Category: Google|Apr 22, 2025 | Author: Admin

Google adds Android auto-reboot to block forensic data extractions

Share on

Google is rolling out a new security mechanism on Android devices that will automatically reboot locked, unused devices after three consecutive days of inactivity, restoring memory to an encrypted state.

Google adds Android auto-reboot to block forensic data extractions

Although the tech giant has not commented on the exact motives behind the addition of this feature, it is expected to make data extraction by advanced forensic tools harder by bringing devices into a non-exploitable state more often.

 

Auto-reboots after 3 days


The new auto-reboot feature was listed in the latest Google Play services update (v25.14), under 'Security & Privacy.'

 

"With this feature, your device automatically restarts if locked for 3 consecutive days," read the release notes.

 

In January 2024, the developers behind the privacy-centric GrapheneOS warned of firmware flaws in Android that digital forensic companies are leveraging to extract data without the user's authorization.

 

When an Android phone is first started, it enters a Before First Unlock (BFU) state, where most user data remains encrypted and inaccessible until the device is unlocked for the first time. Once the user unlocks it with their PIN or biometrics, the device enters the After First Unlock (AFU) state, which decrypts the user's data, making it accessible for data extraction or surveillance.

 

Devices seized or stolen are typically already in the AFU state, so even if the screen is locked, forensic tools can extract at least some user data from them.

 

To solve this, GrapheneOS for Android devices introduced an auto-reboot mechanism that restarted the system after 18 hours of inactivity, bringing the device back into the "Before First Unlock" (BFU) state. This made the data fully encrypted again and unable to be accessed by forensics companies.

 

Google has now introduced this same feature into Android, though the reboot isn't set to an aggressive 18-hour interval as Graphene. Instead, the device is rebooted after 72 hours of inactivity, with no options to reduce the time.

 

However, this timeframe should still be good enough to block many attacks involving long-term physical access associated with forensic investigations.

 

To further strengthen physical security, it is recommended to turn off USB data transfer when the device is locked.

 

Amnesty International uncovered earlier this year that Cellebrite tools leveraged USB kernel driver flaws in Android to unlock locked devices that had been confiscated.

 

You can install the latest Google Play services update (v25.14) via the Google Play store. However, the update is rolling out gradually, so it may not be immediately available for everyone.

 

Important security updates for Android devices are also made available through Settings > Security & privacy > System & updates > Google Play system update.

Sponsored Ads:

Comments:


Cloudflare-12-06-25.png

Google Cloud and Cloudflare hit by widespread service outages

Category: IT|Jun 12, 2025 | Author: Admin
Outlook-11-06-25.png

Microsoft Outlook to block more risky attachments used in attacks

Category: Microsoft|Jun 11, 2025 | Author: Admin
Google_headpic-10-06-25.png

Google patched bug leaking phone numbers tied to accounts

Category: Google|Jun 10, 2025 | Author: Admin
Vodafone-headpic-09-06-25.png

Germany fines Vodafone $51 million for privacy, security breaches

Category: IT|Jun 9, 2025 | Author: Admin
Microsoft_logo-08-06-25.png

Microsoft unveils free EU cybersecurity program for governments

Category: Microsoft|Jun 8, 2025 | Author: Admin
FBI__headpic-07-06-25.jpg

Play ransomware breached 900 victims, including critical orgs

Category: IT|Jun 7, 2025 | Author: Admin
Cisco-06-06-25.png

Cisco warns of ISE and CCP flaws with public exploit code

Category: IT|Jun 6, 2025 | Author: Admin
Tu-160_strategic_bomber_aircraft-05-06-25.png

Ukraine claims it hacked Tupolev, Russia’s strategic warplane maker

Category: General|Jun 5, 2025 | Author: Admin
salesforce-04-06-25.png

Hackers target Salesforce accounts in data extortion attacks

Category: Google|Jun 4, 2025 | Author: Admin
logo.png

Mozilla launches new system to detect Firefox crypto drainer add-ons

Category: IT|Jun 3, 2025 | Author: Admin
Google_Chrome-02-06-25.png

Google Chrome to distrust Chunghwa Telecom, Netlock certificates in August

Category: Google|Jun 2, 2025 | Author: Admin
Cisco-logo-01-06-25.png

Exploit details for max severity Cisco IOS XE flaw now public

Category: IT|Jun 1, 2025 | Author: Admin
firefox-header-31-05-25.png

Mozilla releases Firefox 139.0.1 update to fix artifacts on Nvidia GPUs

Category: IT|May 31, 2025 | Author: Admin
microsoft-notepad-30-05-25.png

Microsoft now testing Notepad text formatting in Windows 11

Category: Microsoft|May 30, 2025 | Author: Admin
Windows_11_headpic-29-05-25.png

Windows 11 might fail to start after installing KB5058405

Category: Microsoft|May 29, 2025 | Author: Admin
more