10 ms·
Interesting technique, but it doesn't remove the long interval between permitted passcode attempts - an equally important problem for brute-forcing. So the FBI
by geographomics 11y ago
Interesting technique, but it doesn't remove the long interval between permitted passcode attempts - an equally important problem for brute-forcing.
So the FBI would most likely still require Apple's assistance in this.
- albinofrenchy 11y agoIsn't it just a 4 digit pin? Even if they input a pin per minute, that is slightly under a week, worst case scenario.
- kyrra 11y agoiOS9 started defaulting to asking for a 6-digit pin now (though you can still do 4-digit). So it may depend on when the phone was setup.
- 05 11y agoOnly for Touch ID enabled devices
- iLoch 11y agoNo, it uses an exponential back off.
- albinofrenchy 11y agoEven after the 'delete everything' ten attempts? In any case, you can just reboot the phone, and if it does write the number of missed attempts to NAND, you were going to revert that anyway.
- deleted 11y ago[deleted]
- jperras 11y agoIf you can copy the contents of the NAND memory to one chip for testing, then you can copy it to a hundred chips and parallelize the process, assuming I haven't misunderstood the hardware issues at hand (not my specialty, to be fair). The exponential backoff of attempts is not really an issue in that case.
- brk 11y agoThis was my thought too after reading this article. Part of this relies on the specific iPhone 5c from the shooter, because of the per-device hardware key. They ultimately need to unlock that specific phone, with the NAND data intact, in order to read the contents. But, if the passcode is stored in NAND and validated only against user input they could duplicate the NAND and parallelize the process. If any part of the user code check involves the hardware key, then it wouldn't work.
- m_mueller 11y agoIn the article it is specifically mentioned that multiple keys are used for the encryption. There is a secret key burned into the A6 processor that is hard to access without the risk of destroying it. This key cannot be destroyed programmatically, so a secondary key on the NAND is destroyed in case of too many attempts. Only that process could be circumvented with this technique, it doesn't address the increasing interval and AFAIK it is not possible to multiply the hacking process without somehow multiplying the A6 chip - i.e. very hard.
- geographomics 11y agoYou can't parallelise it like that, because the passcode check relies on an unreadable AES key (the UID) that is unique to that particular iPhone.
- jperras 11y agoI guess it would depend, like brk mentioned, on whether or not the passcode is stored in NAND and only validated against user input. I'm out of my depth here, so I'll gladly defer to the experts.
- cwkoss 11y agoWhat is the A6's trusted source for time? Does it have an internal clock, and if so, what happens when it loses power?