[Q] How to truly secure your device? - Security Discussion

I have a few questions about the security about my phone.
First of all, I have AOSP based ROM but with unlocked bootloader and custom recovery, this is a hole in security so anyone can access to the phone data bypassing patterns/fingerprints etc just by removing some files in system/data like locksettings.db.... How could I protect me from that? Should I put a pin to the boot or something?
Secondly, if I solve the first problem and someone steals my phone, and do a factory reset. With Forense recovery tools (I m not going to mention about this programs)... Would he/she be able to access to the data even with a factory reset? Because the data is not going to be erased in a low level way for sure right?
Thanks in advance

If the device is encrypted and factory reset, no, he/she can't access the data anymore, the encryption keys are lost and the data looks like gibberish.
But if he does not reset the phone, then as you correctly said before, your bootloader is unlocked and you are not protected from someone still getting everything on your phone through for example a custom recovery or forensic tools.
I thought about this issue myself and i am not sure how to solve it properly besides that you should never unlock the bootloader if you need a "truly" secure device.

Adriantrejo said:
I have a few questions about the secure and best deals for my phone.
First of all, I have AOSP based ROM but with an unlocked bootloader and custom recovery, this is a hole in security so anyone can access the phone data bypassing patterns/fingerprints, etc just by removing some files in system/data like lock settings.db... How could I protect me from that? Should I put a pin to the boot or something?
Secondly, if I solve the first problem and someone steals my phone, and do a factory reset. With Forense recovery tools (I m not going to mention about these programs)... Would he/she be able to access the data even with a factory reset? Because the data is not going to be erased in a low-level way for sure right?
Thanks in advance
Click to expand...
Click to collapse
Are you satisfied with DIR49DNOR0N??

DIR49DNOR0N said:
If the device is encrypted and factory reset, no, he/she can't access the data anymore, the encryption keys are lost and the data looks like gibberish.
But if he does not reset the phone, then as you correctly said before, your bootloader is unlocked and you are not protected from someone still getting everything on your phone through for example a custom recovery or forensic tools.
I thought about this issue myself and i am not sure how to solve it properly besides that you should never unlock the bootloader if you need a "truly" secure device.
Click to expand...
Click to collapse
Yes, unless you put an encryption to the boot system in the same way to Bitlocker to the mobile I think. Anyway if the police/justice requieres the company to unlock your device (in this case to have the google account password) with 2 steps verification I do not know how is the google policy about that, I know that apple for examples refuses always to do that even if there is an order.

wenn Entwicklermodus bei gerootetem handy mit Alternativfirmware deaktiviert wurde UND Displaysperre aktiviert ist UND bei USB Einstellunge steht ( Android 11 ): "handy steuert dieses Gerät + keine Dateiübertragung aktiviert",
-
könnte dann beispielsweise ein Dieb, sofern das Display bereits im standy ( aus ist ) noch Zugriff auf interne Daten erlangen ?

Related

[Q] Bootloader & recovery security

Is there a way how to set a password or PIN lock for the bootloader or at least the recovery? There's been a lot of break ins in my area lately and when someone steals my phone, I wanna make sure that it will be rendered completely useless (Including IMEI blacklist) and non-recoverable.Is there a way how can be bootloader & recovery locked so a thief can't access the recovery without a password or a PIN lock and thus not able to reset the phone to factory settings?
So far, any anti-theft software I've seen doesn't have this ability and can be easily removed by factory data reset
Thundery Steak said:
Is there a way how to set a password or PIN lock for the bootloader or at least the recovery? There's been a lot of break ins in my area lately and when someone steals my phone, I wanna make sure that it will be rendered completely useless (Including IMEI blacklist) and non-recoverable.Is there a way how can be bootloader & recovery locked so a thief can't access the recovery without a password or a PIN lock and thus not able to reset the phone to factory settings?
So far, any anti-theft software I've seen doesn't have this ability and can be easily removed by factory data reset
Click to expand...
Click to collapse
I believe, but not sure, that TWRP has a PIN code system
You should try Cerberus or avast!, with root they can lock into the system which means the thief has to reflash an FTF file
EDIT
Nope, TWRP doesn't have PIN protection. If you want to secure your phone, some tips:
1. Make sure the on/off menu cannot be opened when the phone is locked.
2. Make sure your data is always on
3. Use CyanogenMod Account / Cerberus / avast! AntiTheft
x. If you phone gets stolen, use one of the above programs to lock and wipe your device.

