MediaTek Extraction: Physical Acquisition With File-Based Encryption


We often hear that digital forensics can access anything these days but sometimes that just isn't the case. This attack still ultimately required knowledge of the users passcode to succeed. Every attack I've seen has needed either that, or needed the device to be after-first-unlock state to extract the keys. It seems that as long as a device has a reasonably long passcode and is in before-first-unlock state, forensics will not have much luck getting any data off it.

