Nexus 5 stolen / Bootloader access

Search This thread

THE_KINGDOM

Senior Member
Sep 20, 2011
1,071
137
OnePlus 11
So guys I just had my Nexus 5 stolen at the gym a couple of days ago, I'm very furious about it... I'm unable to track the device with Android Device Manager because the device was dead at the time it had been stolen and probably hasn't been turned on since.

As I imagine the thief will probably fastboot the phone and erase everything, before ever turning it on, or selling it.
My question is, is there not a way to put a startup password on the phone to prevent bootloader/download mode/adb/fastboot access to the phone?

I am also very upset because I called into Google, and there is absolutely no way to have the phones Serial/IMEI "flagged" or "blocked" with Google. Which would be technically such a simple system to implement.
This means that all those people who have had their Nexus 5's stolen, the device can just be re-registered with another Google account at a later date and nobody will blink an eye.

Views? Suggestions?

Thanks
 
Last edited:

spinninbsod

Senior Member
May 17, 2013
682
85
new york city
Wow that sucks you can encrypt your phone that requires a password to startup you may have to have a password to enter fastboot if you encrypt it not sure never done it

Sent from my Nexus 5 using Tapatalk
 

THE_KINGDOM

Senior Member
Sep 20, 2011
1,071
137
OnePlus 11
black listing the IMEI won't prevent somebody from re-registering that device with another Google account though. As it seem Google doesn't track or flag stolen Serial/IMEI.

BUMP to confirm Does encrypting the phone ask for a password at startup?
 

simms22

Recognized Contributor - R.I.P
Jun 4, 2009
34,053
25,934
BROOKLYN!
www.androidcommunity.com
black listing the IMEI won't prevent somebody from re-registering that device with another Google account though. As it seem Google doesn't track or flag stolen Serial/IMEI.

BUMP to confirm Does encrypting the phone ask for a password at startup?

no, but it will prevent the thief from using it on any US or Canadian carrier.

---------- Post added at 12:56 PM ---------- Previous post was at 12:52 PM ----------

black listing the IMEI won't prevent somebody from re-registering that device with another Google account though. As it seem Google doesn't track or flag stolen Serial/IMEI.

BUMP to confirm Does encrypting the phone ask for a password at startup?


can still flash the factory img in the bootloader and not worry about the encryption. also, every single person ive known that has encrypted, eventually(weeks/months) got locked out of their own phones eventually because it wouldnt except a password, and had to flash the factory img.
 

Wh1t3Rose

Senior Member
no, but it will prevent the thief from using it on any US or Canadian carrier.

---------- Post added at 12:56 PM ---------- Previous post was at 12:52 PM ----------





can still flash the factory img in the bootloader and not worry about the encryption. also, every single person ive known that has encrypted, eventually(weeks/months) got locked out of their own phones eventually because it wouldnt except a password, and had to flash the factory img.
Right but the whole point of encrypting is to protect the data not the device. So if a thief has to wipe the device to get rid of the encryption then he won't be able to access the data. It's gone.
 

simms22

Recognized Contributor - R.I.P
Jun 4, 2009
34,053
25,934
BROOKLYN!
www.androidcommunity.com
Right but the whole point of encrypting is to protect the data not the device. So if a thief has to wipe the device to get rid of the encryption then he won't be able to access the data. It's gone.

no, its not gone. its relatively easy to recover the data, even after a factory reset, if the thief wanted to. unless the data is written over.
 
There is an app here on XDA as well as the play store called "bootunlocker" that allows you to lock and unlock your bootloader. Newer versions of Trickster MOD also do this. This way, if someone finds your phone and fastboot OEM unlocks it, it will wipe everything. The only thing we need to do at this point is secure the recovery. As no one seems to think a password protected recovery is necessary as no one has made one, you would have to flash the stock recovery.

If you need to make a nandroid then you would need to unlock and flash custom. This is the only way I can think of to fully ensure data gets wiped in the event someone really knows what they're doing. I might go this route, at least for a little bit to try it out
 

simms22

Recognized Contributor - R.I.P
Jun 4, 2009
34,053
25,934
BROOKLYN!
www.androidcommunity.com
There is an app here on XDA as well as the play store called "bootunlocker" that allows you to lock and unlock your bootloader. Newer versions of Trickster MOD also do this. This way, if someone finds your phone and fastboot OEM unlocks it, it will wipe everything. The only thing we need to do at this point is secure the recovery. As no one seems to think a password protected recovery is necessary as no one has made one, you would have to flash the stock recovery.

