I've had a quick search around the forums and a bit more of a thorough search of the internet at large, but I can't seem to find an answer to my question.
With the new KitKat NFC policies etc., will it now to possible to [finally] emulate my work ID card with my phone. It would be ridiculously useful to be able to swipe my phone on the key card scanner, for example, if I forgot my card at home.
I am aware that there are security issues here, because we can't just have anyone going around, copying key cards with their phones etc.
Thanks,
Adzrules
I'd love to do that do unfortunately my badge uses thousand bit encryption so i dunno if that would work.
Such a thing will never be possible - that flies in the very face of the security the RFID badges are designed to have in place to begin with. Imagine how messed up things would be if you could go to work, with your NFC enabled phone, and casually brush past a co-worker and just clone their RFID badge in a second flat and then do things using their identity with respect to the company security.
It's never going to be that easy as life isn't a TV show like "Person of Interest" where you can clone a smartphone's identity/IMEI/etc from 30 yards away just by running some uber-hack app.
It might be possible to have such an identity programmed into the phone by your employer but it would end up being a totally new one since the cryptographic data contained on the actual RFID badge is a one-shot and can't be duplicated. That would end up being more trouble for the company, I'd say, and not likely to end up being an SOP anytime soon, it's just too risky for them.
Hey!
It's my first post here so it this isn't the best place for such a question then by all means mods pls move the thread to where it should be
Basically, where I'm currently living (Brazil), things tend to get pretty violent and phone thefts are very common. Now the thing is, if it's an iPhone usually the thieves just throw it away, as once it's locked it becomes useless. When it comes to Android though, some of them will dig deep trying to access your info like pictures, passwords, bank information, among other things. They even manage to break IMEI locks and stuff. I got my S5 stolen recently and the information theft part put me through hell. Yet, I'd much rather have an S8+ then any other iPhone currently, so my question is how could I completely theft proof it?
I'm not really worried about them restoring the phone and reselling it, more about them accessing the data inside of it. I know the SD card can be protected through cryptography (although would accept "stronger" tips if there are any). When it comes to apps, aside from the basics of trusting what you install and stuff, are apps like Cerberus, Knox 2.0, or other Samsung features I'm not aware of, any good against someone who knows what they're doing? Is there a way to disable airplane mode or power offs? Also what is probably my strongest concern: is there a way to completely not allow system changes through a computer, like the one that removes the lock screen?
Being a programmer and computer science undergrad student (although not specializing in security nor mobile), I'd have no problem if the solutions would involve some coding or tweaking, just as long as they prove to be effective.
So, would you guys have any tips on how to completely secure the data given those concerns?
The sd card can be Encrypted and if you have a password lock (fingerprint irsi etc...) then it will ask for that before it will unlock the phone.
Also they have a remote wipe. You can log i to google and remote wipe your phone when you found out its been stolen.
You can set the phone to require a password to decrypt it when it's restarted. You can encrypt the SD card too. You can set it to lock instantly when the screen turns off. And you can use only a password to unlock it (no biometrics), which is the most secure option (if you use a suitable password). Finally, you can set the phone so that you can wipe it remotely, or to wipe itself after a number of consecutive incorrect password attempts. But even without the last two measures, your data will be unreadable without your password.
Unfortunately, though, if thieves are violent enough, they may be able to coerce you into divulging the password. If they succeed, they have full access to your phone.
Gary02468 said:
You can set the phone to require a password to decrypt it when it's restarted. You can encrypt the SD card too. You can set it to lock instantly when the screen turns off. And you can use only a password to unlock it (no biometrics), which is the most secure option (if you use a suitable password). Finally, you can set the phone so that you can wipe it remotely, or to wipe itself after a number of consecutive incorrect password attempts. But even without the last two measures, your data will be unreadable without your password.
Unfortunately, though, if thieves are violent enough, they may be able to coerce you into divulging the password. If they succeed, they have full access to your phone.
Click to expand...
