Hello all
As someone handling sensitive information, I would like to investigate the security Android is dealing with.
First of all I got scared when I bought the app called SQLite Editor. It had all of my most vital passwords just stored in plain text. What I did immediately was a format of both internal and SD card as a reaction. However, I couldn't even find a feature to secure wipe the internal memory, while I've DBAN'd the SD card 7x.
So my thought was, I have to encrypt it. ICS seems to have a nice feature for that, however, it doesn't kind of work for me. I'm currently on cm-9.0.0-rc1-tinystream-hephappy-p500 (RC1-Rev.B). I went to Security in System Settings and touched "Encrypt Device". It gave some confirmations and I've accepted them however, now I'm kind of stuck on this screen.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
My first thought was "it is encrypting". But after hours of waiting, I wanted to check if it's done already. So I clicked the power-button once (just to unlock) and it asked for my password. I've entered it and it just went into my normal launcher. I've checked if anything had changed and no, my device has not been encrypted. Any logs somewhere? Any ideas what could have caused the problem?
Beside that, I asked myself the question "how secure is my Google account". As I am not planning to store any password to my device anymore, I am still connected to my Google account. I have DroidWall blocking all connections (except for my OpenVPN one).
Now my question is, what if my phone gets stolen. Does my SD-card contain any sensitive data, that's the first question. I am using LINK2SD to put everything on my SD card by the way. What security does Android use to connect to my Google account? If the thief turns on wifi and starts sniffing what data passes, what exactly would a hacker be able to sniff from me? Even then, my contacts contain valuable information. If my phone gets stolen, a hacker could simply steal all of my contacts, can't he?
Does someone have any idea to secure my phone? To connect to the internet I have OpenVPN working and blocking other connections with DroidWall. So the real case is, the data on my phone itself. Even if I use a anti-theft tool from the market and do a remote factory reset, the thief would still be able to use a datarecovery tool and so I would be screwed...
Another question: is it possible to combine a password lock and a slide lockscreen? As when I now enter my password and then put my phone in my pocket, it automaticly presses lots of things I don't want to press as there is no lockscreen for 30 minutes (I made the modification to the settings as my password is very long and I don't want to re-enter it each time). It would be perfect if a password lock would be on there to boot the phone (and even better to decrypt it) and every next time without rebooting the phone getting a patern unlock, that would be great.
So, if you can add anything usefull about securing or what security Android uses, please let me know.
Thank you very much
PS: One completely different question: does someone know why my phone boots when I plug it in to a charger? I don't like that, I want to charge without booting.
Encrypting the device will just make your device request a password each time you power it on. Since you securely erased your SD card (7x), it'll be somewhat difficult to recover those files. Just to be sure though, you could erase it using 35x (you may also want to defrag any files first). Your device connects to your Google account using a secure connection (more detailed here: https://developers.google.com/secure-data-connector/docs/1.3/security). If your contacts were synced with your Google account, it'll be ridiculously easy for anyone to access them (as long as your device is still linked to your account). So yes, a hacker could gain access (you wouldn't even need to be a hacker to do it; It's that simple).
This is quite a useful app to secure your device: https://play.google.com/store/apps/details?id=com.morrison.applock&hl=en. There are some methods to get around it, but you are able to prevent them from happening so it's still quite handy. If you remotely wipe your device, a "theif" may not be able to recover your data. Data recovery tools usually deal with external memory, so it'll be harder to recovery your device's internal data.
Yes, it is possible. If you set a password lock on your device and use some 3rd party screen lock, then you can use them at the same time. Remember you can also setup a SIM lock.
P.S: Does your device boot up fully or just to the battery charging icon? Does your device boot into recovery mode while attempting to charge it while off?
Thank you for your valuable reaction. According to what you say, Android actually doesn't care about security at all. I've just read that the Device Encryption isn't even 256-bit AES, but only 128. However, according to the link I can see that it actually uses some kind of VPN to connect to my Google account? If it is that secure, can I assume that my SQL Database of the Googel account also has extra encryption on it? And how far do you think that tunnel connection goes, does it also count for the GMail app or just for the basic Android connection? However, my contacts are indeed synced with my Google account. What do you suggest to do then? Noone should ever possibly get access to it. Let's say that I want to be as secure as that even the FBI or CIA won't be able to access it, any suggestions to accomplish that?
