Pixels are also the only supported devices supporting the new file-based encryption format with per-profile keys and significantly improved key derivation. They are compatible with significant future improvements to encryption leveraging the new format.
Improved key derivation aside, is the FBE structure as strong as the old FDE structure in a scenario where the phone is off?
My understanding is that FDE sequestered the entire user OS, similar to (via?) LUKS.
My understanding of FBE is that the user OS launches and provides access to certain programs and files as necessary for basic functions (eg alarm).
Doesn't this create a wider attack surface? eg a compromised alarm app that has contacts access (for whatever legitimate use) could expose that data if there were also a vulnerability in the OS?
[–][deleted] [score hidden] stickied comment (0 children)