• 2 Posts
  • 123 Comments
Joined 1 year ago
cake
Cake day: July 22nd, 2024

help-circle



  • While unlocking the bootloader […] unleashes the full potential of the bootloader, it also poses a security risk. Even with your lockscreen protected with a pattern/PIN/password, not having flashed a custom recovery, having an anti-theft app installed (maybe even converted/installed as a system app) your phone’s data is easily accessible for a knowledgeable thief.

    All the thief needs to do is reboot into the bootloader and boot or flash a custom recovery such as ClockWorkMod or TWRP. It’s then possible to boot into recovery and use ADB commands to gain access to the phone’s data on the internal memory (unless you have it encrypted) and copy/remove files at will.

    Granted, the risk seems low. The thief would not only require knowledge of fastboot, he would have to turn off the phone before you have issued a wipe command using an anti-theft app. You could of course flash back the stock recovery & relock the bootloader after being done with flashing stuff, but that would require you to unlock it again if needed which will erase your userdata.

    Of course, a thief can/is also the government.

    But, most phones can be unlocked by the pigs regardless, with eg. Cellebrite. The best bet is probably a pixel, as it can be relocked easily, with graphene. Or no phone at all.
    Also, I’d guess many Cellebrite tricks work with (weak?) pins/patterns. Use a password, and no fingerprint. And on eg. graphene, the emergency wipe after 10 wrong pws etc.





  • Why tho? I never complained about the way it is, I use testing/nightly/beta/alpha everywhere and I rarely have problems. Also with FF. I was more ranting about myself not realizing that the requirement was gone, considering I, multiple times, upgraded and then e.g. opened a few tabs after, which usually prompted for a restart. And in the end, it’s not gonna change anything, as the point of nightly is to catch any bugs and instabilities, which would very likely only occur after a restart of FF.