What I'm thinking about now is unlinking my Google account with my Android device (or even flashing a rom without Google Apps), but what would my phone make sense then? All of my contacts, numbers and more are stored on my Google profile, no other place. You also mentioned "so it'll be harder to recovery your device's internal data", from which I presume it is possible. Because I'm kind of paranoid because of what happened to me in the past, I hereby think that the only way to fix it is by encrypting the device. However, I can't get past that logo and a 3rd party app doesn't seem to do that kind of job (except for WhisperCore, which has been out of development since it has been bought by Twitter).
An interesting idea that I've just thought of is importing my contacts into Skype and then just always use the Skype app (combined with 3G). Skype always uses a 256-bit AES encryption and so it is secure for sure.
So, what do you think? Should I unlink my Google account with my Android device? Or should I just disable sync? Also, in my experience, there indeed always is a way to bypass an app locker (as easy as just removing the app, which can easily be done from recovery).
PS: It fully boots up. My previous version of CM9 booted to the battery charging icon, it's that that I want back.
Set a pattern unlock... it is FBI-proof as stated by CNET (if I've not mistaken)
And even amazon is using 128-bit... that isn't anything strange that Google isn't using 256-bit
Accidentally sent from my Google Nexus S
Yes it does use that connection (it wouldn't make sense to make it "open stream"). Your database files can be easily accessed from your device. The information will be secured in your Google account, but hackers can still find ways to access it (difficulty would depend on what you do). The tunnel connection goes for all your Google apps. Well if you're that paranoid, you'll probably want to remove your contacts from your Google account and disable sync.
If you do that, you will not be able to access any Google services from an app, your device will be missing important Google framework files, and you will not be able to download apps from the Play Store. Everything's possible .
Yes, you could do that. Keep in mind that the number of bits isn't necessarily important. See here: http://www.bestsslcertificates.com/articles11.html.
I would suggest disable sync.
P.S: Did you change your recovery since then?
melvinchng said:
Set a pattern unlock... it is FBI-proof as stated by CNET (if I've not mistaken)
And even amazon is using 128-bit... that isn't anything strange that Google isn't using 256-bit
Accidentally sent from my Google Nexus S
Click to expand...
Click to collapse
I am going to be honest, the first thing I did when I read this was laughing. But after some research, I saw you actually have a point. I've just read this: http://www.electricpig.co.uk/2012/0...roids-old-school-pattern-unlock-is-fbi-proof/
But then I ask myself, how hard can the FBI suck? If I'm right, you can just reboot into recovery and then access everything from there? Even disabling the pattern unlock from there is an option, no?
Beside that, what about encrypted messaging and encrypting calls. There are lots of apps available for that, but none except for Skype is stable and non-ugly at the same time.
Rakoen said:
I am going to be honest, the first thing I did when I read this was laughing. But after some research, I saw you actually have a point. I've just read this: http://www.electricpig.co.uk/2012/0...roids-old-school-pattern-unlock-is-fbi-proof/
But then I ask myself, how hard can the FBI suck? If I'm right, you can just reboot into recovery and then access everything from there? Even disabling the pattern unlock from there is an option, no?
Beside that, what about encrypted messaging and encrypting calls. There are lots of apps available for that, but none except for Skype is stable and non-ugly at the same time.
Click to expand...
Click to collapse
You can't change the setting in recovery, eg. Disable pattern unlock. It is a setting, unless you are just a little bit lucky, or else system will be corrupted
Accidentally sent from my Google Nexus S
Rakoen said:
I am going to be honest, the first thing I did when I read this was laughing. But after some research, I saw you actually have a point. I've just read this: http://www.electricpig.co.uk/2012/0...roids-old-school-pattern-unlock-is-fbi-proof/
But then I ask myself, how hard can the FBI suck? If I'm right, you can just reboot into recovery and then access everything from there? Even disabling the pattern unlock from there is an option, no?
Beside that, what about encrypted messaging and encrypting calls. There are lots of apps available for that, but none except for Skype is stable and non-ugly at the same time.
Click to expand...
Click to collapse
You could "encrypt" your messages and calls with an app locker (make "settings" be a locked app so it cannot be uninstalled). No, the pattern unlock cannot be disabled via recovery. You can access many things from recovery, but not like that. The only way they could know your pattern would be by finger markings (which you could wipe away or get a fingerprint resistant screen; unless your device is one of those which can be bypassed with key combinations).
