{"id":17587,"date":"2020-01-29T10:45:19","date_gmt":"2020-01-29T18:45:19","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2020\/01\/29\/news-11322\/"},"modified":"2020-01-29T10:45:19","modified_gmt":"2020-01-29T18:45:19","slug":"news-11322","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/01\/29\/news-11322\/","title":{"rendered":"How to Get the Most Out of Your Smartphone&#8217;s Encryption"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5e30c958347f2e0008d36101\/master\/pass\/Security_phoneencryption-158682817.jpg\"\/><\/p>\n<p><strong>Credit to Author: David Nield| Date: Wed, 29 Jan 2020 13:08:22 +0000<\/strong><\/p>\n<p class=\"byline bylines__byline byline--author\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\"><span class=\"byline__name byline--with-bg\"><a class=\"byline__name-link\" href=\"\/contributor\/david-nield\">David Niel<span class=\"link__last-letter-spacing\">d<\/span><\/a><\/span> <\/span><\/p>\n<p class=\"content-header__row content-header__dek\">Both iPhones and Androids are encrypted by default. But there are steps you can take to safeguard your data on backups and messaging apps.<\/p>\n<p>You may not think much about encryption day to day, but it\u2019s the reason the <a href=\"https:\/\/www.wired.com\/story\/apple-fbi-iphone-encryption-pensacola\/\">FBI can&#x27;t easily get<\/a> at the data on the iPhones that come into its possession; it also means if someone steals your phone, they won&#x27;t be able to get anything off it without the PIN code.<\/p>\n<p>In terms of individual apps, it stops anyone snooping on <a href=\"https:\/\/www.wired.com\/2016\/04\/forget-apple-vs-fbi-whatsapp-just-switched-encryption-billion-people\/\">your WhatsApp<\/a> and <a href=\"https:\/\/www.wired.com\/story\/ditch-all-those-other-messaging-apps-heres-why-you-should-use-signal\/\">Signal conversations<\/a> when they\u2019re in transit from one device to the other\u2014and that includes anyone who works at WhatsApp or the Signal Foundation. In short, it makes it much, much harder for anyone to get at your photos, messages, documents, and everything else you&#x27;ve got stored on your phone. Here\u2019s how to make sure it\u2019s working for you.<\/p>\n<p>It was the 2014 release of iOS 8 that encrypted every iPhone back to the 4S by default. Much to the chagrin of various law enforcement agencies, that encryption has only gotten tougher over time.<\/p>\n<p>Everything on an iPhone is locked down as soon as you set a PIN code, a Touch ID fingerprint, or a Face ID face\u2014your PIN, fingerprint, or face acts as the key to unlock the encryption, which is why you&#x27;re able to read your messages and view your files as soon as your phone is unlocked.<\/p>\n<p>This is also why you should never leave your phone lying around unlocked if you value the data on it. You can configure the screen lock on your iPhone by going to <strong>Face ID &amp; Passcode<\/strong>\u2014or <strong>Touch ID &amp; Passcode<\/strong>\u2014on the iOS <strong>Settings<\/strong> menu. If you go the PIN route, use <a href=\"https:\/\/www.wired.com\/story\/smartphone-security-101\/\">at least a six-digit alphanumeric code<\/a>. Anything shorter, or using numbers only, is <a class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/appleinsider.com\/articles\/18\/04\/16\/researcher-estimates-graykey-can-unlock-a-6-digit-iphone-passcode-in-11-hours-heres-how-to-protect-yourself&quot;}\" href=\"https:\/\/appleinsider.com\/articles\/18\/04\/16\/researcher-estimates-graykey-can-unlock-a-6-digit-iphone-passcode-in-11-hours-heres-how-to-protect-yourself\" rel=\"nofollow noopener noreferrer\" target=\"_blank\">too easy<\/a> for forensic devices to brute force.<\/p>\n<p>Encryption extends to backups of your iPhone made through Apple&#x27;s own software too, whether that&#x27;s on the web in iCloud, or in iTunes or Finder on a connected computer. (Tap your name at the top of the iOS <strong>Settings<\/strong> screen, then <strong>iCloud<\/strong> and <strong>iCloud Backup<\/strong> to set which one you&#x27;re using.) You can choose to leave local iTunes or Finder backups unencrypted if you want, via the tick box labeled <strong>Encrypt local backup<\/strong> on the <strong>Summary<\/strong> or <strong>General<\/strong> tab.<\/p>\n<p>iCloud backups are encrypted, but Apple can potentially get at them if needed.<\/p>\n<p>However, there\u2019s a crucial distinction between data on your iPhone and data in your iCloud backups. While the latter are encrypted and thus protected against hackers, Apple does hold its own key to decrypt them, and will pass the data on to law enforcement if forced to. Apple will also use it to help you regain access to your backup if you lose it. If that\u2019s a concern for you, keep your backups stored locally on a Windows or Mac laptop.