3 ms·
Grubby wrote about this yesterday: > I [used a 6-digit passcode] thinking, basically, that even though a 6-digit passcode is less secure, anything truly danger
by n3k5 6y ago
Grubby wrote about this yesterday:
> I [used a 6-digit passcode] thinking, basically, that even though a 6-digit passcode is less secure, anything truly dangerous like disabling Find My iPhone requires my iCloud password as well. It simply never occurred to me that if a thief (or law enforcement, or any adversary) has the device passcode, and your iCloud password is in your keychain, they can get your iCloud password from your keychain. All you need is the device passcode to access all of the passwords in iCloud keychain.
— https://daringfireball.net/linked/2020/08/24/can-thieves-crack-6-digit-iphone-passcodes https://daringfireball.net/linked/2020/08/24/can-thieves-cra...
Btw., I'm sceptical about this part of the original Twitter thread:
> why [is a weak passcode] an acceptable alternative to biometric verification to decrypt your keychain
This assumes that biometric verification is better for this purpose. I don't think that's the case when the attacker grabbed the device right out of your hand and then gets to work on it for several hours. What your face or fingerprints look like isn't all that secret. Fooling the device into accepting a clone as the real thing takes some expertise and special equipment and time — but so does “using some kind of device like the GrayKey”.
When it comes to somewhat sophisticated attacks (as opposed to keeping your shoulder-surfing kids from making in-app purchases), Touch ID and Face ID are merely improvements for people who would otherwise use no passcode (or ‘00000’). I hope what they'll actually be used for, eventually, is sparing you from having to re-enter the same code you just unlocked your device with ten minutes ago in cases where you had it in your hand or in front of your face that whole time.
This would allow for more nuanced threat models. For example, just seeing your home screen and then opening your podcast feed could have a way longer time-out, whereas toggling ‘Find My …’ still requires a password every single time. That sort of convenience would convince me to use these features.
But for now, if you want an alternative to a 6-digit code that's definitely more secure, use an alphanumeric passphrase. Quoting Gruber's post once more:
> a 6-character alphanumeric passphrase would take on average 72 years to crack by brute force because it takes 80-milliseconds for the secure enclave to process each guess.
- innagadadavida 6y agoThis seems more like a UI bug that Apple needs to fix. If the UI doesn’t give any indication of how many digits are expected and _always_ allows me to input both numbers and alpha, then no one can guess these things. Instead there are 4 separate UIs here: 4-digit, 6-digit, 7+ digits, alpha-numeric. Each of them gives an attacker lots of hints. Insecure by design.