4 ms·
Passphrases are always going to be the strongest, but you can have more than 6 digits in your pincode. Select "Custom Alphanumeric Code" in Passcode Options[1]
by thisacctforreal 9y ago
Passphrases are always going to be the strongest, but you can have more than 6 digits in your pincode.
Select "Custom Alphanumeric Code" in Passcode Options[1], but only enter digits using the keyboard. iOS will display a pin pad on the lock screen that will accept any number of digits[2].
I picked this up from the delicious iOS 11 security whitepaper[3].
[1] https://i.imgur.com/KEEC71B.png https://i.imgur.com/KEEC71B.png
[2] https://i.imgur.com/YrgQA5s.png https://i.imgur.com/YrgQA5s.png
[3] https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf
- teilo 9y agoIt was rumors of this process that made me encourage everyone to use a 12-digit or greater passcodes.
- CydeWeys 9y agoI have a 15+ character password that is a mix of alphanumeric and punctuation. I have to enter it at startup and also once per day, which isn't a huge deal. Naturally I use fingerprint/smartwatch authentication throughout my normal day, but once the phone is off, good luck getting access to its contents.
- Twisell 9y agoThis is plainly brilliant. Just done that and the interface seems to not give any clue about the expected number of digits. Meaning that an attacker have no mean to even estimat the time needed to unlock. One could only figure out that complexity of password increased after failing all attempts with less digits (which will already take a lot of time). But of course alphanumerical would be even safer.
- nerdponx 9y agoI love it, but the XKCD wrench comic is fresh in my mind. When I was mugged, they just made me unlock the phone right there on the street.
- wil421 9y agoI would gladly give my passcode if I was mugged. The main issue is either smarter more mischevious criminal, identity thieves and the like, or bad governments. It would be terrible if all airports had these and could crack you on demand. I can imagine them holding you until the device cracks it.
- jostylr 9y agoIt would be nice to have a panic code that one could type in, making it look unlocked, hiding apps a user could mark as secret, and optionally sending a security/tracking alert. This could also thwart a cracking device by making it look cracked at a shorter code, but giving no actually useful info.
- deleted 9y ago[deleted]
- martin_bech 9y agoMany fingerprint systems have this for access. A "Duress" Finger. If you use that finger, the system can be set up for a silent alarm, full on alarm, lockdown or whatever configuration you need.
- xoa 9y agoThat XKCD comic was wrong and one of the rare truly stupid and actively misinformative ones. Security measures are always about responding to threat scenarios and economics, and must in turn be analyzed in context. The general use paradigm for an average device involves many different threats and in turn separate measures for each one. FDE for example is only about protecting from cold attacks, warm/hot ones are just plain out of scope. Similarly, authentication systems (including passcodes and biometrics) are purely about ensuring that only authorized people may gain access with whatever permissions they're authorized for and no more. Their threat scenario and usage does not involve intent. Authentication "primitives" can be used as part of a counter-intent security measure, but by themselves they only determine a "who" not a "why". Strong authentication backed by strong encryption is a stand alone good and a required foundation to do more complex stuff, but that's it. The "wrench" attack is an intent-based threat scenario: the person performing access is in fact authorized, and there is nothing at all buggy, malfunctioning, misdesigned, weak or wrong in any way with an authentication system allowing access. It'd take an intent reactive security measure to deal with. Regrettably there are still no main stream smartphones that implement this as far as I know (though at times it's been possible to do your own to some extent via jailbreaking on iDevices at least and I assume on rooted Android as well). Which is really too bad because Apple in particular have a lot of very good tools at this point to do a really, really good implementation. A classic measure would be coercion/distress codes, ie., alternate passcodes an operator can enter that will cause the device to perform different actions then a straight authentication (these can range from a full deletion to more subtle actions like a silent alarm). Apple though could use TouchID/FaceID to make this even more user friendly, merely "use this finger vs that finger" or "be making this facial expression vs that one" as triggers. They (and anyone else with a secure hardware stack) could also implement temporal and spatial trigger options which would be very useful. Finally the iOS design is decently placed to allow relatively easy and more selective view filters on accessing apps and data due to how heavily everything is silo'd. The silos have been intensely frustrating a lot of the time vs standard computer access patterns, but in this instance it could be a real strength. Imagine being able to have a "travel view" we could set before a trip so that sensitive apps simply vanish until GPS indicates we've arrived at our destination or connected to a specific network or whatever. Or there could be distress views that react to a facial expression or code or finger and then permanently hide everything but a cleaned minimal data and app set, including your cloud stuff, until you get home and enter a special unlock code (or for a set amount of time or whatever). I think intent-systems/view triggers will (or at least should) be the next big leap forward for helping our personal information devices get not just more secure and better for privacy but more productive. I'd like to see that start to show up in future versions of iOS and Android more then nearly anything else.
- chiefalchemist 9y agoBut why not take it a step further and present the standard KB? That would be a slight inconvenience, with a massive gain in confusion for anyone trying to guess their way in.
- Rychard 9y agoI had a bug recently on my Windows Phone after adding my corporate email account to Outlook. I assume it was some sort of group policy being erroneously applied, but it turned out to be a massive inconvenience. Mostly because trying to unlock it displayed the standard keyboard[1], but simply wouldn't allow me to create a PIN with anything other than numeric characters[2], so every time I needed to unlock my phone I had to swipe the screen up, then change the keyboard over to the number/symbol mode, and enter my PIN using the small row of numbers there. In the end, all I had to do was change my pin, and from that moment on, it only ever displayed the standard number pad for unlocking. [1]: https://i.imgur.com/YENnjtY.png https://i.imgur.com/YENnjtY.png [2]: https://i.imgur.com/OaSqLYO.png https://i.imgur.com/OaSqLYO.png
- chiefalchemist 9y agoTo clarify. The PIN pad tells you it's undoubtedly going to be numeric. The keyboard masks that fact. But still allows the entry of a # only PIN. Thanks for the down votes.