[Q] Why not make more secure recoverys - Android Q&A, Help & Troubleshooting

Well, first i don't know if this is the correct arrea but let's go.
everyday hundreds of people lost your phones, or get stolen sometimes you can get it back, sometimes not.
the first problem is that android is a VERY unsecure platform, and in 1 minute i can shutdown the phone, go to the recovery and make a hard reset, boom, you lost your phone, or just enable USB depuration and go fastboot and do whatever i want.
in iOS 8 it's impossible to a stolen iphone be usable again by a robber, you NEED icloud login, it's a real secure operating system
i am thinking ways that i can make my phone secure, and i have 2 ideias, one is just silly but can work.
the silly idea is put some kind of tape on the contacts of the micro usb input, so when they see my second idea, they will be unable to fastboot, just charge, EDIT: i don't know if there are ways to securely disable usb depuration...
the second idea it just put a PIN password protection in the CWM or TWRP recovery, if you fail 4 times, it gets blocked for xx or erase all data, or whatever.
that's it, and for the phone's security, just another PIN password, and cerberus running .

Related

[Q] Android data security best practices?

The full phone encryption as currently implemented on Android is inconvenient because you have to enter 6+ chars every time you want to unlock your phone.
Since most of the time you want to do something unimportant, it quite kills the usability.
Knox seems to have nice approach to that by splitting the phone into personal and business part, only the later being protected.
However it's inaccessible for non-corporate customers, and still unclear how exactly it works.
So are there any other solution that allow you to protect part of your phone, like encrypt choosen folders only and password/pattern protect specific apps only, while still leave the most of the functionallity of your phone conviniently accessible?
Well, you can always go for a combo... PIN + encryption of files + password protected apps... and cerberus for anti theft (you can always remote wipe and try to recover the mobile after). Of course most security measures are "wiped" soon as the phone is wiped to install a new firmware, but while it isn't... there's a short window to recover your phone.
Seems like there isn't much security apps to more serious issues either...
The biggest issue is that PIN + encryption kills the usability since you have to enter the PIN (6+ chars) every time you want to glance at the phone.

Someone please help, for this Idiot :D

Hey Everyone. I have a extremely annoying and stupid problem with my phone
I have Z5 Premium. What happen is that my phone was always locked with fingerprint and pin number. BUT, for some reason after installing some applications and launchers to try on my phone my locking system sometimes didn't work. Some it lets me just to swipe my finger and I unlocks the phone, without asking for pin... sometimes it asks and sometime it don't, it started to be very annoying so I wanted to check if I change it to password instead of pin if it will be the same. The good news is, it looks like it fixed that problem and the bad news is my phone is so f***ing safe now that I can't even unlock it my self!
I created that password for very temporary time, for some extremely stupid reason I used password which I never used it anywhere else, it was only 4 letters and at that time it looked very easy to type and remember it but I was wrong... I reminded it for 20 mins than I felt a sleep for a short nap and when I woke up, its gone I'm trying to guess that pass and unlock it for 4 straight days now!!
I know I can do hard reset and start again from scratch but I don't want that. I just made all the setups for my phone and everything and I don't want to loose whats in it.
So what options do I have? I found quite few good methods but usually I'm not able to do one of the steps in it..
I tried Google Device Manager method, it didn't work because I already had password not a pin or pattern so it didn't let change pass
The best one I found so far is to flash a script through CWM to remove my pass. The only thing is my phone is stock at the moment and unrooted so I don't have CWM. Another problem is I don't think USB Debugging is enabled on my phone which creates even more problems in my situation I couldn't even get my phone into normal recovery mode when I tried with this phone, anyone know how to do it?
So guys, what options do I have without resting and deleting everything on my phone again?? Please help me, as this thing drives me crazy form 4 days now... I want to smash my phone into wall or my fu****g head because I set that pass up...
Ps. Is it possible to do a android backup on my phone? with looked screen and debugging disabled? but somehow so it doesn't backup my lock screen pass to? I dont think so my self but may be Im wrong..
thanks
I just found another method which I will try now, it could work...
nope, usb debuging needs to be enabled on that method too.. :/
never mind "helpful people" sort it out by my self.. how do i delete this threat??
Hi, I have the exact same problem but I want to hard reset the phone as it is new. What should I do to achieve that?