Click to collapse
What about stuff like that Dr. Fone Toolkit that supposedly removes the lock screen? From the quick look I took it seems it somehow patches the Android on the phone to remove the lock screen. Is there some sort of system encryption/lock to avoid that kind of stuff when connected to a computer?
xile6 said:
The sd card can be Encrypted and if you have a password lock (fingerprint irsi etc...) then it will ask for that before it will unlock the phone.
Also they have a remote wipe. You can log i to google and remote wipe your phone when you found out its been stolen.
Click to expand...
Click to collapse
Usually they just put it on airplane mode though, so google remote wipe is useless... Which is why I was looking for more of an offline fix through cryptography and such
I use smart Lockscreen protector to prevent somebody putting my phone to airline mode or shutting it down ( It won't help phones with removable battery)
If you have the phone encrypted and have the require pin on boot set. And you have the Qualcomm version that is locked down you have nothing to worry about.
Even the iPhone 7 has been jail broken or rooted the S8 with the Qualcomm chip is one of only a few phones that have not been hacked. It's actually WAY more secure than an iPhone.
lvrma said:
What about stuff like that Dr. Fone Toolkit that supposedly removes the lock screen? From the quick look I took it seems it somehow patches the Android on the phone to remove the lock screen. Is there some sort of system encryption/lock to avoid that kind of stuff when connected to a computer?
Click to expand...
Click to collapse
The phone is completely encrypted, so if you set it to require a password to restart and to turn the screen back on, then its contents are unreadable without the password regardless of how you connect to it.
lvrma said:
...
Usually they just put it on airplane mode though, so google remote wipe is useless... Which is why I was looking for more of an offline fix through cryptography and such
Click to expand...
Click to collapse
If you have a lock screen set you can lock the status of your phone(wifi state, airplane mode, power settings). This way you have to unlock it to toggle these modes.
I just ran across this, some good advice.
http://thedroidguy.com/2017/04/setu...security-features-tutorials-1071462#Tutorial1
lvrma said:
What about stuff like that Dr. Fone Toolkit that supposedly removes the lock screen? From the quick look I took it seems it somehow patches the Android on the phone to remove the lock screen. Is there some sort of system encryption/lock to avoid that kind of stuff when connected to a computer?
Click to expand...
Click to collapse
Like you, I'm interested with this topic, but unlike you, I would like the theief to have a useless phone if they cant unlock it. So that they would think twice the next time they want to steal an android. Else they would just continue stealing since you just put the phone on download mode, connect to a computer and root it.
About your question. Isnt disabling usb debugging mode on developer option block that risk? Also in my note 4, enabling knox will prevent your device from being rooted, at least thats what i understand from the description. i wonder where it is in s8.
speaking of knox, s8 has "Secure folder". its like a secured environment within a phone. Everything you put in here will be protected by knox. Apps, accounts, files, etc. And it would ask for another security to access it(pattern/pin/password).
lvrma said:
Usually they just put it on airplane mode though, so google remote wipe is useless... Which is why I was looking for more of an offline fix through cryptography and such
Click to expand...
Click to collapse
you mentioned cerberus app, it has a function than can wipe device memory and wipe sd card via SMS command. so if you are fast enough, while the thief is running away and before he pulls out your sim card from the phone, you can send an sms command to wipe data.
Since you mentioned you are a programmer, this may be interesting to you, locking download mode and recovery mode on android to prevent thief from flashing hack to your phone. but this require a bit of patience if android isnt your forte.
https://ge0n0sis.github.io/posts/20...-mode-using-an-undocumented-feature-of-aboot/
BratPAQ said:
Like you, I'm interested with this topic, but unlike you, I would like the theief to have a useless phone if they cant unlock it. So that they would think twice the next time they want to steal an android. Else they would just continue stealing since you just put the phone on download mode, connect to a computer and root it.
About your question. Isnt disabling usb debugging mode on developer option block that risk? Also in my note 4, enabling knox will prevent your device from being rooted, at least thats what i understand from the description. i wonder where it is in s8.
speaking of knox, s8 has "Secure folder". its like a secured environment within a phone. Everything you put in here will be protected by knox. Apps, accounts, files, etc. And it would ask for another security to access it(pattern/pin/password).
you mentioned cerberus app, it has a function than can wipe device memory and wipe sd card via SMS command. so if you are fast enough, while the thief is running away and before he pulls out your sim card from the phone, you can send an sms command to wipe data.
