probably also not a likely scenario.
- userbinator 10y agomoving the eMMC to a new phone's mainboard is probably also not a likely scenario. Data recovery is, however, which is why I don't think one-sided promotion of ubiquitous hardware-locked-FDE is a good idea --- it becomes a tradeoff between others getting access to, and you losing access to, your data. Is it more important that this data be accessible by no one but you even if it means you might also lose access to it, or that you not lose access, even if it means others can access it? Hardware-locked FDE is suited only to the former case.
- 616c 10y agoAs someone who deals with hardware-backed encryption in laptops, it's a huge pain. Modern phones are worse. I was at a training and happened to sit with computer forensicators and they complain about the new eMMC systems. Forensics systems for mobile devices were a piece of cake prior to that. I suspect the eMMC thing is meant to make this difficult on purpose. So, so much for that ...
- ultramancool 10y agoPrecisely - if you're relying on no one to be able to reverse engineering the "secure enclave", you're already in deep trouble.