Homeinet"Hole" in Android encryption | Which devices are at risk

"Hole" in Android encryption | Which devices are at risk

[su_heading size=”18″ margin=”40″]Security gaps related to encryption measures on Android smartphones put millions of users at risk.[/su_heading]

Android encryption

And while some Google- related vulnerabilities have already been patched, there are some security holes related to Qualcomm's Snapdragon processors that have been marked as unpatchable.

[su_spacer size=”50″][su_spacer][/su_spacer]In our recent article we talked about a dangerous malware that can root users’ Android smartphones without their knowledge. And although users, in their attempt to protect themselves, use various antivirus solutions, Google’s security features still face numerous challenges from time to time. This time, security researcher Gal Beniamini, identified a series of dangerous vulnerabilities, which put millions of Android users at risk.

More specifically, due to multiple security vulnerabilities in full disk encryption feature , attackers are able to launch a series of brute-force attacks, compromising the security of the platform.

[su_spacer size=”10″][su_spacer][/su_spacer][su_note note_color=”#9ac191″ radius=”7″]And if you’re thinking that Google is going to release an OTA fix that will fix this vulnerability soon, unfortunately it won’t. This time, it’s not a flaw of the internet giant. Instead, the problem lies with Qualcomm’s Snapdragon processors.[/su_note][su_spacer size=”10″][su_spacer][/su_spacer]

Full disk encryption technology protects Android and stops intruders, hackers, and governments from accessing the content stored on your phone. However, researchers have identified weaknesses in the way Qualcomm handles this security mechanism.

[su_spacer size=”10″][su_spacer][/su_spacer][su_note note_color=”#91aac1″ radius=”7″]Android uses secure 2048-bit RSA keys to encrypt files and passwords. However, due to security vulnerabilities, an attacker can easily gain access to these keys and brute force passwords without any attempt to break the encryption.[/su_note][su_spacer size=”10″][su_spacer][/su_spacer]

The researcher is working with Google and Qualcomm to patch the reported security holes. However, there are some vulnerabilities that are solely hardware-related and appear to be unpatchable.

Beniamini says that fixing these vulnerabilities is not simple and the problems will remain until devices are upgraded to newer models.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS