Skip to content

Comment on Cellebrite claims it can unlock any iPhone, many new Android phones for policeparent

Comments

What's the difference? Why are phones such a security nightmare? At least in terms of encryption at rest on a cold device, isn't this a solved problem?

One horribly annoying decision of Android is that the encryption passphrase cannot be different from the unlock pin, leaving users with two choices:

- Have a long, secure password that actually makes Android's encryption worth a damn. They then have to enter this password every time they want to unlock their phone. I don't think many people go for this option.

- Have a short usable password so you can painlessly unlock your phone. However, then encryption only provides a marginal benefit

(- I decided to use a long password with fingerprint unlock as a compromise, which creates its own security problems.)

It seems that they ignore that a powered off devices could easily provide much stronger protection by allowing a separate encryption password. And if the device is powered on, limiting unlock attempts might be somewhat useful to frustrate attacks against short lock screen passwords.

You are only forced to enter your passphrase when you turn on the mobile and once every X days. The rest of the time you can use your fingerprint to unlock the mobile. Seems like a good compromise.

True, except that fingerprint sensors can often be fooled and you cannot change your fingerprint once it becomes "compromised". For instance, anyone who ever visited the US, at least as a non-citizen, will have given their fingerprints to CBP.

I think this only works for an attacker model that excludes reasonably sophisticated attackers. I expect this to thwart pickpockets or muggers, but not the police or anyone more sophisticated than that.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.