Sold phone but now its locked by android security

Hi @ all,
i have a problem i sold the XT1541. Had used it before with my google account for testing purposes. Before i sold it i forgot do DELETE the account from the phone and just did a factory reset via recovery.
The customer now cannot log in with his account. Is there anything i can do to help him - would not like to give him my account infos. Any input would be reakky helpful.
I did not know about this new feature....
simple (easy): Just go to your customer and log in for him and delete your account
harder (risky): flash the stock firmware
Try factory reset via recovery
Well the customer is 500km away. So its not an Option to visit him. How could a second factory reset via recovery help in this case? The device is still bootloader locked. Can he install the stock Rom without loosing the motorola warranty? I could assist him via teamviewer. But he does not want to loose the full warranty.
Gesendet von meinem Nexus 7 mit Tapatalk
Delete all your info off your Google account(credit cards, Google+, etc) and give him the password and Google email so he can bypass then have him delete it in settings.
Or return the phone and give him his money back.
To my knowledge you can install stock firmware without unlocking your bootloader, also in my post above a i meant via the bootloader menu.
I hope another member can confim whether you can factory reset via the bootloader menu
Yup! Stock recovery has this feature!

Bootloader and may security patch

I unluckly discovered that with the may security update, both unlocking and locking the bootloader will result in a complete wipe of all user data.
Is this intended? Will this be the standard for all the next updates? It's really a shame that unlocking ther bootloader is now a relatively pricey and hard thing to do.
Or did I just do something wrong? Lost data... twice in a day
What about GCam and root if the bootloader can't be altered without clearing all user data? Does this mean I'll have to dump my data every time I update my system (and so root again)?
Hope someone knows better than me :crying:
_MrAlpha_ said:
I unluckly discovered that with the may security update, both unlocking and locking the bootloader will result in a complete wipe of all user data.
Is this intended? Will this be the standard for all the next updates? It's really a shame that unlocking ther bootloader is now a relatively pricey and hard thing to do.
Or did I just do something wrong? Lost data... twice in a day
What about GCam and root if the bootloader can't be altered without clearing all user data? Does this mean I'll have to dump my data every time I update my system (and so root again)?
Hope someone knows better than me :crying:
Click to expand...
Click to collapse
Yes, from now it's "normal"
On all devices you lose all data for locking/unlocking BL, our Mi A1 was lucky.
Its upgrading security
Wiping FRP was a piece of cake

Verify Pin after hard reset

Hello,
a friend of mine gave me his U11+ because he had a problem with it. After a factory reset he can start the phone and log in to wifi, but after that, the phone always asks for the last verify PIN
He told me he never had one.
At first i tried a factory reset and a cache wipe with no effect. Then i flashed a ruu with the SD method, but the Phone keeps asking for the verify PIN.
The Phone has S-On, is not rooted and the bootloader is looked.
Does anybody know, how to fix this?
Thanks!
Chris
Ist it maybe possible, to delect or chrash the current Firmware and then installing the ruu again? I don't know, where the information about the verify Pin is saved.
Please help me
6nchris said:
Ist it maybe possible, to delect or chrash the current Firmware and then installing the ruu again? I don't know, where the information about the verify Pin is saved.
Click to expand...
Click to collapse
please help me if your know how to verify or bypass Pin verification

Can downloade mode be locked on sumsung devices and if so, can you unlock a locked download mode

