OK, so I had no problem doing the PIN encryption with my old GNex.
Now I get the GS4, and go ahead and try to do sthe same thing-set up PIN encryption.
First thing I hit-It won't let you select PIN encryption as a valid security method-you have to select password.
So, yo go ahead and set up password mode, and tell it to do the encryption. Screen goes blank, you see the split andriod for a sec, and then...
It does a normal boot. No indication that its encrypting at all.
Anybody else see this?
Please read forum rules before posting
Questions and help issues go in Q&A
Thread moved
Thank you for your cooperation
Friendly Neighborhood Moderator
I've installed v2 of the wicked rom with the twrp recovery and device encryption won't work. Everything else works fine, but when I go to do the encryption it says that it's encrypting, but it sits at 0%. So not exactly the same as you wazmo, but still is an encryption problem.
Found out phone will encrypt but only with password-no PIN allowed.
I can confirm as well, phone will not encrypt with PIN Unlock, changed to Password and it encrypts now.
Samsung i9305 running stable CM 10.1.3
I've a similar problem except:
1) I'm using a password not PIN
2) I get the green outline android
3) OS and Launcher are both still running but encryption process won't start
Related
Hey All!
I've been browsing the XDA scene for a while after getting my new E4GT back in November, and until now haven't had any sort of problem flashing roms, themes, mods, and the like.
I had flashed the phone back to stock EL29 in order to have a chance to return the phone to my carrier for some USB issues I'm having...
But earlier today, I put a pin code on my phone in order to secure it when being put into a shared locker at my work, and I promptly forgot it. Now here's my problem:
I can't access the phone. I've tried every combination of every pin I think of that I would have used. Now, I wouldn't have thought this would be an issue, being able to hard reset the phone.
Well, it won't let me do any sort of factory reset to the phone without inputting the forgotten pin...
Read online that after 5 failed entries, Android asks for other security info to override pin codes. 50 failed attempts later, no prompts.
Ok no problem, I'll Odin EL29 using the rooted one-click method to put stock back onto the phone. (No Go... requires PIN to even boot system)
Ok I'll flash CWM5 (was able to get in and flash a rom that was on my SD card)
Success! I have a bootable OS now, and can change security.
Go to re-activate PIN security, type in new security code, it accepts it. Lock the Phone, put in the -new-code (that was just made), and it's incorrect.
Reboot CWM5, Wipe Data, Cache, etc. and reboot. Able to access phone again.
Go to try a password based security using a simple password. Lock the phone, put in the new password, and again it's incorrect.
Basically, no matter what I do, if I put a pin or password, it defaults to that forgotten pin code and locks me out of my phone.
Now my question to everyone is this:
Is there a way to wipe the boot-loader security, so it wont override the new settings, so that i can use my own passwords again?
(As a side note, pattern unlocks work)
I think if you had held the power button down, the phone should have rebooted no matter what. A battery pull of course would have too.
Did you do a format all then you reinstalled the rom? You should still do the one-click and reinstall the rom now that the phone is back up to see if the problem still persists.
try last 4 digits of your phone # or 0000.
SilverDFlame said:
Hey All!
I've been browsing the XDA scene for a while after getting my new E4GT back in November, and until now haven't had any sort of problem flashing roms, themes, mods, and the like.
I had flashed the phone back to stock EL29 in order to have a chance to return the phone to my carrier for some USB issues I'm having...
But earlier today, I put a pin code on my phone in order to secure it when being put into a shared locker at my work, and I promptly forgot it. Now here's my problem:
I can't access the phone. I've tried every combination of every pin I think of that I would have used. Now, I wouldn't have thought this would be an issue, being able to hard reset the phone.
Well, it won't let me do any sort of factory reset to the phone without inputting the forgotten pin...
Read online that after 5 failed entries, Android asks for other security info to override pin codes. 50 failed attempts later, no prompts.
Ok no problem, I'll Odin EL29 using the rooted one-click method to put stock back onto the phone. (No Go... requires PIN to even boot system)
Ok I'll flash CWM5 (was able to get in and flash a rom that was on my SD card)
Success! I have a bootable OS now, and can change security.
Go to re-activate PIN security, type in new security code, it accepts it. Lock the Phone, put in the -new-code (that was just made), and it's incorrect.
Reboot CWM5, Wipe Data, Cache, etc. and reboot. Able to access phone again.
Go to try a password based security using a simple password. Lock the phone, put in the new password, and again it's incorrect.
