3 ms·
My understanding was that the malformed update would allow them to bypass the 10-attempt limit and also the delays between attempts, allowing a brute force atta
by 2bitencryption 11y ago
My understanding was that the malformed update would allow them to bypass the 10-attempt limit and also the delays between attempts, allowing a brute force attack. Meaning a device with a sufficiently strong password would still be capable of being secure, barring any secret government technology that we don't know about that can crack 64 character random passwords(which probably does exist).
HOWEVER, if I'm not mistaken, the newer iPhones (the one in question is a 5c) hold the delay-between-attempts limit IN HARDWARE, so a firmware upgrade would do nothing. The encryption is all done in dedicated hardware on the device. Someone please correct me if I'm wrong.
- niij 11y agoYou're correct. Each attempt takes 80ms as a hardware limitation.
- plorg 11y agoEach attempt takes 80 ms. That's in hardware. There is a separate retry delay that increases exponentially then tops out at 1 hour per unsuccessful attempt. The 10-try limit is the number of consecutive unsuccessful attempts before the device erases its stored encryption keys (effectively wiping itself). It seems that the attempt limit at least is not hardcoded and can be updated, as it has been increased in the past by an iOS update. I would suspect the same is true for the attempt retry delay time. Either way, this is only specifically applicable to devices newer than the 5c, which doesn't have a Secure Element (or "Secure Enclave" in Applespeak). In any case, given a software image made to the FBI's specifications, the time to crack a phone depends on the complexity of the user passcode. If the user had a 4-digit numeric PIN it could be cracked in under 15 minutes. On the other hand, with a sufficiently complex passcode the expected time to brute force the device could be literally in the millions of years.