Android's full-disk encryption just got much weaker--h ere’s why

Android's full-disk encryption just got much weaker--here's why

Privacy advocates take note: Android's full-disk encryption just got dramatically easier to defeat on devices that use chips from semiconductor maker Qualcomm, thanks to new research that reveals several methods to extract crypto keys off of a locked handset. Those methods include publicly available attack code that works against an estimated 37 percent of enterprise users.

A blog post published Thursday revealed that in stark contrast to the iPhone's iOS, Qualcomm-powered Android devices store the disk encryption keys in software. That leaves the keys vulnerable to a variety of attacks that can pull a key off a device. From there, the key can be loaded onto a server cluster, field-programmable gate array, or supercomputer that has been optimized for super-fast password cracking.

formatting link
t-much-weaker-heres-why/

read more and respond »

Posted 5 years ago by Monty Solomon in General Telecommunications Forum

Report misuse

Image for Android's full-disk encryption just got much weaker--h ere’s why