11 ms·
Can someone explain how Apple has managed to render brute force ineffective if there are only 10000 possible 4-digit passcodes?
by lemiant 11y ago
Can someone explain how Apple has managed to render brute force ineffective if there are only 10000 possible 4-digit passcodes?
- jansenvt 11y agothe same way everyone else does. they limit the number of attempts you get.
- simmons 11y agoI'm not too familiar with how iPhone hardware is put together, but is there a possibility of performing a forensic extraction of the flash memory and performing a brute-force attack offline? Or does the conversion of PIN to the storage encryption key happen in the secure enclave, which may resist such forensic meddling?
- dogma1138 11y agoYou probably can, but this isn't to access the phone of some international criminal mastermind but of some guy that was picked up on the corner for peddling drugs. Its not like the NYPD can dump 500,000 or more for every phone they need to access. What worries me is that this will lead to laws being passed that will criminalize refusal to hand over passwords and encryption keys.
- mehrdada 11y agoEach iPhone comes with a unique key burned into the processor. I believe the PIN is cryptographically combined with the unique key to derive the encryption key on device. That makes offline brute-force intractable without knowing the unique key (or somehow getting it out of the chip by looking at it or something, but it won't be easy).
- beeboop 11y agoAh yes, the infallible password that's really small and hard to see. I'm sure the guys at the NSA were all "man we'd need, like, a microscope or some shit to read that!" and just went to lunch and called it a day. There is literally nothing Apple could do to have a key of some sort on their processor that wouldn't be laughably easy for a well funded organization to get access to.
- mehrdada 11y agoI am no expert in that sort of stuff, so I have no estimate of the difficulty of it. I'd imagine it's too costly to be worth doing on every random iPhone in every random investigation, but if someone really really wants it, then yes. The weakest link most of the time remains the stupid unencrypted iCloud backup. If you actually care about security, use a long alphanumeric password. It's not a big hassle when you have Touch ID. If you are ever in trouble, try turning the iPhone off immediately or quickly touch your fingerprint reader a few times with a wrong finger or enter the passcode wrong five times (so that Secure Enclave discards the cached decryption key and no longer accepts fingerprints). Also, use Apple Configurator tool to make your iPhone "Supervised" and don't let it pair with any new computer. And disable iCloud backup entirely.
- beeboop 11y agoIf you really care about security from an organization like the NSA, the only option is either to have it be entirely air gapped or to be entirely open source, including BIOS and UEFI firmware and anything else that might run on the hardware. There are really no feasible options, and especially so in phones.
- simcop2387 11y agothe secure enclave stores the actual encryption key. I'm not sure if it's just unlocked or generated from the PIN, but in either case they can only brute force the actual encryption on the flash and not the pin offline.
- risk 11y agoAfter six tries a rate limit is reached. There is no cool down period. You have to connect it to your computer and login to apple, or wipe it.
- awqrre 11y agoIs that rate limit hardware based? or implemented in software? If it's software, they can update it at any time.
- mjcl 11y agoHardware. There is a chip (or a SoC component) called Secure Enclave that holds the real encryption key and accepts PINs or fingerprint data and releases the key. Of course, there is the potential that Secure Enclave could be updated with new microcode (I have no idea if that is actually possible).
- tartuffe78 11y agoThere is an option to "Erase Data after 10 failed passcode attempts"
- mcculley 11y agoAfter a few invalid attempts, it forces you to wait a while before trying again, increasing the wait time each time. One can also set the phone to wipe itself after 10 failed attempts.