Phone got stolen - Looking for some feedback

Hi, my girl's Samsung S6 Edge got stolen today, snatched from her hand. Easy victim.
I'm trying to review the aftermath and what I did and maybe get some feedback on this.
Tracking/Remote lock
1. https://findmymobile.samsung.com/ failed - always set a password you remember; I didn't. After 7 failed login attempts account gets locked and you must reset your password, but it seems you can still lock your phone even if password is reset.
Anyway phone lock says will trigger once the device connects to the network. Is this still true if the phone is wiped?
2. https://www.google.com/android/devicemanager failed too
Maybe both failed because thief turned phone off? I did not try calling the number.
Security
3. All passwords were reset immediately, and gmail sessions were deleted.
4. Phone was locked with a PIN though a pattern would have been preferred. I do not remember if I encrypted it, but I know you cannot use pattern after you encrypt. Maybe that's why it had a PIN.
Assuming it was NOT encrypted, can a new ROM be flashed to unlock the phone and access content on storage drive (USB Debug was off)? I cannot remember if this is the case, I only rooted once and it was long time ago.
5. After 30 minutes I called the service provider and blocked the SIM card. She also offered to blacklist the IMEI number so I agreed. She even said that once you blacklist the IMEI, phone gets locked so thief cannot access it anymore - but this is bull****, it just won't be able to register to the network; it does not act as a remote lock lol. And IMEI can be easily overwritten once phone is rooted, so kind of an useless feature.
6. Reported to police but they don't care anyway, it's a petty crime. And chances of recovery are very little.
a) Would it be worthwile for the thief(s) to replace the front/back cover of the S6 Edge to a different color so they can easily sell it online locally afterwards? It seems to me the front cover is attached to the display, and to change that is quite expensive. Thoughts?
b) What happens with stolen phones anyway? Do they just root them and replace IMEI? I saw on a tv show that some will even replace the IMEI sticker on them.
thoughts:
- activate remote controls and TEST them
- install some app that takes snapshot of front camera when PIN is entered incorrectly
- encrypt phone, don't use dumb PIN
- set lock timeout to something short
- back up often
- engrave phone with custom message? (viable if you don't change often)
- have an action plan in case this happens
First two probably useless if thief switches phone off and reflashes it.
I probably need to restate my questions in a shorter format:
1. I had my phone registered with https://findmymobile.samsung.com. Will it still work if the phone is wiped?
2. Can content on the phone be accessed if phone was unencrypted and only had a PIN lock?
3. Is it easy to replace front/back case and bezel to give the phone a new 'look'?
Nobody answering... I'll try one last time.
1. Does flashing a new ROM give access to the stored files on the internal storage (like photos)?
2. Can a new ROM be flashed if the device is encrypted?
it can be flashed but the persob fill be stuck in bootloop and if the booted up ge will be stuck in frp lock by google he cant go past setup
w00tz said:
Nobody answering... I'll try one last time.
1. Does flashing a new ROM give access to the stored files on the internal storage (like photos)?
2. Can a new ROM be flashed if the device is encrypted?
Click to expand...
Click to collapse
If the guy who stole your phone flash another Rom and if not wipe the data then your photos etc will remain in your phone.. so if he wipe the data your file won't remain.. but the best option for him it's to wipe the data so this is good for you because he can't see your data.. make sure on your next phone to put pattern or a good code.. maybe you had put I didn't read all your posts.. that's all I know dude

How to bypass knock code, or change to MTP on an old android of mine

I just stumbled upon one of my old android phones (LG Stylo 3 - LGS777 - Android 6 - non-rooted stock) and I charged it just to see I had used a knock code as protection. I don't remember it for the life of me, and I've tried so many combinations of knocks (I used 6 knocks) and now I have to wait for 2 minutes before I can try to attempt again. Really, all I want to do is get whatever pictures that are on my phone, so that I can factory reset it after, and there's nothing on the SD card, so everything is on the internal storage. I plugged the phone into all my computers, and it just says charging only, but USB Debugging is on, and on every laptop and computer I use, even the ones I know I've used before for that phone says connected but unauthorized so I can't do any adb commands to change the mode from charging to mtp. I don't even remember if the phone asked for me to set up a backup pin or anything, and if it did, I would know that pin, but it doesn't even ask me to try any pin after failing 60 or so times. Is there any way that I can change the usb mode to mtp to check my files, get rid of the knock code, or anything at all to help me? Thanks! (USB Debugging is ON, can't do any RSA fingerprint popup to authorize without unlocking)

Fingerprint works but pattern not recognized anymore

Hello!
I'm facing a very weird issue with my HTC U11 Life.
I've been using it for years with the same pattern and fingerprint, and out of the blue, my pattern appears as wrong while I haven't changed it.
It happened for the first time after restarting my phone (I switch it off pretty often though).
The fingerprint is recognised, but the pattern isn't.
I have no other option on the screen than the emergency call (no "forgot pattern"/enter password/pin/connect to my Google account), and the "find my phone" doesn't show anything ("Can't reach device"), even if it's connected to my home regular wifi.
Not sure it's relevant, but I tried to deactivate the pattern a month ago, as I'm using that phone only at home. But it sounds like it didn't go through.
After browsing forums for hours, I tried a few steps, all unsuccessful.
Using the ADB tools, when I enter the bootloader, I run “./fastboot reboot bootloader”, after which I see the device show up in “./fastboot devices”. Then I try to run “./fastboot boot twrp.img” for the HTC U11 Life, at which point I see a “Device corrupt, cannot be trusted” message. So I seemingly can't progress without flashing my phone, which I don't want to do.
I should probably also mention that I have another phone (Google Pixel 6), and I tried to put my home as a "Trusted place" for my Google account, but it unfortunately didn't change anything.
I saw the hard reset option but I can't afford losing any data on that phone, and I believe there is a solution given the fact that I can provide the right fingerprint and any password, if they're requested.
I hope your fabulous community can be of any help.
Thank you very much!
Take it to a data recovery specialist if you really need the data. They might be able to recover it.
Either a hardware failure or possibly malware, or a Single Event Upset.
Always redundantly backup critical data. Avoid encryption if possible. Use an SD card as the data drive if you have that option.
Hey Blackhawk!
Thanks a lot for this super quick answer, I really appreciate it
I should admit I have a hard time believing a malware attack, given that I was barely using Internet on this phone. So that indeed must be a hardware failure or a Single Event Upset. Go figure!
That's a pity that there is no solution to that, especially that my fingerprint works, which is super frustrating. Anyway, too bad, I guess I'll factory reset as it's my only option.
Have a great weekend!
seems theres no way to fix this
ccaye said:
seems theres no way to fix this
Click to expand...
Click to collapse
There is. A factory reset. The data partition was somehow corrupted. If it reoccures then either the firmware has been corrupted or there's a hardware failure.
Anytime you set a password for device access, you are the one most likely to get locked out. It may be through no fault of your own however had no lock had been set you have a higher probability of retaining access.
NEVER set passwords for backup drives. Always keep backup drives isolated from everything unless in use.

Categories

Resources