Florent TARDIF
I am doing vulnerability research and reverse-engineering in the Donjon, Ledger's product security team.
Intervention
How safe is the data on your phone? On modern Android phones, all OS data except a minimal boot image is encrypted on the flash memory in a way that is device-bound, so that if we take out the flash and dump it we get nothing of interest. But encrypted with what?
This talk presents our research on cold-storage security on Android against an attacker with physical access. In the process, we uncovered a decade-old vulnerability on Mediatek-based Android phones (CVE-2026-20435), which allows us to recover the PIN and all user data (including Keystore content) from the flash memory of a switched-off phone. Depending on the models, it only takes a USB access and a few minutes, which we will demonstrate during the talk.