Basically, no matter what I do, if I put a pin or password, it defaults to that forgotten pin code and locks me out of my phone.
Now my question to everyone is this:
Is there a way to wipe the boot-loader security, so it wont override the new settings, so that i can use my own passwords again?
(As a side note, pattern unlocks work)
Click to expand...
Click to collapse
Excuse me if I missed something because I skimmed through your paragraph but I had the same problem with this phone and I followed sfhubs directions to the tee for restoring a phone with a pin code and it worked flawlessly.
http://forum.xda-developers.com/showthread.php?t=1433101
Note #1: Please DISABLE any PIN code you may have created to protect your phone. As a security measure, after the flash, Android will ask you for your PIN, if you have one enabled. It is simpler to have no PIN active. If you forgot your PIN then, after the factory restore, just enter the wrong PIN a few times and it will warn you. Enter the wrong PIN again and it will reset the filesystem.
Click to expand...
Click to collapse
^^^that gets done right after you odin it back to stock or restore it in his words
I am trying to encrypt my sprint GS3 but the encrypting is not working at all.
I made sure the battery is %100 full. I create a good password of letters and numbers. I select encrypt device and wait for it to finish and reboot. After all that, the device reboots like normally and doesn't ask for password in boot menu.
Only when the phone comes to the home screen does it ask for password to unlock the screen.
Right now I have on it the stock android 4.3 rooted.
My encryption used to work fine before on android 4.2 but I forgot to unencrypted the device before upgrading and I think that's what broke the encryption system.
I don't know what other details I need to include here. I have searched google but I couldn't find any posts that describe my situation.
Please Help.
Thank you!
I have a Nexus 5x that I rooted. For a brief time, whenever I booted into TWRP, it would ask for my pin to decrypt the phone and access data. Now however, it does not. Under security settings, it still says the phone is encrypted. I'm not sure if it's still encrypted or not at this point, and I'm not sure what I might have done to disable the encryption. I used to have to enter a pin when I turn it on before it fully boots, like it wouldn't even get to my proper lock screen before I entered it. Now it'll boot to my lock screen, but if I try to use my finger print scanner to unlock it, it'll prompt me for my pin the first time.
Any advice on finding out if it's truly encrypted or not, and if not, how to renable the encryption? If there's any other info needed please let me know.
EDIT: Issue was solved by turning off Taskers accessibility service.
Boot into twrp. Does it ask for your pin? If so, encrypted. If not, unencrypted.
My phone is unencrypted and requires me to enter my password at the lockscreen on a cold boot. In pretty sure that is expected behavior.
Sent from my Nexus 5X using Tapatalk
PiousInquisitor said:
Boot into twrp. Does it ask for your pin? If so, encrypted. If not, unencrypted.
My phone is unencrypted and requires me to enter my password at the lockscreen on a cold boot. In pretty sure that is expected behavior.
Sent from my Nexus 5X using Tapatalk
Click to expand...
Click to collapse
It doesn't ask for my pin... but it does say it's encrypted under the security settings. How do I go about reactivating encryption this case? Any ideas? Thanks for the reply.
Flashing the stock boot image will then encrypt data on next boot.But I have no idea if your rom works with stock kernel.
Search your rom's thread
PiousInquisitor said:
Boot into twrp. Does it ask for your pin? If so, encrypted. If not, unencrypted.
My phone is unencrypted and requires me to enter my password at the lockscreen on a cold boot. In pretty sure that is expected behavior.
Sent from my Nexus 5X using Tapatalk
Click to expand...
Click to collapse
So the phone showing a status of "Encrypted" inside android security is inaccurate if we're on the PureNexus ROM?
IamFuzzles said:
I have a Nexus 5x that I rooted. For a brief time, whenever I booted into TWRP, it would ask for my pin to decrypt the phone and access data. Now however, it does not. Under security settings, it still says the phone is encrypted. I'm not sure if it's still encrypted or not at this point, and I'm not sure what I might have done to disable the encryption. I used to have to enter a pin when I turn it on before it fully boots, like it wouldn't even get to my proper lock screen before I entered it. Now it'll boot to my lock screen, but if I try to use my finger print scanner to unlock it, it'll prompt me for my pin the first time.
Any advice on finding out if it's truly encrypted or not, and if not, how to renable the encryption? If there's any other info needed please let me know.
Click to expand...
Click to collapse
I would guess that you are encrypted with the default password. If you change the password, TWRP would probably ask you for a PIN/password.
