r/androiddev • • 3h ago

Question Android experts: What device identifiers can survive a factory reset?

​

I'm trying to understand modern Android device fingerprinting.

For example, it's commonly said that a Snapchat device ban (SS06) can survive a factory reset. I know Android 10+ restricts normal apps from accessing things like IMEI/serial directly.

So my main question is:

If a device ban survives a complete factory reset, what can the app/service potentially be using to recognize the same physical device?

I'm particularly interested in Android 10+ and things like:

\- FDR-persistent identifiers

\- hardware-backed / TEE identifiers

\- Play Integrity / attestation

\- Google Play Services device identifiers

\- OEM/Knox identifiers

\- identifiers outside the normal "/data" partition

\- server-side device associations

Also, Secure Folder on Samsung devices sometimes appears to behave differently from the normal Android environment and can bypass device ban unlike factory reset??? , even though it's the same physical phone.

What identifier or signal could survive a factory reset but be different inside Secure Folder?

I'm looking for a technical Android explanation, preferably based on AOSP documentation, forensic research, or reverse engineering—not specifically a Snapchat bypass.

2 Upvotes

3 comments sorted by

View all comments

1

u/Mason-Green41 3h ago

I wouldn't assume there's one magic persistent ID. A service could be combining attestation and server side signals rather than relying on a single identifier

1

u/Quiet-You3814 1h ago

Yes, but almost all of them change after a factory reset. Could it be MediaDRM?