4 ms·
The attack is a brute force attack. My understanding is that if a secure enclave is present, then the PIN timeout feature which prevents brute force is impleme
by Crito 11y ago
The attack is a brute force attack. My understanding is that if a secure enclave is present, then the PIN timeout feature which prevents brute force is implemented in the secure enclave. If the secure enclave did not permit updates, then this logic would be relatively unassailable.
But since the 5C has no secure enclave, the PIN lockout logic can simply be overwritten by updating the OS.
- criddell 11y agoI think you and I have the same understanding. Even with no secure enclave, if a user picks a good password (which nobody does on a phone), the security is still unassailable.