- 0x0 11y agoDepending on the settings, the phone could: * Wipe after 10 unsuccesful PIN attempts * Be configured with a 6 digit numeric PIN code * Be configured with an unlimited alphanumeric password * Exponentially increase delay between PIN attempts after unsuccessful entry - for example 3 attempts in 3 seconds, next attempt after 10 seconds, next attempt after 60 seconds, next attempt after 4 hours, next attempt after 24 hours, next attempt after a week, next attempt in a year (making up numbers to prove a point)
- wingerlang 11y agoMaybe fixed now, but there was someone who got around the 10 unsuccessful (an perhaps the last one as well) by shutting the device off after an attempt was failed (like 0.001ms, not manually)
- eridius 11y agoBy "shutting it off" you mean they inserted themselves in between the battery and device and instantly cut power at the right time. Not something that you can easily do to an arbitrary device (especially if you have to give the device back). And I don't know for sure, but I feel like that one was fixed at some point. Edit: Yep, superuser2 links to the CVE: https://news.ycombinator.com/item?id=10423257 https://news.ycombinator.com/item?id=10423257, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4451 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4451
- beeboop 11y agoThese are mostly moot points. They don't have robots trying millions of passwords on phones. They make an image of the phone's memory and brute force it elsewhere. Even a 6 digit code would be cracked in seconds, at most.
- deleted 11y ago[deleted]
- superuser2 11y ago
- djrogers 11y agoAside from the valid points below about rate limits and auto-wiping, the new default is a 6 digit passcode, so more zeros..
- TazeTSchnitzel 11y agoYou can also have a longer, possibly alphanumeric password if you like.
- deleted 11y ago[deleted]
- peterhadlaw 11y agoTo everyone replying to this comment saying that you can set a limit and then the phone will wipe itself after the limit has been reached - that point is moot. Although I wish it wasn't so, there are a couple people who were able to setup a mechanism to brute force an iPhone pin by shutting off the device before it registered an unsuccessful attempt therefore ... giving you limitless potential.
- RexRollman 11y agoApple fixed that in iOS 8.1.1. (CVE-2014-4451).
- scintill76 11y agoThat's patched: https://news.ycombinator.com/item?id=9225317 https://news.ycombinator.com/item?id=9225317 Unless you're talking about a newer instance of the same bug.
- peterhadlaw 11y agoHere is what I was referring to: https://youtu.be/meEyYFlSahk https://youtu.be/meEyYFlSahk Seems more of a mechanical setup, rather than this guy's video. Like put a kill switch ON THE PATH (i.e. before signals reach) the "Okay iPhone, register this failed attempt" destination.
- scintill76 11y agoThe automatic thing is just an automatic exploit of the same issue[0] (forcefully cutting power rather than powering off with the buttons might make it more reliable.) It's called an iPBOX and AFAICT it doesn't support iOS 8.1.1[1], when the issue was fixed. Other commentors have pointed out that the PIN/crypto stuff is handled by dedicated hardware designed to resist tampering, probably pretty much state-of-the-art. The issue before was a software issue. Now that it's fixed it's very hard to completely hack the hardware and would have to be done to each phone individually: https://news.ycombinator.com/item?id=10424439 https://news.ycombinator.com/item?id=10424439 I'm not an expert, but I imagine intercepting the signal would be just as hard, as the signal is contained within one tiny chip and it might not even be possible to reliably modify a circuit on that scale. You can't just replace the chip with a no-PIN version either, because it contains a unique crypto key to the data you presumably want from the phone. This also makes modifying the chip difficult, because if you screw up you could lose the key. [0] https://www.mdsec.co.uk/2015/03/apple-ios-hardware-assisted-screenlock-bruteforce/ https://www.mdsec.co.uk/2015/03/apple-ios-hardware-assisted-... [1] http://forum.gsmhosting.com/vbb/10720367-post1.html http://forum.gsmhosting.com/vbb/10720367-post1.html
- draw_down 11y agoYou don't just get to try 10000 times.
- dankohn1 11y agoMy 6 year old was very excited to find the passcode feature on his iPad and disregarded Daddy's direct warnings that if he kept changing the passcode ("soccer", "baseball", etc.) he wouldn't be able to remember the result and would get locked out. This, of course happened, and after some tears, the solution was for me to remote wipe the iPad and then restore from iCloud backup. The whole process was an extremely impressive mix of security and usability.