Since you mentioned you are a programmer, this may be interesting to you, locking download mode and recovery mode on android to prevent thief from flashing hack to your phone. but this require a bit of patience if android isnt your forte.
https://ge0n0sis.github.io/posts/20...-mode-using-an-undocumented-feature-of-aboot/
Click to expand...
Click to collapse
Don't put your phone anywhere besides your pocket. Get a cover that makes it look like as different phone with a cracked screen.
the easiest way to encrypt sd and phone, enable adoptable storage.
cantenna said:
the easiest way to encrypt sd and phone, enable adoptable storage.
Click to expand...
Click to collapse
How is that easier than just selecting the Settings options to encrypt the SD card and to require a password to unlock upon restart?
---------- Post added at 06:08 AM ---------- Previous post was at 05:11 AM ----------
lvrma said:
Usually they just put it on airplane mode though, so google remote wipe is useless[.] Which is why I was looking for more of an offline fix through cryptography and such
Click to expand...
Click to collapse
Yes, and even without airplane mode, they can physically enclose the phone to block all electronic signals. Encrypting the phone (and SD card), using a secure password as the sole unlock method, affords the strongest protection against all attacks (except coercing the password from you).
Gary02468 said:
How is that easier than just selecting the Settings options to encrypt the SD card and to require a password to unlock upon restart?
---------- Post added at 06:08 AM ---------- Previous post was at 05:11 AM ----------
Yes, and even without airplane mode, they can physically enclose the phone to block all electronic signals. Encrypting the phone (and SD card), using a secure password as the sole unlock method, affords the strongest protection against all attacks (except coercing the password from you).
Click to expand...
Click to collapse
oh yea, may bad, i often assume everyone on xda is here because there interested in unlocked boot loaders, root and custom kernels. My recomindation applies only to people who have unlocked pandor's box only.
the method of encyption you suggested the isnt availble for users like me but we can enable adoptable storage which does encrypt the system by other means and it is compatible with root, etc
dynospectrum said:
Don't put your phone anywhere besides your pocket. Get a cover that makes it look like as different phone with a cracked screen.
Click to expand...
Click to collapse
Where can you get/ how can you make such a cover?
Also sometimes when I'm in bad Areas, I go to developer options and turn on some of the screen update stuff, so it flashes the screen purple a lot and make it look messed up.
My friend's son died in a car crash, so I would like to get the sentimental data off of the device. Here are my ideas:
Idea 1: In recovery mode, the device is found, but the computer is not authorized. Unfortunately, no access to the son's PC. An exploit to find the correct key would work.
Idea 2: Brute force 4 digit pin. I could do it, but the lockscreen wait time is currently 30 minutes. It will probably go up to 1 hour. Brute forcing would take a year. Also no guarantee his pin was only 4 digits.
The solution is probably brute force + network spoof. The date and time are synced with the cell network. If you could feed incorrect date and time info to the phone, you wouldn't have to wait in between guesses. I would do this, but I am not sure how.
Idea 3: Sideload fake OTA update that removes password lock . This would work if you had the official key. Maybe I could send the phone to Samsung and have them do it?
I'm open to any ideas.
Hello , I am giving the data recovery service from locked mobile phone. If you need feel free to contact me on xxxxxx
Mod Edit: Mail id removed.
@Moni9t6
If you want to help someone, please do so on the open forum so that it will be helpful to others too. Inviting conversations outside of XDA for solutions is not the proper course.
Hello - I have a rather unique situation and have been searching for possible solutions since last few days. I have forgotten my pin or potentially an update or my office apps have locked my phone. I have it connected using fastboot to my PC however I am not able to flash TWRP as it gives an error: Flashing not allowed in Lock State. Is there any way for me to back up the data before doing a reset? Is there any code which can be used to bruteforce different pin combinations in recovery mode / fastboot mode? Any help is greatly appreciated. I have the output of "fastboot getvar all" in case that can help you locate the partition to boot/erase. thanks a ton!
