Book Image

Learning Android Forensics

Book Image

Learning Android Forensics

Overview of this book

Table of Contents (15 chapters)
Learning Android Forensics
Credits
About the Authors
About the Reviewers
www.PacktPub.com
Preface
Index

Issues and opportunities with Android Lollipop


As noted several times in this chapter, the recent unveiling of Android Lollipop Version 5.0 has introduced many strong security features, which of course creates complications for forensic examiners. It was initially announced that Android Lollipop devices would ship with full disk encryption by default, however, Google later retracted this requirement due to performance issues on many devices. Instead of a requirement, Google only strongly suggests that full disk encryption be enabled when the user first creates an account. Google has also hinted that this will be a requirement in future OS versions, more information can be found in section 9.9 at http://static.googleusercontent.com/media/source.android.com/en/us/compatibility/android-cdd.pdf.

Devices with full disk encryption enabled make bypassing locked devices all but impossible, because even if the key files could be recovered, they would be encrypted; though surely the commercial tool...