6 ms·
The device in question does not have a secure enclave. It's a 5c.
by zabuni 11y ago
The device in question does not have a secure enclave. It's a 5c.
- d_theorist 11y agoBut it's more interesting to think about the case where the phone does have a secure enclave.
- conradev 11y agoand yet it would be less interesting to consider if the password was a "six-character alphanumeric passcode with lowercase letters and numbers" because even if the software rate-limiting was disabled with a rogue firmware update, the PBKDF2 or similar iteration count makes brute-forcing impractical. > A large iteration count is used to make each attempt slower. The iteration count is calibrated so that one attempt takes approximately 80 milliseconds. This means it would take more than 51⁄2 years to try all combinations of a six-character alphanumeric passcode with lowercase letters and numbers (Page 12 of https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf).
- bluesaunders 11y agoIn that case, they could just bring the phone down to the morgue and unlock it with touch id.
- mef 11y agoTouch ID requires the passcode after reboot or timeout. They'd need to do it very quickly.
- lololomg 11y agoIf the phone is rebooted or if 48 hours have passed since the last passcode was entered, the touch ID can't be used to unlock the phone.
- katbyte 11y agoTouch ID does not work after a reboot, to many attempts or a long of delay. Additionally you don't have to use your thumb, so if you don't know what body part was used your out of luck.