Danger on ice: Android info thaws in cold boot attack

Feb 18, 2013 by Nancy Owano report
Danger on ice: Android info thaws in cold boot attack

(Phys.org)—Can low temperatures yield access to information in the phone's memory? Researchers found that a "FROST" attack can unlock an Android's phone data. Their research findings discuss how hackers can freeze their way into a phone's sensitive data. Researchers at Erlangen University in Germany showed how their cold boot attack method was able to read information from a Samsung Galaxy Nexus running the latest version of Android.

They said the hack can be achieved even if the phone is protected by a PIN and with its storage disk encrypted. They said they chose the from Samsung because it was the first device with Android 4.0 and consequently it was the first Android-based smartphone with encryption support. Also, since it is an "official" phone, they added, it carries an official Android version from Google unmodified by the phone manufacturer. They said that Google releases are most amenable for in-depth security analysis.

In their paper, they wrote, "We present FROST, a tool set that supports the forensic recovery of scrambled telephones. To this end we perform cold boot attacks against Android smartphones and retrieve disk encryption keys from RAM. We show that cold boot attacks against Android phones are generally possible for the first time, and we perform our attacks practically against Galaxy Nexus devices from Samsung."

Authors Tilo Mueller and Michael Spreitzenbarth of the Friedrich-Alexander University of Erlangen-Nuremberg discovered that Android's boot sequence enabled them to perform cold boot attacks, and they observed how valuable information can be retrieved from RAM. According to the researchers, such cold boot attacks can allow the retrieval of sensitive information such as contact lists, visited web sites, and photos, directly from RAM, even though the bootloader is locked. By chilling the Galaxy , the researchers could bypass security settings and read from the phone's memory. The recovery tool FROST stands for Forensic Recovery of Scrambled Telephones.

In chilling the phone to freezing temperatures, the information lingered on in memory for five or six seconds, which was long enough to pull data out with a computer.

Mueller and Spreitzenbarth found they could read data that included images, e-mails and web browsing history.

Their research is not a first in explorations into cold-boot attacks, which were in evidence as early as 2008, shown on PCs. Their research, however, focused on mobile devices.

The authors referred to data remanence, where the computer RAM holds residual information briefly even after the computer is shut down. Mueller observed that in cooling the phone the contents are lost in five or six seconds, enough time to reboot the phone and access the memory. Rebooting a phone more often may leave less in its memory.

On the flip side, their research is not only a warning for users but may be helpful for forensic experts who attempt to recover data from a seized phone.

Explore further: Faster search, better photo sharing in new Android

More information: www1.informatik.uni-erlangen.de/frost
www1.cs.fau.de/filepool/projects/frost/frost.pdf

Related Stories

Google working on phone with built-in payment tool

Nov 16, 2010

Google Inc. is taking another stab at designing a game-changing mobile phone, this time by including a built-in payment system that could eventually enable the devices to replace credit cards.

Recommended for you

Research finds new channels to trigger mobile malware

May 16, 2013

(Phys.org) —Researchers at the University of Alabama at Birmingham (UAB) have uncovered new hard-to-detect methods that criminals may use to trigger mobile device malware that could eventually lead to targeted ...

Fewer Facebook users take a liking to its new Home software

May 16, 2013

It may be too soon to call Facebook Home a flop. But it's clearly not the breakout hit that some expected. One month after its splashy debut, fewer and fewer people are downloading Facebook's new mobile software. It took ...

Google adds player matching to Android

May 15, 2013

Google is adding leaderboards and the ability to match players in online games to its Android operating system for smartphones and tablet computers.

User comments : 4

Adjust slider to filter visible comments by rank

Display comments: newest first

gwrede
5 / 5 (1) Feb 18, 2013
I experimented with my VIC-20 in the early eighties, and found out that its RAM retained all data very reliably if I pulled the power plug for less than a quarter of a second. I then used this for debugging.

Later I had a handy friend install a real Reset Button on it, which felt like real luxury.
PPihkala
5 / 5 (1) Feb 18, 2013
VIC-20 had static RAM (SRAM) while current memories are almost exclusively Dynamic RAM (DRAM). SRAM stores the information in the way the currents flow inside it, whereas DRAM stores the information into tiny capacitors. The charge in those capacitors discharges with time, so each one is refreshed at regular intervals while the memory is in use. The colder the memory the longer it takes to bleed the charge from it's cells. And that is exploited in these cold attacks. They could put sensitive info into SRAM, because that will lose it's state immediately when the current is interrupted. Of course they would need to put those memories into the devices first, before they could use this method.
antialias_physorg
1 / 5 (2) Feb 18, 2013
Yay for the guys from my alma mater.
baudrunner
3 / 5 (2) Feb 18, 2013
Looks like an oversight by the manufacturers. The issue of data remanence could be easily resolved by draining all the energy immediately during shutdown by adding an emitter-follower cascade circuit, much like those used in solid state refrigeration devices.

More news stories

German energy shift faces headwinds

Tense engineers have their eyes peeled on complex colour-coded diagrams on a wall-sized screen that makes their control room look like the inside of a spaceship.

Internet in 'coma' as Iran election looms

Iran is tightening control of the Internet ahead of next month's presidential election, mindful of violent street protests that social networkers inspired last time around over claims of fraud, users and ...

China police billions spell profit opportunity

Mannequins in riot gear, armoured cars and drones line a police equipment and "anti-terrorism technology" trade fair in Beijing as vendors seek to profit from China's huge internal security budget.

Honeybees trained in Croatia to find land mines

(AP)—Mirjana Filipovic is still haunted by the land mine blast that killed her boyfriend and blew off her left leg while on a fishing trip nearly a decade ago. It happened in a field that was supposedly ...

Bold action, big money needed to curb Asia floods

Asia's flood-prone megacities should fund major drainage, water recycling and waste reduction projects to stem deluges and secure clean supply for their booming populations, experts said Sunday.

Mice, gerbils perish in Russia space flight

A number of mice and eight gerbils sent into space in a Russian capsule destined to find out how well organisms can withstand extended flights perished during their journey, scientists said Sunday as the ...