If you need to make a nandroid then you would need to unlock and flash custom. This is the only way I can think of to fully ensure data gets wiped in the event someone really knows what they're doing. I might go this route, at least for a little bit to try it out

wiping isnt a solution, as the wiped data is easily recoverable. and password protection for a recovery exists as well, twrp has it. and it also wont help as all you would have to do is flash another recovery via fastboot.

btw, heres a recent article about recovering data from a wiped phone http://www.theverge.com/2014/7/8/5881573/test-shows-data-can-be-recovered-from-wiped-android-phones
 

danarama

Senior Member
Aug 22, 2010
31,277
18,811
Oxenhope, West Yorkshire, UK
no, its not gone. its relatively easy to recover the data, even after a factory reset, if the thief wanted to. unless the data is written over.

Fairly easy as in yes, I could do it. Fairly easy as in a random thief on the street, probably too much trouble and effort.

wiping isnt a solution, as the wiped data is easily recoverable. and password protection for a recovery exists as well, twrp has it. and it also wont help as all you would have to do is flash another recovery via fastboot.

That's why the boatloader is locked. Yep, TWRP implemented Philz recovery lock.

Sent from my Nexus 5 using Tapatalk < Yes, I want you to know that I'm using a mobile client
 
Last edited:

upndwn4par

Inactive Recognized Developer
Jan 22, 2012
3,640
10,375
New Jersey
I say keep trying to locate the device with the Android Device Manager. The thief might not have charged it yet, or even won't at all. Might not be charged until someone buys it. Keep trying, and good luck.
 

simms22

Recognized Contributor - R.I.P
Jun 4, 2009
34,053
25,934
BROOKLYN!
www.androidcommunity.com
Fairly easy as in yes, I could do it. Fairly easy as in a random thief on the street, probably too much trouble and effort.



That's why the boatloader is locked. Yep, TWRP implemented Philz recovery lock.

Sent from my Nexus 5 using Tapatalk < Yes, I want you to know that I'm using a mobile client

the average theif, i absolutely agree. they want to steal the device and collect money for it. but if someone is specifically looking for your data, now that doesnt sound like the average thief, thats who i would want to keep away.

bootloader locked, then unlocked, back to that data being recoverable, not by your average thief.
 

danarama

Senior Member
Aug 22, 2010
31,277
18,811
Oxenhope, West Yorkshire, UK
the average theif, i absolutely agree. they want to steal the device and collect money for it. but if someone is specifically looking for your data, now that doesnt sound like the average thief, thats who i would want to keep away.

bootloader locked, then unlocked, back to that data being recoverable, not by your average thief.

As I've said to you in another thread, there's no protection against that and that's the same with any file system.

Working on national security issues? Don't save data on your phone.

Sent from my Nexus 5 using Tapatalk < Yes, I want you to know that I'm using a mobile client
 
  • Like
Reactions: simms22

simms22

Recognized Contributor - R.I.P
Jun 4, 2009
34,053
25,934
BROOKLYN!
www.androidcommunity.com
As I've said to you in another thread, there's no protection against that and that's the same with any file system.

Working on national security issues? Don't save data on your phone.

Sent from my Nexus 5 using Tapatalk < Yes, I want you to know that I'm using a mobile client

lmao!
whats funny is that either we misunderstood each other, or a penguin was just spotted in the sahara desert(lol), because what you said is what i keep trying to say, theres no real protection. the best protection is that tbe average person doesnt have enough knowledge, patience, time to go after your data on a serious level. but those that are specifically targeting you for your data, those are who you should fear, as the data can be gotten to, if they really want to get it.
 
  • Like
Reactions: danarama

Top Liked Posts

  • There are no posts matching your filters.
  • 1
    If your bootloader wasn't locked lol

    Obviously recovery lock is pointless if either android or bootloader is unlocked.

    Sent from my Nexus 5 using Tapatalk < Yes, I want you to know that I'm using a mobile client
    1
    the average theif, i absolutely agree. they want to steal the device and collect money for it. but if someone is specifically looking for your data, now that doesnt sound like the average thief, thats who i would want to keep away.

    bootloader locked, then unlocked, back to that data being recoverable, not by your average thief.

    As I've said to you in another thread, there's no protection against that and that's the same with any file system.

    Working on national security issues? Don't save data on your phone.

    Sent from my Nexus 5 using Tapatalk < Yes, I want you to know that I'm using a mobile client
    1
    As I've said to you in another thread, there's no protection against that and that's the same with any file system.

    Working on national security issues? Don't save data on your phone.

    Sent from my Nexus 5 using Tapatalk < Yes, I want you to know that I'm using a mobile client

    lmao!
    whats funny is that either we misunderstood each other, or a penguin was just spotted in the sahara desert(lol), because what you said is what i keep trying to say, theres no real protection. the best protection is that tbe average person doesnt have enough knowledge, patience, time to go after your data on a serious level. but those that are specifically targeting you for your data, those are who you should fear, as the data can be gotten to, if they really want to get it.