Skip to main content

Google can bypass security on all Android systems that don't use full-disk encryption

Android Phone
Image used with permission by copyright holder
Here’s a great reason to switch phones and upgrade to the latest version of Android: At least 74 percent of the Android devices out there can be remotely reset by Google if law enforcement orders the company to do so. The discovery was made in a document released by the New York District Attorney’s Office.

Included in that percentage are all older Android phones running 4.4 and lower. However, Google told the Next Web that remote reset only worked on phones secured with a pattern (not a PIN or password) with older versions of Android. Most devices that run Android 5.0 and up cannot be remotely reset because they enable full-disk encryption by default.

Here’s the catch: Encryption isn’t a mandatory setting in Android 5.0. Some manufacturers don’t enable it, even if it’s an option. In other words, the estimate of 74 percent could actually be low, meaning even more devices are open to remote resets. Luckily, in the case of Android 6.0 Marshmallow, all devices ship with encryption enabled, making them safe from prying eyes.

Google revealed that encryption would be mandatory in a recent Android Compatibility Definition Document. The compatibility document describes various elements of Android 6.0 and defines how it is intended to run on a variety of devices. Those devices that support full-disk encryption and Advanced Encryption Standard (AES) crypto performance above 50MiB/sec, full-disk encryption must have this feature enabled by default. Full-disk encryption utilizes a key for all data that is stored from the disk. Data must pass through the key and be encrypted or decrypted before any data can be either written or pulled into system processes.

Encryption is something that Google has wanted to make mandatory on Android for a while, and the company almost got it completely enforced as a standard when Android 5.0 Lollipop rolled out just a year ago.

The feature’s addition to Android 6.0, along with fingerprint sensors on new phones, have combined to create a higher standard in security than was previously available. Full-disk encryption is not a new feature to Android, but the enforcement of the policy in the setup experience certainly is.

Security aficionados, privacy advocates, and corporate users welcome the higher security standard that the technology provides. The security level also raises the bar that government and police agencies must go through in order to retrieve data from seized devices.

Editors' Recommendations

John Casaretto
Former Digital Trends Contributor
John is the founder of the security company BlackCert, a provider of SSL digital certificates and encryption products. A…
The 6 biggest announcements we expect from Google I/O 2024
Google I/O 2019

Google will hold its annual developer conference, Google I/O 2024, on May 14 in Mountain View, California. The event is about a month away, and we're expecting a few big announcements.

As with any Google I/O event, this year's conference will start with a big opening keynote presentation from CEO Sundar Pichai. But what actual announcements are we looking forward to? Here are a few of the biggest things that we are likely to see at Google I/O 2024.
Android 15

Read more
This crazy headband uses music and brainwaves to make you a better athlete
A person wearing the Alphabeats headband.

This company wants you to put on a headband and listen to music while the device's sensors in it read your brainwaves to help you focus and to increase your sporting performance. It’s called Alphabeats, and the electroencephalogram (EEG) headband combines with your choice of music and an app on your phone to help train your brain to either stay in its top-focused state or concentrate on its requirements in the moment, whether that’s relaxation, recovery, or sleep.

Aimed at professional ahtletes or highly motivated amateurs, Alphabeats won a CES 2023 Innovation award and is now available for pre-order. It costs $499 at the moment, but the price will increase to $689 after the promotional period ends. You probably won’t be surprised to learn (given the recent growing and  unfortunate trend) that this price includes a year’s subscription to the service, but at the time of writing, there’s no information about how much the subscription will cost after the first year.

Read more
Here’s how Apple could change your iPhone forever
An iPhone 15 Pro Max laying on its back, showing its home screen.

Over the past few months, Apple has released a steady stream of research papers detailing its work with generative AI. So far, Apple has been tight-lipped about what exactly is cooking in its research labs, while rumors circulate that Apple is in talks with Google to license its Gemini AI for iPhones.

But there have been a couple of teasers of what we can expect. In February, an Apple research paper detailed an open-source model called MLLM-Guided Image Editing (MGIE) that is capable of media editing using natural language instructions from users. Now, another research paper on Ferret UI has sent the AI community into a frenzy.

Read more