Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

Researchers bypass Android encryption by exposing phones to freezing temperatures

Security researchers in Germany have discovered that physically freezing an Android smartphone can grant access to encrypted data.


Researchers freezing a Galaxy Nexus, via Friedrich-Alexander University.

Google's encryption method, which has been a part of Android since the "Ice Cream Sandwich" release, was bypassed by exposing a smartphone to freezing temperatures for an hour, according to the BBC. After that time period, researchers were able to access previously encrypted contacts, browsing histories, and photos.

The test was conducted by researchers from Friedrich-Alexander University in Germany with Samsung Galaxy Nexus handsets, and the phones were cooled to 10 degrees below zero Celsius. Then the battery was quickly disconnected and reconnected, placing the handset into a vulnerable mode.

"This loophole let them start it up with some custom-built software rather than its onboard Android operating system," the report said. "The researchers dubbed their custom code Frost — Forensic Recovery of Scrambled Telephones."

Frost
The "FROST" hack in action, via Friedrich-Alexander University.

The strange and involved process of bypassing Android encryption is not likely a concern to end users of Android devices, but could be an issue for corporations and governments that carry highly sensitive information on mobile devices. The researchers said that while they tested their methods with the Galaxy Nexus, other Android phones are also likely to be vulnerable.

Freezing the phone reportedly aids in the hacking of Android because the low temperatures cause data to fade from internal chips more slowly. Researchers used this phenomenon to obtain encryption keys and unscramble the phone's encrypted data.



55 Comments

tallest skil 14 Years · 43086 comments

And now the spin: "Apple phones just break when they're that cold! At least Android keeps working!"

solipsismx 13 Years · 19562 comments

You'd think something called Ice Cream Sandwich could withstand freezing temperatures. PS: Beat you to it, [B]GTR[/B]. :D

igriv 12 Years · 1177 comments

Is that why they call it "ice cream sandwich"?

jragosta 17 Years · 10472 comments

Now, that's a really strange one. Not only the fact that the bug exists, but the fact that someone was able to find it.

malax 16 Years · 1596 comments

This sounds like bad science fiction. Impressive work by those Germans.