Broken State of Android Encryption

Thai

Elite Member
Link: Android?s full-disk encryption just got much weaker?here?s why | Ars Technica

Privacy advocates take note: Android's full-disk encryption just got dramatically easier to defeat on devices that use chips from semiconductor maker Qualcomm, thanks to new research that reveals several methods to extract crypto keys off of a locked handset.

A blog post published Thursday revealed that in stark contrast to the iPhone's iOS, Qualcomm-powered Android devices store the disk encryption keys in software. That leaves the keys vulnerable to a variety of attacks that can pull a key off a device. From there, the key can be loaded onto a server cluster, field-programmable gate array, or supercomputer that has been optimized for super-fast password cracking.

Since the key resides in software, it likely can be extracted using other vulnerabilities that have yet to be made public. Beyond hacks, Beniamini said the design makes it possible for phone manufacturers to assist law enforcement agencies in unlocking an encrypted device. Since the key is available to TrustZone, the hardware makers can simply create and sign a TrustZone image that extracts what are known as the keymaster keys. Those keys can then be flashed to the target device.

"That's significantly different than how iOS works," Dan Guido, an expert in mobile device encryption and the founder and CEO of security consultancy Trail of Bits, told Ars. "What it means is that now you trust a second party, you trust somebody who built the software that holds the key. Maybe people didn't realize that before, that it's not just Google that can mess around with the software on your phone, but it's also [Google partners], and it's in a very significant way."

"The way Apple builds their phone is they actually build that UID key into the silicon of the device so even if they can push a software update they can never actually extract it from the device short of using an electron microscope or something like that," Green explained. "It sounds like in the Qualcomm TrustZone, that's not true."

According to a comment left in response to Thursday's blog post, the lead developer of the freely available Hashcat password-cracking program is exploring the possibility of building in support for extracted disk-encryption keys. This would streamline attacks once a key has been extracted.
 
Register to hide this ad
Here is the BAD part: Android full-disk encryption can be hacked | BGR

t appears that millions of Android devices are still vulnerable. Qualcomm and Google have patched the issue with updates in May and January, but many users haven’t yet received the patch.

Even once the fix is installed, the patches will not offer full protection. “If an attacker can obtain the encrypted disk image (e.g. by using forensic tools), they can then ‘downgrade’ the device to a vulnerable version, extract the key by exploiting TrustZone, and use them to brute-force the encryption,” the researcher said. “Since the key is derived directly from the SHK, and the SHK cannot be modified, this renders all down-gradable devices directly vulnerable.”
 
Link: Here?s what Apple thinks about the black market for $1 million iPhone hacks - Business Insider Nordic

The U.S. government paid a steep price to hackers earlier this year to help it break into an iPhone used by on of the San Bernardino shooters.

The most recent credible report pegs the price the government paid at "under $1 million," but comments by FBI director James Comey peg the price as being at least $1.3 million.

(NOTE by me: THIS $1.3 million hack does NOT work on iPhone 5s and later with Secure Enclave.)

It turns out, Apple likes the fact that the prices for iPhone hacks are high - because it means they're rare and difficult to pull off.

"As probably most of you know, there is a black market for software vulnerabilities, and once in a while some of the prices on the black market become known," Krstić said. "Usually these prices are tens of thousands of dollars, sometimes $100,000."

Those are prices for software like Microsoft Windows or Google's Android - but the prices for iPhone hacks are much, much higher.

More recently, Forbes reported that the going rate for an iOS hack was $1 million.

"Take that with a grain of salt, but it's a fascinating number to think about," Krstić said. "What you're seeing now is the result of a decade of our best work in protecting our users."

During Krstić's talk, he emphasized how many hacks require malicious actors to string together 5 to 10 separate bugs, partially because Apple strives to "build security into every level," from its chips to its software.

In April, Apple said that it has "the most effective security organization in the world," and during Krstić's talk, he bragged that the iPhone hasn't had a virus or malware problem at scale over the past nine years.
 
Last edited:
The iphone been backdoored since its creation. Even though android is buggy, id still prefer it over an iphone.

Dropoutjeep%20Original.jpg
 
The iphone been backdoored since its creation. Even though android is buggy, id still prefer it over an iphone.]

Uh no. Your posted "hack" worked back in 2008...basically jail breaking an iPhone. This was closed long time ago AND would not work now.

Android security is not buggy, it is broken at the core.

Read up on hardware encryption and why Apple services have end-to-end encryption.

And just out of curiosity,why would government spend $1.3 million given to a 3rd party to crack an iPhone 5c if your posted hack worked?! Lol.
 
Last edited:
I'm a fan of Apple products, but I gotta say, those articles sound like they were written by Apple's PR department.
 

Members online

Forum statistics

Threads
278,307
Messages
3,554,050
Members
248,016
Latest member
Advally Service

Trending content

Back
Top