Researchers Explain How Locked Android, iOS Phone Encryption Gets Bypassed

Android is said to be more vulnerable due to its fragmented nature, researchers say.

Advertisement
By Tasneem Akolawala | Updated: 15 January 2021 14:25 IST
Highlights
  • Maximilian Zinkus is one of the researchers behind this study
  • The research says that there are many loopholes for exploiting phones
  • With right knowledge and tools, law enforcement can access phone data

The new research on Android, iOS phone encryption is conducted by Johns Hopkins University

Researchers at Johns Hopkins University have come out with a report that highlights all the vulnerabilities that Android and iOS phone encryption have, and how law enforcement agencies can exploit these to access even locked smartphones. This research comes at a time when governments in various countries are pressuring for backdoors in encryption for accessing data on smartphones when the national security is at stake. However, this new research claims that methods are already available for law enforcement to access locked smartphones of they have the right knowledge and tools, thanks to current security loopholes in the Android and iOS ecosystems.

This new research was reported by Wired, and it has been conducted by Maximilian Zinkus, Tushar Jois, and Matthew Green, of Johns Hopkins University. In their analysis, it is found that Apple does have a powerful and compelling set of security and privacy controls, backed by strong encryption. However, critical lack in coverage due to under-utilisation of these tools allows for law enforcement and other hackers to access the phones if they desire. “We observed that a surprising amount of sensitive data maintained by built-in apps is protected using a weak “available after first unlock” (AFU) protection class, which does not evict decryption keys from memory when the phone is locked. The impact is that the vast majority of sensitive user data from Apple's built-in apps can be accessed from a phone that is captured and logically exploited while it is in a powered-on (but locked) state.”

The researchers also spoke about weakness in cloud backup and services as they found ‘several counter-intuitive features of iCloud that increase the vulnerability of this system.' They also highlight the blurred nature of Apple documentation when it comes to “end-to-end encrypted” cloud services in tandem with iCloud backup service.

Advertisement

The researchers said that while Android also has strong protections, especially on the latest flagship phones, the fragmented and inconsistent nature of security and privacy controls across devices, makes it more vulnerable. The report also blames the deeply lagging rate of Android updates reaching devices, and various software architectural considerations as big reasons for high breach rate. “Android provides no equivalent of Apple's Complete Protection (CP) encryption class, which evicts decryption keys from memory shortly after the phone is locked. As a consequence, Android decryption keys remain in memory at all times after “first unlock,” and user data is potentially vulnerable to forensic capture,” the researchers detail in their post.

Advertisement

Further, it faults de-prioritisation and limited use of end-to-end encryption. Researchers also pointed to the deep integration with Google services, such as Drive, Gmail, and Photos. These apps offer rich user data that can be infiltrated either by knowledgeable criminals or by law enforcement.

Johns Hopkins cryptographer Matthew Green told Wired, “It just really shocked me, because I came into this project thinking that these phones are really protecting user data well. Now I've come out of the project thinking almost nothing is protected as much as it could be. So why do we need a backdoor for law enforcement when the protections that these phones actually offer are so bad?”


What will be the most exciting tech launch of 2021? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Poco X8 Pro, Poco X8 Pro Max to Launch on This Date
  2. SanDisk Extreme Fit USB Type-C Flash Drive Launched in India at This Price
  3. Leaked Renders Show Us What Apple's Rumoured iPhone Fold Might Look Like
  4. Vivo V70 FE Arrives With a 7,000mAh Battery: See Price, Specifications
  5. OnePlus 15T Official Images Confirm 'Squircle' Camera, Two Colourways
  6. Claude Finds 22 Vulnerabilities in Firefox in Just Two Weeks
  7. Poco C85x 5G Key Features Revealed a Day Ahead of Launch in India
  8. Swery65 on Hotel Barcelona's New Update and His Collaboration With Suda51
  1. NASA’s Webb Telescope Confirms Asteroid 2024 YR4 Will Safely Pass the Moon in 2032
  2. ChatGPT Adult Mode Delayed Again as OpenAI's 'Code Red' Reportedly Ends
  3. Lava Bold 2 5G India Launch Date Announced; Confirmed to Feature Under-Display Fingerprint Scanner
  4. Realme Note 80 Launched With 6,300mAh Battery, 6.74-Inch Display: Price, Specifications
  5. Anthropic’s Claude Finds 22 Vulnerabilities in Mozilla Firefox in Just Two Weeks
  6. Samsung Galaxy Smartphones Get Inactivity Restart Security Feature With Latest Update: Report
  7. Poco C85x 5G Key Specifications, Features Revealed a Day Ahead of Launch in India
  8. Rooster Now Available for Streaming Online: What You Need to Know About its Plot, Cast, and More
  9. Bhartha Mahasayulaku Wignyapthi OTT Release Date Reportedly Revealed: When and Where to Watch Ravi Teja’s Romantic Drama Online?
  10. Ghost Elephants Out on OTT: Know Where to Watch This Biographical Film Online
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.