Android Encryption Demystified
blog.elcomsoft.com
blog.elcomsoft.com
- Encryption keys are derived from various inputs including the user credentials, not stored in the TEE. The TEE is involved in key derivation and is really supposed to use a hardware-bound key not directly accessible to software including itself but it's an implementation detail that varies by device.
- Pixel phones ship with file-based encryption. It's not an option. A phone either uses FDE or FBE. If it uses FBE, then it supports Direct Boot (partial functionally before the user credentials for encryption are enabled via device-encrypted storage class) and per-profile encryption keys. It enables a bunch of possible improvements like authenticated encryption down the road, but isn't much of a security improvement itself. Nexus 5X and 6P only offered a partial implementation as preview for developers tucked away in the hidden developer options, not a user-facing option.
- Credential-based encryption is enabled by default when setting a lockscreen method.
- Android has a Keystore, that's not exclusive to iOS.
- Android doesn't use ECB even though it's implied that only iOS uses unique keys per block. Android does too.
There's some more, but I don't have time to go through and nitpick. It's clearly written based on interpreting other people's blog posts, etc. rather than direct knowledge of how it works or even reading the documentation. It doesn't even sound like they have experience using an Android device based on some statements they make.
The post totally misses out on things like key derivation and which data is kept at rest. The article misses the real remaining iOS encryption advantages (FBE data classes that Android hasn't added yet and more of the key derivation work is hardware-bound) and just tries to make it sound good by stating things that are not unique to iOS.
1. They're being stiffed by Google and Apple upping their security game, hence the amount of complaints on this blog in the comments
2. Their users all seem dodgy as fuck, it's not even funny.
3. Passwords and 2fa are making their brute force methods completely outdated
Why haven't they shut down yet?
"Completely outdated" you may say - but most people still don't use these things. Most people won't go out of their way to take anything more than the most basic security measures. So that's good enough most of the time for forensic purposes.
Apple's "secure by default" concept sounds like the best practice in theory, but their backups and account tying of devices make it so that there's easy attack vectors for tools like this. In order to fully take advantage, you'd have to have never taken a backup of your iOS device and have all iCloud features disabled. Most people don't do that, most people would rather get their data back if they forget their password than keep them private in an extreme situation - for most people that probably makes sense.
Just because you enabled 2fa doesn't mean you're safe. Apples 2fa was easily bypassed using iCloud restore.
My point is that android encryption has problems if you can just lose the encryption between os version upgrades.
Wasn't a big deal for me, since I just tried to revive that thing anyway. But that seems like a bad idea..