So I looked into it some more, and it seems that because I granted Tasker accessibility access, it prevented proper encryption. Turning off Taskers accessibility access fixed the issue. Thanks for the help all.
Hey Guys,
When I got my OP3 I unlocked the bootloader right away and installed FreedomOS to get rid of the bloatware. As this is my first device, which comes with a locked bootloader and decryption, I have some questions about this topic. I was wondering that the encryption does not make any sense when you unlock your bootloader, because if somebody steals your phone, he can just enter twrp and access all your data. Then I flashed CM and after that TWRP was asking me to set a pin or pattern to lock my phone. Now I've to unlock my phone every time I want to enter the recovery or boot the system with a pattern, which is great, because now the encryption is not worthless anymore. Now I'm asking myself if this feature is somehow integrated into CM or was it just random that I found this feature? Is there any way to get this also with OOS installed? What things do I have to note to not accidentally make my phone unencryptable with the pattern? Is this even possible, maybe by flashing a new recovery or so?
Thanks in advance
Gerrit507 said:
Hey Guys,
When I got my OP3 I unlocked the bootloader right away and installed FreedomOS to get rid of the bloatware. As this is my first device, which comes with a locked bootloader and decryption, I have some questions about this topic. I was wondering that the encryption does not make any sense when you unlock your bootloader, because if somebody steals your phone, he can just enter twrp and access all your data. Then I flashed CM and after that TWRP was asking me to set a pin or pattern to lock my phone. Now I've to unlock my phone every time I want to enter the recovery or boot the system with a pattern, which is great, because now the encryption is not worthless anymore. Now I'm asking myself if this feature is somehow integrated into CM or was it just random that I found this feature? Is there any way to get this also with OOS installed? What things do I have to note to not accidentally make my phone unencryptable with the pattern? Is this even possible, maybe by flashing a new recovery or so?
Thanks in advance
Click to expand...
Click to collapse
If your phone is encrypted, TWRP has to prompt you to decrypt the /data partition before it can be mounted. This isn't a CM feature, it should act like this with any ROM if phone encryption is enabled. I've flashed most every rom and version of twrp in this forum and they all seem to work fine with the encryption enabled. I have not flashed multiboot yet as that requires your phone to be completely unencrypted. Not sure if that answers your question.
If security is your concern though, I would recommend switching to a passphrase instead of pattern for encryption unless your pattern is very long and complex. I recommend a passphrase of at least 16 characters.
kennonk said:
If your phone is encrypted, TWRP has to prompt you to decrypt the /data partition before it can be mounted. This isn't a CM feature, it should act like this with any ROM if phone encryption is enabled. I've flashed most every rom and version of twrp in this forum and they all seem to work fine with the encryption enabled. I have not flashed multiboot yet as that requires your phone to be completely unencrypted. Not sure if that answers your question.
If security is your concern though, I would recommend switching to a passphrase instead of pattern for encryption unless your pattern is very long and complex. I recommend a passphrase of at least 16 characters.
Click to expand...
Click to collapse
Ok I see, than I was getting something wrong there, thank you. The thing is FreedomOS stated that the phone is encrypted but I was never asked for the pattern by TWRP...
Gerrit507 said:
Ok I see, than I was getting something wrong there, thank you. The thing is FreedomOS stated that the phone is encrypted but I was never asked for the pattern by TWRP...
Click to expand...
Click to collapse
When you first booted up your stock phone and went through setup it asks if you want to secure the phone using pin/pattern/passphrase. I think that is where it is created then that key is written somewhere, not on the data or system partitions because is persists between wipes, and that is where TWRP and all future roms are authenticating you.
kennonk said:
When you first booted up your stock phone and went through setup it asks if you want to secure the phone using pin/pattern/passphrase. I think that is where it is created then that key is written somewhere, not on the data or system partitions because is persists between wipes, and that is where TWRP and all future roms are authenticating you.
Click to expand...
Click to collapse
Ok, I can not remember this... Then I guess the phone just stated it was encrypted and wasn't... And how can I change this pattern or unencrypt the phone?
Gerrit507 said:
Ok, I can not remember this... Then I guess the phone just stated it was encrypted and wasn't... And how can I change this pattern or unencrypt the phone?
Click to expand...
Click to collapse
Here is how to decrypt without losing data. http://forum.xda-developers.com/oneplus-3/how-to/unencrypt-oxygenos-loosing-data-t3412228
There is another article I think I saw it on the OnePlus forums about how to decrypt and wipe which will let you change the passphrase I think.