i've read a blog post somewhere which talks of the possibility to lock a sumsung download mode, how can this be done or undone?
thelite said:
i've read a blog post somewhere which talks of the possibility to lock a sumsung download mode, how can this be done or undone?
Click to expand...
Click to collapse
Can you provide more details?
The bootloader lock prevents flashing and booting of unsigned images. With a locked bootloader, download mode does not accept custom software; all software packages must be OEM signed.
An unlocked bootloader (with Knox Guard disabled) will allow flashing custom firmware, such as TWRP recovery.
So, in that sort of sense, I suppose the bootloader lock does control what download mode will accept via Odin.
V0latyle said:
Can you provide more details?
The bootloader lock prevents flashing and booting of unsigned images. With a locked bootloader, download mode does not accept custom software; all software packages must be OEM signed.
An unlocked bootloader (with Knox Guard disabled) will allow flashing custom firmware, such as TWRP recovery.
So, in that sort of sense, I suppose the bootloader lock does control what download mode will accept via Odin.
Click to expand...
Click to collapse
im on the sumsung galaxy a032F, there is no oem unlock in developer options so i guess i cannot unlock the bootloader, and when i try to flash a custom firmware via odin i get an error mdm mode can't download odin. so after reading the blog post i was wondering, could the download mode be locked
thelite said:
im on the sumsung galaxy a032F, there is no oem unlock in developer options so i guess i cannot unlock the bootloader, and when i try to flash a custom firmware via odin i get an error mdm mode can't download odin. so after reading the blog post i was wondering, could the download mode be locked
Click to expand...
Click to collapse
im a newbie and i could be wrong about all this, but its been 2 days and googling has not hepled
thelite said:
im on the sumsung galaxy a032F, there is no oem unlock in developer options so i guess i cannot unlock the bootloader, and when i try to flash a custom firmware via odin i get an error mdm mode can't download odin. so after reading the blog post i was wondering, could the download mode be locked
Click to expand...
Click to collapse
Ah, ok. That makes a little more sense.
The bootloader has to be unlocked in order to flash custom firmware.
The process works like this:
Turn on OEM Unlocking in Developer Options (allows bootloader to be unlocked)
Boot device into unlock mode - starting with device off, hold both Volume buttons and plug in USB cable)
Follow device instructions to unlock (will wipe data)
Boot into system, allow system to connect to Internet to disable Knox Guard
Reboot into download mode, use Odin to flash TWRP
Use TWRP to flash custom ROM
So, if OEM Unlocking is not available, you can't do any of this, because that is the first step.
Unless you have factory restarted your device within the last week, no oem unlock means no custom firmware. You have the snapdragon variant, right?
V0latyle said:
Ah, ok. That makes a little more sense.
The bootloader has to be unlocked in order to flash custom firmware.
The process works like this:
Turn on OEM Unlocking in Developer Options (allows bootloader to be unlocked)
Boot device into unlock mode - starting with device off, hold both Volume buttons and plug in USB cable)
Follow device instructions to unlock (will wipe data)
Boot into system, allow system to connect to Internet to disable Knox Guard
Reboot into download mode, use Odin to flash TWRP
Use TWRP to flash custom ROM
So, if OEM Unlocking is not available, you can't do any of this, because that is the first step.
Click to expand...
Click to collapse
thanks for the answer, but i was wondering is there a way in which the oem unlock option can be hidden and unhidden or some way in which you can be prevented from unlocking the bootloader, because even the wipe data/factory reset is disabled, i came across this kind of devices and i was just curious is this entailed in android development or what material can you recommend if i want to know more about this
thelite said:
thanks for the answer, but i was wondering is there a way in which the oem unlock option can be hidden and unhidden or some way in which you can be prevented from unlocking the bootloader, because even the wipe data/factory reset is disabled, i came across this kind of devices and i was just curious is this entailed in android development or what material can you recommend if i want to know more about this
Click to expand...
Click to collapse
Bootloader lock doesn't prevent a factory reset. The screen you showed is recovery mode, not download mode. That's really strange, I've never seen factory reset hidden before
thelite said:
i get an error mdm mode can't download odin.
Click to expand...
Click to collapse
I think this is the clue. You have a organization managed device with an MDM lock (Mobile Device Management). MDM is used by enterprise IT departments to manage devices and can prevent bootloader unlocking as well as factory reset.
Let me guess, you bought this device used?
V0latyle said:
Bootloader lock doesn't prevent a factory reset. The screen you showed is recovery mode, not download mode. That's really strange, I've never seen factory reset hidden before
I think this is the clue. You have a organization managed device with an MDM lock (Mobile Device Management). MDM is used by enterprise IT departments to manage devices and can prevent bootloader unlocking as well as factory reset.
Let me guess, you bought this device used?
Click to expand...
Click to collapse
yes, i got this device from somebody for experiment, just to see if i can go past all this, and yes the screen i showed is a recovery mode screen, i was showing the hidden factory reset option. any help how i can go about this
thelite said:
yes, i got this device from somebody for experiment, just to see if i can go past all this, and yes the screen i showed is a recovery mode screen, i was showing the hidden factory reset option. any help how i can go about this
Click to expand...
Click to collapse
I think your only option is to find out which company the phone belonged to before. If they removed it from their fleet, they can probably remove the MDM lock. This is actually pretty common - enterprise managed devices will be "retired" from fleet service and sold without being properly decommissioned - they're wiped, but the IT department doesn't remove the MDM lock.
They might or might not unlock it for you, but it doesn't hurt to ask.
V0latyle said:
I think your only option is to find out which company the phone belonged to before. If they removed it from their fleet, they can probably remove the MDM lock. This is actually pretty common - enterprise managed devices will be "retired" from fleet service and sold without being properly decommissioned - they're wiped, but the IT department doesn't remove the MDM lock.
They might or might not unlock it for you, but it doesn't hurt to ask.
Click to expand...
Click to collapse
so technically i can't find a way around it myself, i just have to request the company
There is no way I know to bypass it.
There are lots of videos online if you Google “ bypass mdm lock android “
thelite said:
so technically i can't find a way around it myself, i just have to request the company
Click to expand...
Click to collapse
MDM locks typically can't be removed by the end user. That's the whole point - to prevent employees from using devices inappropriately and removing them from enterprise management via factory reset
Kolay gelsin hocalarım telefon kendi kendine Samsung yazısında kaldı revovery kullanamıyor bende Odin ile stok rom attı kilit açmadan
Şuan telefon indir sadece tek giriyor başka hiçbir şey açılmıyor OEM kilit ve frp kapalı
Take it easy, my teachers, the phone is stuck in the Samsung text itself, cannot use revovery, I have a stock rom with Odin, without unlocking it Now the phone is downloading only one entry nothing else does not open OEM lock and frp is off

Categories

Resources