Android Full Disk Encryption Cold Boot Attack (2012)
www1.informatik.uni-erlangen.de
www1.informatik.uni-erlangen.de
I did a search on the Internet Archive and see caches of this page going back at least as far as 2013:
https://web.archive.org/web/20130115000000*/https://www1.inf...
You may want to update the submission with a year.
The paper is really nice and readable. TL;DR: Freezing the phone makes the RAM static and not clear on reboot, giving you time to sideload their custom recovery image that iterates the ram and looks for AES encryption key patterns.
Actual freezing. Like, putting the phone in a freezer to create sub-zero temperatures.
Under many circumstances, the attack worked at room temperature; one main reason for using low temperatures was if you needed to physically move the RAM chips from one machine to another.
from https://www1.informatik.uni-erlangen.de/filepool/projects/fr...
> The remanence effect says that RAM contents fade away gradually over time, as slower as colder the RAM chips are.
And also on more recent Android devices you cannot even perform an unlock of the bootoader without knowing the device PIN. Try it on a nexus 5x/6p/9.
> Once the smartphone is up again, the risk of loosing RAM contents is defeated. Flashing the recovery image does not destroy important RAM lines according to our tests.
I'd assume, encrypted or not, physical access to a phone with an unlocked bootloader means it's owned.
In practical terms, the only people who would ever unlock their bootloaders are those who wish to perform modifications (ie. rooting and customs ROMs), and they typically accept a somewhat lessened amount of security anyway.
A locked bootloader is an essential line of defense.
Fun fact: This is why during raids against cyber criminals reports claim they often dive for their computer to try and turn it off before being restrained. Police can do the same thing with liquid nitrogen and a desktop machine.
I'd bet that most people that think they are in this risk category do not have strong enough security practices to prevent data from being cracked by other means.
Thermite, even the more explosive copper-based variant, is pretty poor at destroying disk platters, sadly. Explosives or cutting equipment seem to be better, although the magnitude of the engineering challenge obviously increases.
Here's an alternate idea: rather than messing around with chemical explosives, how about filling the computer with poisonous snakes?
You can easily get a user to install some app that has all kinds of permissions, including all their contacts, camera, mic, current and past call history, phone number, etc. They wouldn't bat an eye.
This is more worrying for a professional locked down corporate device full of sensitive data or trade secrets. For example, I work in health studies - my worry would be patient info getting into the wrong hands.
Android could do a simpler version by unconditionally clearing RAM on boot in the bootloader.