Basically if you decrypt, then flash Oxygen or Hydrogen without SuperSU it will force you to re-encrypt. At least that is my understanding as I haven't decrypted yet.
Good luck
kennonk said:
Here is how to decrypt without losing data. http://forum.xda-developers.com/oneplus-3/how-to/unencrypt-oxygenos-loosing-data-t3412228
There is another article I think I saw it on the OnePlus forums about how to decrypt and wipe which will let you change the passphrase I think.
Basically if you decrypt, then flash Oxygen or Hydrogen without SuperSU it will force you to re-encrypt. At least that is my understanding as I haven't decrypted yet.
Good luck
Click to expand...
Click to collapse
As far as I understood it, it's all about wiping userdata, which I did before flashing Freedom OS. This might explain why I had no encryption... Still strange that it did not prompt me again to set a new one...
edit: FreedomOS has supersu, but systemless... I also flashed supersu right after CM which is even more strange...
Gerrit507 said:
As far as I understood it, it's all about wiping userdata, which I did before flashing Freedom OS. This might explain why I had no encryption... Still strange that it did not prompt me again to set a new one...
Click to expand...
Click to collapse
Yeah I have wiped userdata and system and clean reflashed like 20-30 times in the last few weeks and I've never been prompted to recreate the initial passphrase I set for encryption.
kennonk said:
Yeah I have wiped userdata and system and clean reflashed like 20-30 times in the last few weeks and I've never been prompted to recreate the initial passphrase I set for encryption.
Click to expand...
Click to collapse
But I never had to decrypt in TWRP... It's mysterious As far as I understand the guide he just wipes userdata and the encryption is gone... Is there somebody who knows for sure where the key is located actually?
edit: Seems like the encryption key is coupled to your password
When a user elects to change or remove their password in settings, the UI sends the command cryptfs changepw to vold, and vold re-encrypts the disk master key with the new password.
Click to expand...
Click to collapse
https://source.android.com/security/encryption/
I can confirm that. I changed my pattern and unlocked the phone with it at booting.
If I remove my password it still says "encrypted" in security but I don't have to enter any pattern at boot.
Mine says "Encrypted" under Settings > Security & Fingerprint > Encryption but I can boot into TWRP and browse the entire file system without ever entering my pin code.
dcdruck1117 said:
Mine says "Encrypted" under Settings > Security & Fingerprint > Encryption but I can boot into TWRP and browse the entire file system without ever entering my pin code.
Click to expand...
Click to collapse
Sounds like you have the same issue like I had. It seems to me like an issue in OOS.
This is awesome. I thought rooting and unlocking the bootloader to install custom ROMs would need the phone to be decrypted -- great, great news!
So without knowing the passphrase a possible attacker can't get to the data even when the bootloader is unlocked and OS rooted?
kanttii said:
This is awesome. I thought rooting and unlocking the bootloader to install custom ROMs would need the phone to be decrypted -- great, great news!
So without knowing the passphrase a possible attacker can't get to the data even when the bootloader is unlocked and OS rooted?
Click to expand...
Click to collapse
Yes, all your data is being decrypted after your enter the passphrase.
Does anyone have any idea how I can encrypt my phone if it already says Settings > Security & fingerprint > Encryption > Encrypt phone = "Encrypted"? It's clearly not actually encrypted because I do not have to enter any pin to boot or read data in TWRP.
dcdruck1117 said:
Does anyone have any idea how I can encrypt my phone if it already says Settings > Security & fingerprint > Encryption > Encrypt phone = "Encrypted"? It's clearly not actually encrypted because I do not have to enter any pin to boot or read data in TWRP.
Click to expand...
Click to collapse
Go to lock screen settings and set it up again. You will be prompted if you want to enter pin every reboot.
proag said:
Go to lock screen settings and set it up again. You will be prompted if you want to enter pin every reboot.
Click to expand...
Click to collapse
Hey, thanks! The "require PIN to start device" screen doesn't make any mention of encryption, so I was under the impression that it was far more basic and wasn't at all related to encryption. I tried it though and now TWRP does ask me to decrypt my data partition, so it does work. Thanks for the assist!
been following this thread and i had a quick questions - so it looks like if you unlock BL and run a custom ROM, you can still have the security of encryption, but does this ONLY apply to the USERDATA partition?
for example, could someone launch TWRP recovery on your phone and flash something into the SYSTEM partition without ever touching your userdata partition (ie, a keylogger or malware)?
