3 ms·
Of course it depends on the phone. Many qualcomm based Android devices seem to have had their Full Disk Encryption scheme broken at the moment [1], for example.
by drvdevd 10y ago
Of course it depends on the phone. Many qualcomm based Android devices seem to have had their Full Disk Encryption scheme broken at the moment [1], for example. But either way, if your disk encryption scheme doesn't fully wipe the disk before use, then any data that ever hit the disk unencrypted could still possibly be sitting there until its physical blocks are consumed (or could be in a cache somewhere). Again this also depends on the hardware, in this case the storage hardware itself. SSDs using TRIM can wipe unused, unencrypted blocks for example in some scenarios. Who knows about the particular functioning of some SD type controller in a phone or even the card's own embedded OS [2].
I would say if you have data on your smartphone you don't want recoverable at rest, take module0000's advice, then also use encryption, and then also use a multi-pass wipe tool on particluar files. Of course all of this could still not work.
For example, I'm not sure what the forensic ramifications of a seemingly more complex filesystem like APFS will be in the near future when it hits iOS.
[1] https://bits-please.blogspot.com/2016/06/extracting-qualcomms-keymaster-keys.html https://bits-please.blogspot.com/2016/06/extracting-qualcomm...
[2] https://www.bunniestudios.com/blog/?p=3554 https://www.bunniestudios.com/blog/?p=3554