One horribly annoying decision of Android is that the encryption passphrase cannot be different from the unlock pin, leaving users with two choices:
- Have a long, secure password that actually makes Android's encryption worth a damn. They then have to enter this password every time they want to unlock their phone. I don't think many people go for this option.
- Have a short usable password so you can painlessly unlock your phone. However, then encryption only provides a marginal benefit
(- I decided to use a long password with fingerprint unlock as a compromise, which creates its own security problems.)
It seems that they ignore that a powered off devices could easily provide much stronger protection by allowing a separate encryption password. And if the device is powered on, limiting unlock attempts might be somewhat useful to frustrate attacks against short lock screen passwords.