Conversation

I feel a little bad RT’ing Maciej bashing Google over Android. Google has an amazing security team and the people working on Android security are surely equal to the task and to the people working on iOS. Google has a harder problem to solve than Apple. But: it shows.
3
28
I’m not sure I’m there for the moralizing over Android security (but I see where it comes from.) But if you’re trying to help a campaign lock itself down, that doesn’t matter; there’s a good reason we recommend iPhones, and a whole crowd of nerds loudly pretending otherwise.
1
22
Replying to
Google’s encryption and security posture has been very far behind, and I think some of that represents past corporate priorities *as well* as the fact that they’re solving a hard problem. They have made some good hires recently though....
1
2
This Tweet was deleted by the Tweet author. Learn more
This Tweet was deleted by the Tweet author. Learn more
This Tweet was deleted by the Tweet author. Learn more
He's talking about FBE keys, not the keystore. The keystore has offered functionality for protecting app data at rest for a while, not just with the new unlockedDeviceRequired API. Apps can protect data when locked via the keystore, but it's another layer of encryption on top.
1
Aside from it being more of a hassle (i.e. bringing in a library or making custom code using the keystore), it's also not very efficient to be layering on another layer of encryption. It can also only be hardware accelerated via the CPU crypto instructions, not the crypto engine.