Theonew said:
Yes it does use that connection (it wouldn't make sense to make it "open stream"). Your database files can be easily accessed from your device. The information will be secured in your Google account, but hackers can still find ways to access it (difficulty would depend on what you do). The tunnel connection goes for all your Google apps. Well if you're that paranoid, you'll probably want to remove your contacts from your Google account and disable sync.
If you do that, you will not be able to access any Google services from an app, your device will be missing important Google framework files, and you will not be able to download apps from the Play Store. Everything's possible .
Yes, you could do that. Keep in mind that the number of bits isn't necessarily important. See here: http://www.bestsslcertificates.com/articles11.html.
I would suggest disable sync.
P.S: Did you change your recovery since then?
Click to expand...
Click to collapse
There must be a solution for this, without having to remove the complete Google framework. But indeed, I am that paranoid. Nothing may lead to any personal file I have. However, you also mentioned "removing contacts from my Google account". Why would that be necessary? Google doesn't even give the FBI access to my account so why wouldn't it be secure? What I'm thinking off now is syncing my Google account with my Android device. Then unlinking it and then encrypting the contacts, just the contacts. Then I did sync, I did unlink and did encrypt. Wouldn't that make it impossible for enyone on the entire world to access anything from me?
Google services are not important for me, that "important framework files" don't sound important enough to me and the Google Play store... I don't care about it. Enough APK's around. Security first.
You are reminding me that the bits aren't important, while that's true, I want to remind you that secure deletion of 35x isn't that important too. 7x is more than enough if you choose a powerfull PNG stream.
Theonew said:
You could "encrypt" your messages and calls with an app locker (make "settings" be a locked app so it cannot be uninstalled). No, the pattern unlock cannot be disabled via recovery. You can access many things from recovery, but not like that. The only way they could know your pattern would be by finger markings (which you could wipe away or get a fingerprint resistant screen; unless your device is one of those which can be bypassed with key combinations).
Click to expand...
Click to collapse
Well, I actually was thinking like "why would you even neet to unlock the device". As far as I know, something as a pattern lockscreen doens't encrypt/decrypt anything except for your launcher, which is not a necessary product. I mean, you say "you can access many things from recovery", doesn't this include like every important files? Aren't databases accessible and so also contacts or messages?
However, about the encrypted calls and messages I actually mean off the record things. Like TextSecure do.
Rakoen said:
There must be a solution for this, without having to remove the complete Google framework. But indeed, I am that paranoid. Nothing may lead to any personal file I have. However, you also mentioned "removing contacts from my Google account". Why would that be necessary? Google doesn't even give the FBI access to my account so why wouldn't it be secure? What I'm thinking off now is syncing my Google account with my Android device. Then unlinking it and then encrypting the contacts, just the contacts. Then I did sync, I did unlink and did encrypt. Wouldn't that make it impossible for enyone on the entire world to access anything from me?
Google services are not important for me, that "important framework files" don't sound important enough to me and the Google Play store... I don't care about it. Enough APK's around. Security first.
You are reminding me that the bits aren't important, while that's true, I want to remind you that secure deletion of 35x isn't that important too. 7x is more than enough if you choose a powerfull PNG stream.
Click to expand...
Click to collapse
About the Google framework files, you may want to take a look here: http://forum.xda-developers.com/showthread.php?t=1715375. That could be necessary to prevent hackers from getting to them. Yes, unless your data was still left on Google servers (in your account) and hackers got to it.
Yes, but some powerful undelete and data recovery softwares can still recovery data deleted using 7x (especially if the files were fragmented).
Rakoen said:
Well, I actually was thinking like "why would you even neet to unlock the device". As far as I know, something as a pattern lockscreen doens't encrypt/decrypt anything except for your launcher, which is not a necessary product. I mean, you say "you can access many things from recovery", doesn't this include like every important files? Aren't databases accessible and so also contacts or messages?
However, about the encrypted calls and messages I actually mean off the record things. Like TextSecure do.
Click to expand...
Click to collapse
You can use 3rd party apps to set pattern unlock for other apps. Partly, but not quite. In recovery, you can access /data (where all your data is stored), but only to backup that partition (unless you made a previous backup which would also allow you to "restore"). You can't access the files like being able to view them (unless you are using Aroma file manager, but you still won't access those files). Databases, contacts, and messages are not accessible (unless you backed them up to your SDcard - they still wouldn't be readable though).