Oneplus8TPinFinder said:
Hello - I have a rather unique situation and have been searching for possible solutions since last few days. I have forgotten my pin or potentially an update or my office apps have locked my phone. I have it connected using fastboot to my PC however I am not able to flash TWRP as it gives an error: Flashing not allowed in Lock State. Is there any way for me to back up the data before doing a reset? Is there any code which can be used to bruteforce different pin combinations in recovery mode / fastboot mode? Any help is greatly appreciated. I have the output of "fastboot getvar all" in case that can help you locate the partition to boot/erase. thanks a ton!
Click to expand...
Click to collapse
In what way are you phone locked? I don't think there are anything you can do to save your data if you don't know your password/pin. TWRP wouldn't have helped in this case either.
Hi - thanks for your reply. My pin is not working and every pin trial is taking quite a bit of time. I am able to try pins quickly in recovery mode but trying all possible 4 digit combinations will take quite a bit of time. Alternatively, a brute force code to keep trying different pins would also be beneficial if you are aware of it.
Wont adb would have let me back up my phone data?
No way to bruteforce it that I am aware off.
your pin is needed to decrypt the encryption key that is used to decrypt data. So you can't access or backup any data without your pin. This is by design.
But cant the encryption key be overwritten using my biometrics which I have registered as well? Or something that manufacturer can do because there are tonnes of solutions for samsung and lg devices but am struggling to find something for oneplus..
Oneplus8TPinFinder said:
But cant the encryption key be overwritten using my biometrics which I have registered as well? Or something that manufacturer can do because there are tonnes of solutions for samsung and lg devices but am struggling to find something for oneplus..
Click to expand...
Click to collapse
Perhaps this is because OnePlus has properly secured their devices and Samsung/LG hasn't? Though I do contest that statement. By my knowledge all devices perform a data wipe when the bootloader is unlocked (aside from one OP device that had a flaw in this area IIRC).
Please view this from another perspective: if your device was stolen and you've PIN protected it, would you want the thief to be able to unlock it and view all your pictures/videos/documents/etc?
Timmmmaaahh! said:
Perhaps this is because OnePlus has properly secured their devices and Samsung/LG hasn't? Though I do contest that statement. By my knowledge all devices perform a data wipe when the bootloader is unlocked (aside from one OP device that had a flaw in this area IIRC).
Please view this from another perspective: if your device was stolen and you've PIN protected it, would you want the thief to be able to unlock it and view all your pictures/videos/documents/etc?
Click to expand...
Click to collapse
I agree but one pin cant and should not be the only way to unlock phone. In my particular case, I have now started to think that some of the app has messed up with the pin or an android update has messed up with the pin. I am quite surprised that a forgot pin / pattern option doesnt even come as if no one can forget pin. Is there a way to hack into my phone given I am logged into same gmail and other apps as I am logged into my new realme phone?
Oneplus8TPinFinder said:
I agree but one pin cant and should not be the only way to unlock phone. In my particular case, I have now started to think that some of the app has messed up with the pin or an android update has messed up with the pin. I am quite surprised that a forgot pin / pattern option doesnt even come as if no one can forget pin. Is there a way to hack into my phone given I am logged into same gmail and other apps as I am logged into my new realme phone?
Click to expand...
Click to collapse
First time I've heard of a failing PIN, let alone an app that would mess with it (which is absolutely impossible). Asking for a hack into your phone is asking for an illegal way to access your device, which crosses a boundary we will not get into on this platform. We tweak devices, we add functionality, we use exploits to alter the aesthetics of a device and we surely mess them up a lot but we will not support anything beyond our terms.
But! If there indeed is an issue with the OnePlus 8T PIN security, I hope people will report it here. AFAIK there is no such issue widely known.
I also hope it's a lesson in creating proper backups. I guess learning the hard way is the best way. I think we've all been there. I sure have!
you could reset it and enter email registered with that device they fix or email you code to fix