Amazon confirms it has dropped device encryption support for its Fire Tablets
techcrunch.com
techcrunch.com
Full disk encryption doesn't protect you against most 'normal' security attacks like privilege escalation, because once an attacker has gained that privilege they can read any data off the mounted encrypted file-system.
The way FDE works is that you're encrypting the blocks stored on the physical storage eMMC[1], so if someone gets their hands on your device and physically tampers with it, in theory, with enough skill and fiddly soldering and wiring to an SD card adapter you could access the data.
However, many SoCs stack the eMMC on top of the application processor directly, look up package on package or "POP". This means you can't even access any pins to wire up an adapter without "extremely" specialized equipment. We're talking about slicing a layer off the chip package without damaging it.
[1]I've left out physical SDcards because until recently there was no facility to encrypt you data in a cross platform compatible way on these devices. Android treats SDcards as plain unencryted FAT/exFAT storage by default anyway.
It can be hard to gauge public opinion from the HN echo chamber, but the apple case is causing national awareness of this important issue. The real question is: will consumers make decisions in the next 6, 12, 24 months based on the information they hear about these devices? I'd like to say yes, but i suspect the answer is no.
Tell me where encryption fits into that use case.
With security features it's probably better to drop them rather than implement them poorly.
As someone else said, this is probably becauase their hardware is somewhat lacklustre (it's a $50 tablet, after all) and therefore the performance hit was hurting the end user experience to an unacceptable level.
I think GPs is opining on user attitudes more than they are saying anything about what they should be able to do with their tablets.
If people buying $50 tablets don't care about FDE, it not being available isn't going to have much impact in the market.
Sure, it's preventable, and it was my own stupid fault, but I bet it happens to a lot of people and it caused them, and Amazon, more heartache than the added level of 'security' encryption would provide. "What do you mean, you can't retrieve my data? You made this thing! Can't you reset the password?"
Making a device more secure when it's off has marginal utility to most customers that aren't on hacker news. And those customers probably don't outweigh the support issues associated with FDE for everyone.
https://news.ycombinator.com/item?id=11223185 http://www.thelocal.fr/20160304/french-mps-back-fines-for-ap...
> French parliamentary deputies, defying government wishes, on Thursday voted in favour of penalising smartphone makers who fail to cooperate in terrorism inquiries
I think it's TechCrunch that's being disingenuous here. Disk encryption is a feature, and has performance, maintenance and UX costs, unlike allowing strong passwords.
People unfamiliar with full-device encryption on Android devices need to be aware of the following: until Marshmallow, it was SLOW. It was so bad that while Google recommended turning on encryption by default on Lollipop, they had to back off of the recommendation because full-disk encryption made the devices run like crap. [0] The reason suspected for this is that up to and including Lollipop, Android handsets did not support hardware-backed encryption/decryption, which meant it all had to be done in software.[1] This had the end result of putting huge overhead onto the device once FDE was turned on, and over time its performance would continue to degrade. Anecdotally, I tried encrypting my HTC One M7 a few years ago when it was my daily driver, and I eventually I had to factory wipe the damn thing to turn it off. The overhead with encryption on got so bad that I would periodically turn on the screen, and it would take so long for the phone to respond that the auto-idle would turn the screen back off before I was even presented with a lockscreen!
The M7's specs were top shelf in 2013. Given the limited specs of Amazon's cheaper tablets, I would not be surprised if encrypting them could slow them down further to the point of being unusable.
[0] http://www.androidpolice.com/2014/11/20/anandtech-posts-side... [1] http://www.androidpolice.com/2014/11/20/anandtech-posts-side....
EDIT: Removed the aside, since I was mistaken that the Kindle reader OS's were affected.
According to the Android team, it's actually even faster to do it in software, at least with the SoC that the Nexus 5x and Nexus 6p use: http://www.androidpolice.com/2015/09/30/the-nexus-5x-and-6p-...
Comparison: https://browser.primatelabs.com/geekbench3/compare/3839281?b...
Amazon controls everything in their ecosystem. They could make the hardware to go with the software.
The only reason I agree with you is that, if the hardware is the problem.. then why not just say that?
Then this begs the hypothetical question, 'If even only one person used encryption out of all of the devices sold, is it a feature worth keeping?'
I think most people here would say 'yes'.. but would most average company executives?
It's one thing to say, we don't support this going forward so if it's something you use get a different device next time. It's another to say, we are disabling or bricking, your choice.
Any idea what HW is in the cheap Kindle tablet?
http://www.blog.fictiv.com/posts/50-kindle-fire-teardown
* Samsung KLM8G1GEND-B031 - data storage chip
* Mediatek ARM Mt8127A - SoC (system on chip)
* Mediatek MT6323LGA - integrated circuit
Kindle Fire tablets aren't really a 'book reader' any more than an iPad is a 'book reader' (perhaps you're thinking of the eInk versions of the Kindle, such as the Kindle Paperwhite). Kindle Fire tablets can be used for anything a standard tablet would be, so to answer your question... Any web browsing or email content you'd rather not share with the government or hackers.
That said, I used FDE on my Moto X 2014 with Lollipop and it worked without any problems or noticeable slowdowns. But typically Kindle has far more low-end hardware.
This isn't true of all android, just the N6 which was having issues with not having hardware acceleration enabled.
If OEMs want fast crypto they have to do what everyone else does: use methods that work with hardware acceleration and put that hardware in the devices.
http://www.androidpolice.com/2014/11/20/anandtech-posts-side...
I believe the 5.1 update fixed the QCE issue.
Maybe I was lucky and both phones support hardware acceleration for the relevant crypto primitives.
/b
I tried to use it as an android tablet, I was able to come up with most of the apps needed but in the end it was little things like lack of configuration that just made it useless to me. Not being able to change the keyboard and such.
Now it's only used by my daughter for content and solarium mobile.