How do we handle forensic imaging of mobile devices with modern File-Based Encryption (FBE)?
Traditional physical imaging seems to be dead for modern Android and iOS devices due to File-Based Encryption. Even with a "logical" acquisition, we are missing so much data from deleted app records. What are current experts doing to get the most data out of a locked iPhone or a modern Samsung device? Are there any bypasses for the latest security patches?
2024-02-05 in Cyber Security by Kevin Foster
| 18378 Views
All answers to this question.
You are correct; the days of easy physical dumps are over. We now rely heavily on "Advanced Logical" or "File System" acquisitions. Tools like Cellebrite or GrayKey are the industry standards for a reason—they leverage specific exploits to bypass the passcode or gain "After First Unlock" (AFU) access. If the device is in a "Before First Unlock" (BFU) state, your options are very limited. One tip is to always put the device in a Faraday bag immediately to prevent a remote wipe. Also, look into "Cloud Extraction" as a supplement. Often, the data you need is backed up to iCloud or Google Drive and can be pulled with proper legal authorization.
Answered 2024-02-07 by Patricia Moore
What about "Chip-Off" forensics? Is that still a viable option for modern UFS chips used in mobile devices, or has the encryption made that technique completely obsolete for evidence recovery?
Answered 2024-02-11 by Thomas Clark
-
Thomas, Chip-Off is essentially useless for modern encrypted devices because even if you get the raw data off the chip, you won't have the hardware-backed keys to decrypt it. Most labs have shifted toward "ISP" (In-System Programming) or simply using specialized software exploits to get a decrypted file system pull. The hardware itself is now a fortress; we have to find cracks in the software to get inside.
Commented 2024-02-14 by James Miller
Don't forget the wear-leveling on SSDs and flash storage. Sometimes deleted data is still "there" but marked as inactive, though FBE makes recovery nearly impossible.
Answered 2024-02-17 by Barbara Taylor
-
Exactly, Barbara. FBE is the ultimate "delete" button. Once the file key is gone, that data is mathematically inaccessible, regardless of what's' left on the physical flash cells.
Commented 2024-02-19 by Kevin Foster
Write a Comment
Your email address will not be published. Required fields are marked (*)

