[Q] Encryption, custom recoveries, unlocked/relocked bootloader and security

Search This thread

himgil

Member
Nov 23, 2013
13
9
Rather technical and controversial topic but I got something really bothers me. I'm about to root my nexus 5 and have checked on xda, reddit, and various forums regarding to possible threats to unlocked bootloaders and security concerns for custom recoveries.

I will certainly encrypt my phone, but not sure how custom recoveries will react to that. Will they work? If so, will they compromise my security? Should I bother with installing stock recovery and re-locking my bootloader? This guy* seems to know what he's talking about, and there are some apps** to ease this process. However, there are loads of forum posts by senior posters assuring that one shouldn't bother with all those.

Being new to android, what advice can you give to me?

ps. sorry for the links. being new to forums, I'm not allowed to embed links into my posts.

*android.stackexchange.com/questions/36830/whats-the-security-implication-of-having-an-unlocked-boot-loader
**play.google.com/store/apps/details?id=net.segv11.bootunlocker
 

himgil

Member
Nov 23, 2013
13
9
Rather technical and controversial topic but I got something really bothers me. I'm about to root my nexus 5 and have checked on xda, reddit, and various forums regarding to possible threats to unlocked bootloaders and security concerns for custom recoveries.

I will certainly encrypt my phone, but not sure how custom recoveries will react to that. Will they work? If so, will they compromise my security? Should I bother with installing stock recovery and re-locking my bootloader? This guy* seems to know what he's talking about, and there are some apps** to ease this process. However, there are loads of forum posts by senior posters assuring that one shouldn't bother with all those.

Being new to android, what advice can you give to me?

ps. sorry for the links. being new to forums, I'm not allowed to embed links into my posts.

*android.stackexchange.com/questions/36830/whats-the-security-implication-of-having-an-unlocked-boot-loader
**play.google.com/store/apps/details?id=net.segv11.bootunlocker


In case anyone come across the same problem in the future, I wrote my first impressions on the issue.

First and foremost, I easily rooted my phone by following this: xdaforums.com/showthread.php?t=2507905

Installed ClockworkMod (CWM) and Koush's Superuser (because it's a free software in Stallman terms), then encrypted my phone.

Later on, installed following trio:

Bootlocker: to allow me to change the state of my bootloader's locking situation
Flashify: to flash the stock recovery by replacing CWM
Cryptfs Password: to change my encrypted partition password.

I don't have any problem whatsoever regarding the performance or stability. Everything is great so far. So, for those who concern for their security of their data, I'd recommend it.