• News
  • 25 November, 2015
Share

74% of all Android devices can have their passcode bypassed if Google is ordered to do so

You know that huge uproar we had about Android security a few weeks ago? Well, looks like we’re in for another round as a new report prepared by the New York District Attorney’s Office has suggested that 74% of all Android devices could have their passcode bypassed by Google if a court order is passed, allowing authorities to remotely access these devices. The reason why this number is so big is because full disk encryption is not necessarily enabled for most devices – in fact, only Android 5.0 and higher devices would be safe, and even then only if it is enabled (and in some cases, it isn’t enabled by default). This is an excerpt from the report:

“Forensic examiners are able to bypass passcodes on some of those devices using a variety of forensic techniques.

For some other types of Android devices, Google can reset the passcodes when served with a search warrant and an order instructing them to assist law enforcement to extract data from the device. This process can be done by Google remotely and allows forensic examiners to view the contents of a device.”

The 74% figure comes from the latest statistics reported by the Android Developer Dashboard, and although that number will continue to decrease as time goes on, it’s not going to disappear overnight. Note however that this number is realistically much lower as the capability to remote reset devices is only available when a device is using the Pattern security measure – PIN and Password security cannot be bypassed this way.

If you do use Pattern, that still leaves the rather confronting possibility that your device could be accessed remotely – naturally, we’re assuming that this power will only be used for good, but it wouldn’t be the first time power has been misused.

What do you think about this capability to bypass passcodes? Let us know your thoughts in the comments below.

Source: New York District Attorney’s Office via The Next Web