Overcoming Android’s Full Disk Encryption Vulnerabilities for Better Application Security

As we know – thanks to Apple’s battle with the FBI over unlocking phones – iPhones running iOS 8 and above automatically enable Full Disk Encryption (FDE) using an encryption key derived from the user’s password. This ultimately means that even Apple cannot gain access to customers’ phones and the data stored within. This is not the case with many of Google’s Android phones. Android smartphones powered by Qualcomm chips store the disk encryption keys in software, leaving them particularly vulnerable to attacks designed to gain access to the device’s keys. A recent Ars Technica article – Android’s full-disk encryption just got much weaker – here’s why – summarized this encryption flaw:

Privacy advocates take note: Android’s full-disk encryption just got dramatically easier to defeat on devices that use chips from semiconductor maker Qualcomm, thanks to new research that reveals several methods to extract crypto keys off of a locked handset. Those methods include publicly available attack code that works against an estimated 37 percent of enterprise users.