Rakoen said:
Well, I actually was thinking like "why would you even neet to unlock the device". As far as I know, something as a pattern lockscreen doens't encrypt/decrypt anything except for your launcher, which is not a necessary product. I mean, you say "you can access many things from recovery", doesn't this include like every important files? Aren't databases accessible and so also contacts or messages?
However, about the encrypted calls and messages I actually mean off the record things. Like TextSecure do.
Click to expand...
Click to collapse
This topic is getting more and more interesting.
In the other hand, IF you're having pure Google Device with build in memory, people cant access your storage (built in memory) without entering a pattern or etc
Accidentally sent from my Google Nexus S
Theonew said:
About the Google framework files, you may want to take a look here: http://forum.xda-developers.com/showthread.php?t=1715375. That could be necessary to prevent hackers from getting to them. Yes, unless your data was still left on Google servers (in your account) and hackers got to it.
Yes, but some powerful undelete and data recovery softwares can still recovery data deleted using 7x (especially if the files were fragmented).
You can use 3rd party apps to set pattern unlock for other apps. Partly, but not quite. In recovery, you can access /data (where all your data is stored), but only to backup that partition (unless you made a previous backup which would also allow you to "restore"). You can't access the files like being able to view them (unless you are using Aroma file manager, but you still won't access those files). Databases, contacts, and messages are not accessible (unless you backed them up to your SDcard - they still wouldn't be readable though).
Click to expand...
Click to collapse
The 7x note is not correct for 100%. The way that I overwrite data won't make it possible to recover anything at 7x, not even using powerful undelete or data recovery software. Even if you're a professional, it will be very hard to get back any data. I have experience in this sector, so I know where I'm talking about on this part.
However, what you just said about the pattern unlock is almost unbelievable. Doesn't this simply solve everything? I mean, why would anyone ever use the Android Device Encryption in ICS if there is something as a pattern unlock? Why would it make sense to use AES 128-bit when you can't even access it without the encryption?
So it wouldn't even make sense to unlink my Google account, would it? It isn't accessible you say, so why whould it be any concern? If the FBI isn't able to break behind the pattern unlock, who would be? You first said that a hacker can easily get access to any sensitive data if I sync my Google account, but why should it? Even without OpenVPN, it uses a VPN encryption for every Google App ... so Android is the best in security, I was wrong?
melvinchng said:
This topic is getting more and more interesting.
In the other hand, IF you're having pure Google Device with build in memory, people cant access your storage (built in memory) without entering a pattern or etc
Accidentally sent from my Google Nexus S
Click to expand...
Click to collapse
You are very right on that. It really is getting interesting. Your "IF" makes me wonder what exactly you mean. As I have a LG Optimus One (P500) with custom rom, custom recovery and custom radio. Does it make any difference here?
Rakoen said:
You are very right on that. It really is getting interesting. Your "IF" makes me wonder what exactly you mean. As I have a LG Optimus One (P500) with custom rom, custom recovery and custom radio. Does it make any difference here?
Click to expand...
Click to collapse
You can't access your storage WITHOUT entering the pattern in stock device. IF you're in stock and wanted to root, both system and internal SD will be wiped (a factory reset will be made). So no data will be left
Device: nexus s, galaxy nexus, nexus 7
Accidentally sent from my Google Nexus S
And regarding to the security, Google released an app that helps you to monitor which app is requesting what permission. You can even set which permission is deny so that you can't install the app and highly "dangerous" app will be kept away from your device.
Accidentally sent from my Google Nexus S
Rakoen said:
The 7x note is not correct for 100%. The way that I overwrite data won't make it possible to recover anything at 7x, not even using powerful undelete or data recovery software. Even if you're a professional, it will be very hard to get back any data. I have experience in this sector, so I know where I'm talking about on this part.
However, what you just said about the pattern unlock is almost unbelievable. Doesn't this simply solve everything? I mean, why would anyone ever use the Android Device Encryption in ICS if there is something as a pattern unlock? Why would it make sense to use AES 128-bit when you can't even access it without the encryption?
So it wouldn't even make sense to unlink my Google account, would it? It isn't accessible you say, so why whould it be any concern? If the FBI isn't able to break behind the pattern unlock, who would be? You first said that a hacker can easily get access to any sensitive data if I sync my Google account, but why should it? Even without OpenVPN, it uses a VPN encryption for every Google App ... so Android is the best in security, I was wrong?
Click to expand...
Click to collapse
Not necessarily. If someone knows your pattern unlock, they could unlock your device. Or even people standing behind you could see it. Someone may use it if another person knows their unlock pattern (but wouldn't know the code).
