Show HN: How I bypassed Exchange security on Android
I was messing around with AOSPA, wanted to figure out a way to bypass the encryption requirement to get exchange mails.
Initially I thought I would have to modify the Email app or the part where the OS the administrative provisioning.
But as it turns out all I had to do was comment out 8 lines of code
private int getEncryptionStatus() {
/*String status = SystemProperties.get("ro.crypto.state", "unsupported");
if ("encrypted".equalsIgnoreCase(status)) {
return DevicePolicyManager.ENCRYPTION_STATUS_ACTIVE;
} else if ("unencrypted".equalsIgnoreCase(status)) {
return DevicePolicyManager.ENCRYPTION_STATUS_INACTIVE;
} else {
return DevicePolicyManager.ENCRYPTION_STATUS_UNSUPPORTED;
}*/
return DevicePolicyManager.ENCRYPTION_STATUS_ACTIVE;
}
So now the OS always thinks that its encrypted, and it doesn't ask for the encryption password on boot as that is done by a separate module.Source - https://android.googlesource.com/platform/frameworks/base/+/master/services/java/com/android/server/DevicePolicyManagerService.java Line 2592