It seems to me that only the data partition is encrypted, but someone correct me if I'm wrong. I looked at the Android full disk encryption page and I only see mentions of the data partition.
dcdruck1117 said:
It seems to me that only the data partition is encrypted, but someone correct me if I'm wrong. I looked at the Android full disk encryption page and I only see mentions of the data partition.
Click to expand...
Click to collapse
so system is never encrypted? i guess at that point the stock recovery stops you from flashing malware but \TWRP wont
dcdruck1117 said:
It seems to me that only the data partition is encrypted, but someone correct me if I'm wrong. I looked at the Android full disk encryption page and I only see mentions of the data partition.
Click to expand...
Click to collapse
Your internal storage is mounted into your data partition actually. I think this means it's also encrypted.
2x4 said:
so system is never encrypted? i guess at that point the stock recovery stops you from flashing malware but \TWRP wont
Click to expand...
Click to collapse
I see no reason behind encrypting system, it's used read-only anyway as long as you don't flash something to it.
edit: Ah I see now what you mean. But if you have stock recovery you can also simply flash twrp over it or flash something to system via adb... I don't know if it would even be possible technically to encrypt system. Anyway I think the only solution would be to lock the bootloader I think. I don't know what actually happens if you lock your bootloader again while on twrp and custom rom, might brick your device
Dear All,
I'm a happy owner aof a brand new OP9Pro. Just upgraded from an older OP3.
I already installed LineageOS on it, the latest one with Android 12.
I noticed, that in Settings-Security-Encryption and credentials the Encryption status says Encrypted. This is good, it is just like my old OP3 used to be. However, unlike in the case of the OP3, when booting up, the OP9Pro doesn't ask for a password or pin or anything, just boots fine. What is going on here? If it is not encrypted, then why does it say encrypted. If it is encrypted, then what is the password/pin and why does it auto decrypt.
More importantly, how can I correct this issue? (to be clear, I would like to create my own encryption password and want to enter it every time the system boots)
What am I missing?
viktak said:
Dear All,
I'm a happy owner aof a brand new OP9Pro. Just upgraded from an older OP3.
I already installed LineageOS on it, the latest one with Android 12.
I noticed, that in Settings-Security-Encryption and credentials the Encryption status says Encrypted. This is good, it is just like my old OP3 used to be. However, unlike in the case of the OP3, when booting up, the OP9Pro doesn't ask for a password or pin or anything, just boots fine. What is going on here? If it is not encrypted, then why does it say encrypted. If it is encrypted, then what is the password/pin and why does it auto decrypt.
More importantly, how can I correct this issue? (to be clear, I would like to create my own encryption password and want to enter it every time the system boots)
What am I missing?
Click to expand...
Click to collapse
Go into settings/security and lock screen/lock screen passcode
I have done that, but no matter which one I set up, it wouldn't ask for it when the phone boots.
viktak said:
I have done that, but no matter which one I set up, it wouldn't ask for it when the phone boots.
Click to expand...
Click to collapse
Then I don't know what the answer would be. All I know is that I see so many users having issues with custom roms. That is why I stay with stock rom.
I'm too old for cherry picking and starting fresh each round. F all that. C-63 is pretty damn righteous. And Ob1 is awesome so ob2 is gonna be a dd I feel.
viktak said:
Dear All,
I'm a happy owner aof a brand new OP9Pro. Just upgraded from an older OP3.
I already installed LineageOS on it, the latest one with Android 12.
I noticed, that in Settings-Security-Encryption and credentials the Encryption status says Encrypted. This is good, it is just like my old OP3 used to be. However, unlike in the case of the OP3, when booting up, the OP9Pro doesn't ask for a password or pin or anything, just boots fine. What is going on here? If it is not encrypted, then why does it say encrypted. If it is encrypted, then what is the password/pin and why does it auto decrypt.
More importantly, how can I correct this issue? (to be clear, I would like to create my own encryption password and want to enter it every time the system boots)
What am I missing?
Click to expand...
Click to collapse
Every time you reboot your phone, you must enter your password/PIN if you set one to get past the lock screen, it's called Before First Unlock. It doesn't ask for a password to turn on your phone, just to get past the lock screen. Also, the keys are not in memory, so this is the encryption part.
ok, thanks. Something must have changed though since Android 11. Thank you for the clarification!