Under the current mechanism, if a user forgets the unlock password on an Android device, the usual recourse is to wipe the phone’s data and set it up again from scratch. Google’s own documentation likewise advises that, when a device cannot be unlocked, one should perform a factory reset. Then, one should sign back into the Google account previously used, to verify ownership of the device.
This design relates to Android’s Factory Reset Protection mechanism. Its chief purpose is to prevent a stolen phone from being wiped through recovery mode and put back into use. After a reset, the system requires the Google account previously signed in to be entered. Furthermore, if that account cannot be signed into to verify ownership, continued use of the device is likewise affected.
Google Tries Replacing the PIN With Account Credentials
Google has added a new feature related to unlocking via a Google account in the newly released Android 17 QPR2 Beta 5. The feature is not yet enabled; only the related code changes can be seen. According to the code in the beta, if a user forgets their phone PIN or unlock password, they may in future be able to regain access to the device through an already-linked Google account. In this process, this would happen without first having to perform a factory reset. Android Authority’s teardown of the beta detailed how the Unlock with Google Account feature could save a forgotten-PIN situation.
The significance of this feature lies in sparing the user a factory reset that wipes all data outright. After all, for a user without a prior cloud backup, a factory reset means contacts, photos, and various app data are all lost and difficult to recover. Accordingly, this creates a considerable problem.
Likely an Optional Feature, Not Enabled by Default
It is worth noting that Google appears to be preparing this feature as optional rather than on by default. The reason is that a phone’s screen lock is generally regarded as the last line of defense for local data. Consequently, if an attacker obtains both the user’s phone and their Google account credentials at once, they could use this very path to bypass the screen lock. They could then access the data on the phone directly.
For security-conscious users, then, leaving this feature disabled is the safer course. For ordinary users, it becomes a trade-off among data security, account protection, and avoiding data loss. Ultimately, the actual security depends on whether Google requires additional verification, such as two-factor authentication, device trust status, or account-recovery information.
Support Our Threat Intelligence
Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!