<\/p>\n<p>The encryption picture used be a patchy for Android, but in the last three or four years most new Android smartphones\u2014including the popular Samsung Galaxy and Google Pixel lines\u2014have come with encryption enabled by default. You can check this under <strong>Advanced<\/strong> and <strong>Encryption and credentials<\/strong> in the <strong>Security<\/strong> page of <strong>Settings<\/strong>.<\/p>\n<p>As with iOS, the PIN code, fingerprint, or face that you&#x27;ve set up to unlock your phone acts as the decryption key, unscrambling the data on your phone and allowing you to read it. From <strong>Settings<\/strong> in Android, pick <strong>Security<\/strong> then <strong>Screen lock<\/strong> to set this up.<\/p>\n<p>Only the cheapest, low-end Android devices\u2014usually the ones sold in developing nations\u2014aren&#x27;t encrypted, to ease the demands on the scarce system resources of those phones. That is <a href=\"https:\/\/www.wired.com\/story\/android-encryption-cheap-smartphones\/\">starting to change<\/a> now too, with the latest encryption protocols able to be run by even low-end devices.<\/p>\n<p>If you&#x27;re using Google&#x27;s own cloud services (you can double check by going to Settings, then System, Advanced, Backup) your backups are fully encrypted as well\u2014and there&#x27;s no way in through the back, as there is with Apple&#x27;s iCloud backups. Even Google can&#x27;t access your data in the cloud.<\/p>\n<p>Android&#8217;s built-in backup function encrypts your data.<\/p>\n<p>If you&#x27;re using a different cloud backup service with your Android phone, then you need to check whether or not it supports encryption for its backups, whether they&#x27;re stored on the web or on a connected computer. If you can&#x27;t find a satisfactory answer, or there&#x27;s no sign of any encryption, you can always switch to Google&#x27;s built-in option.<\/p>\n<p>WhatsApp uses end-to-end encryption, but its Google Drive backups don&#8217;t.<\/p>\n<p>While your phone\u2019s encryption protects the files on the device, plenty of data finds its way out into the ether. Here it&#x27;s important to look out for end-to-end encryption, where data is protected while it&#x27;s been transferred and when it&#x27;s being stored. This type of encryption will thwart hackers, law enforcement, and the tech companies themselves from snooping on your messages. Just remember, though, that it won\u2019t hide your data if someone manages to get access to your device itself.<\/p>\n<p>In terms of security practices and comprehensiveness, Signal leads the way for end-to-end encrypted messaging apps, while iMessage and WhatsApp also offer the feature. Facebook Messenger, Telegram, and Skype also offer end-to-end encrypted conversation modes, but they&#x27;re not switched on by default.<\/p>\n<p>Consider cloud backups of your messages as well. We\u2019ve already talked about how Apple can theoretically get at some of your data if it&#x27;s stored in an iCloud backup, which <a href=\"https:\/\/www.wired.com\/story\/paul-manafort-bad-tech-pdfs-passwords\/\">Paul Manafort learned the hard way in court<\/a>. If you&#x27;re backing up WhatsApp messages to Google Drive in the cloud, it&#x27;s important to note that these backups aren&#x27;t encrypted when they&#x27;re stored.<\/p>\n<p>In other words, always check the small print for the apps and services you use. Instagram messages aren&#x27;t encrypted, for example, although it&#x27;s something Facebook is apparently working on. End-to-end encryption has also been promised for messages inside Gmail for years, but isn&#x27;t here yet.<\/p>\n<p>Using services without end-to-end encryption doesn&#x27;t mean your data is necessarily at a high risk of being exposed, and any kind of encryption is better than none. But it does mean government agencies or the app developer might be able to get at your data, if needed. As always, <a href=\"https:\/\/www.wired.com\/story\/delete-old-apps-accounts-online\/\">the fewer apps and services<\/a> you&#x27;re using, the better.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/smartphone-encryption-apps\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5e30c958347f2e0008d36101\/master\/pass\/Security_phoneencryption-158682817.jpg\"\/><\/p>\n<p><strong>Credit to Author: David Nield| Date: Wed, 29 Jan 2020 13:08:22 +0000<\/strong><\/p>\n<p>Both iPhones and Androids are encrypted by default. But there are steps you can take to safeguard your data on backups and messaging apps.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21466],"class_list":["post-17587","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-security-advice"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17587","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17587"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17587\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17587"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17587"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17587"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}