3 ms·
I wonder if they can crack devices that haven't been booted. Many of the newer smartphones encrypt data and require a password on boot.
by libeclipse 10y ago
I wonder if they can crack devices that haven't been booted. Many of the newer smartphones encrypt data and require a password on boot.
- cxseven 10y agoToo bad Google made the boot password the same as the screen unlock password. Since virtually everyone wants to be able to quickly unlock their phone, this makes security a Hobson's choice.
- libeclipse 10y agoYeah I can see that being the case for the vast majority of users. Also it's a damned shame that Google enforces a limit of 16 characters for the password. My own password is a random 16 character string.
- ThatGeoGuy 10y agoFortunately the community has addressed both these claims, although you need root to set it up (you can remove after). An app on F-droid known as "Cryptfs Password" can change the encryption password separately from your screen unlock password. It also bypasses the 16 character limit, as the encryption key I used on my last phone was 27 characters. At the end of the day Android encryption runs using dm-crypt, so the same sort of rules apply. The 16 character limit is a UI limitation, and there's no technical reason for it. * Note: I fully acknowledge that Google needs to do better here, as I would never assume a normal user could root + install Cryptfs password + unroot after, but at least for those of us who can, we can do something in the meantime.
- golergka 10y agoWell otherwise the user will most likely forget the separate boot password as phones typically get rebooted once a month or so.
- cxseven 10y agoForcing boot passwords to be the same as what unlocks the screen guarantees that they're so weak that they might as well not exist. Meanwhile, users who want real security are fucked. The same kind of boneheaded removal of features in the name of simplicity is behind Android Pay requiring your phone to have a locked screen -- because that supposedly solves the problem that used to exist of users having to enter a PIN twice when they'd unlock the screen and then unlock Android Pay.
- andrewpi 10y agoFingerprint readers seem to solve that problem. Booting the phone requires the secure password, but after that a fingerprint will suffice until the phone is powered off or left locked for 24 hours.
- bobbob1 10y agoForensics have pretty strict rules. One of the assumptions and limitations is that the phone will be off. However, they're not that good in all cases. As I mentioned in my original comment, brand new phones , (and usually older versions 1 year old ones), would suffice. The worst things Cellebrite tries to keep off hands the "evil" people (those who are already paying them enough money), will get access to the zero-days I referred to in my original reply.