Fully encrypted (full Disk encryption, FDE)
Encrypt all flash data. Performance degradation is greater
Nexus 6,nexus 9 cannot shut down Fde
For other devices. Google recommends opening
Multi-user support
4.2 has increased multi-user support for tablets, but the user configuration is too cumbersome. 4.3 has improved, 5.0 increased support for mobile phones
The user is divided into four categories: Owner, Normal, Restricted, Guest
Normal user cannot see the app installed by owner
The guest user will be cleared at the next logon
BYOD solution: Android for Works (Enterprise security)
V=fbvwtyppzis ">https://www.youtube.com/watch?v=fbvwtyppzis
Securely isolate the work app from the user's private app
Google had intended to use Samsung Knox Lock technology, but finally did not talk about
SELinux
5.0 SELinux runs in enforcing mode in all domains
In the previous 4.4, SELinux was only opened in some important domains
Root is much more difficult
5.0 enhanced SELinux, the normal mode of root almost impossible. Root must be done by brushing the kernel, and the brush kernel needs to be unlocked bootloader, we can lock the bootloader on the basis of 5.0 to achieve root protection
Android 5.0 Five security features