If USB debugging is enabled, someone could access your databases, etc. over adb. You wouldn't need to sync your Google account - your device would do that automatically (unless you disabled sync which is what I suggested).
melvinchng said:
You can't access your storage WITHOUT entering the pattern in stock device. IF you're in stock and wanted to root, both system and internal SD will be wiped (a factory reset will be made). So no data will be left
Device: nexus s, galaxy nexus, nexus 7
Accidentally sent from my Google Nexus S
Click to expand...
Click to collapse
That's a true thing you say there. But however, it doesn't apply in my situation. I currently am on a rooted device that not even is a nexus (LG Optimus One P500)... so how does it make sense in my case?
melvinchng said:
And regarding to the security, Google released an app that helps you to monitor which app is requesting what permission. You can even set which permission is deny so that you can't install the app and highly "dangerous" app will be kept away from your device.
Accidentally sent from my Google Nexus S
Click to expand...
Click to collapse
I've blocked all connections using DroidWall, so it would be impossible to upload anything personal to an intruder. Beside that, I use my own way of scanning apps and so I do know if I'm secure on that matter. However, thanks for letting me know there is an app for that.
However, I'm not concerned about that kind of security (I am protected against any kind of virusses or malware), my concern is about sniffers and more importantly thiefs that are great hackers (which in my case are around the corner).
Theonew said:
Not necessarily. If someone knows your pattern unlock, they could unlock your device. Or even people standing behind you could see it. Someone may use it if another person knows their unlock pattern (but wouldn't know the code).
If USB debugging is enabled, someone could access your databases, etc. over adb. You wouldn't need to sync your Google account - your device would do that automatically (unless you disabled sync which is what I suggested).
Click to expand...
Click to collapse
Disable visible pattern and use two steps verification for Gmail.
Google search for it, 2 steps verification for Gmail.
Even thought someone has your Gmail account AND password, they still aren't able to log in into your mail... and the password that you use to log in in your Android device IS different from the normal one AND the password has to renew monthly..
Google really put a lot of hard work on solving those problem that you mentioned. Try out those things that Google has made
Accidentally sent from my Google Nexus S
Theonew said:
Not necessarily. If someone knows your pattern unlock, they could unlock your device. Or even people standing behind you could see it. Someone may use it if another person knows their unlock pattern (but wouldn't know the code).
If USB debugging is enabled, someone could access your databases, etc. over adb. You wouldn't need to sync your Google account - your device would do that automatically (unless you disabled sync which is what I suggested).
Click to expand...
Click to collapse
Well, then I'm going to create a pattern unlock as strong that it's impossible to follow, even if the person is standing beside me and looking at it. I'm also not planning to show it to anyone and will look around if there are cameras every time I unlock (yes, I am paranoid, but with reason).
I thought exactly the same about USB debugging and so I disabled it. I don't understand what you are trying to say with the sync. Why would I want to disable it? What would it add as security?
And it seems like I skipped this:
Theonew said:
P.S: Did you change your recovery since then?
Click to expand...
Click to collapse
No, I haven't change my recovery since a long time.
Rakoen said:
That's a true thing you say there. But however, it doesn't apply in my situation. I currently am on a rooted device that not even is a nexus (LG Optimus One P500)... so how does it make sense in my case?
I've blocked all connections using DroidWall, so it would be impossible to upload anything personal to an intruder. Beside that, I use my own way of scanning apps and so I do know if I'm secure on that matter. However, thanks for letting me know there is an app for that.
However, I'm not concerned about that kind of security (I am protected against any kind of virusses or malware), my concern is about sniffers and more importantly thiefs that are great hackers (which in my case are around the corner).
Click to expand...
Click to collapse
Can you let us know what is your job / what does your phone contains / what is most of them...
And actually, there is an Chinese app, 360 Strong Box, and what it does is exactly what you want. It is a software made by 360 company, the app can convert image / video / documents and data into a file that can only be access by using the 360 strongbox... you don't have to worry about the security, 360 is one of the largest Chinese security company that provides antivirus or anti spyware on different platform, windows, android, symbian, iOS etc.
UNFORTUNATELY, it is in Chinese language and the company signed it in private, so I couldn't compile and recompile it and make a translation.
Request from the company for the English translation. I can help them to translate if they're willing to release a copy of English version. The translation is about 400 lines only, a short app.
Accidentally sent from my Google Nexus S