4 ms·
183 days to try 63 million passwords. Roughly 4 per second by my math.. that seems pretty low to me. Any decent password would be uncrackable in that case - but
by Tangokat 5y ago
183 days to try 63 million passwords. Roughly 4 per second by my math.. that seems pretty low to me. Any decent password would be uncrackable in that case - but of course if people mostly use numerical 4 digit passwords that's plenty fast.
- tempay 5y agoI believe the secure enclave, which is responsible for mapping the passcode to an encryption key, has hardware level rate limiting so I suspect GrayKey is limited by that.
- jackric 5y agoWho was smart enough to implement rate limiting there, but not an exponential lockout period?
- bildung 5y agoThe probable standard answer for every large organization: Those were the responsibilities of different teams.
- vxNsr 5y agoThey did, the exploit here is shutting down the phone before it has a chance to log there was a password attempt.
- TwoBit 5y agoDoesn't that apply only to older phones?
- Scoundreller 5y agoSomeone who never got DDoS’d by their own app after their server went down, that’s who.
- dylan604 5y agoHaven't there been stories of parent's losing their phones because their kids randomly entering in passcodes forced the exponential time outs to be into the years (and longer) time frames?
- alias_neo 5y agoI can see it happening. My 1.5 year old daughter routinely locks me out of my phone by touching the in-screen fingerprint reader when she takes my phone from the desk or wherever it's lying around at home. I have a password the maximum length allowed so it's not trivial to unlock when she does that.
- FearlessNebula 5y agoReset the phone and restore from backup
- russh 5y agoNot possible, it is now a paper weight. Found this out when a disgruntled employee “forgot” the passcodes to several devices before quitting.
- tinus_hn 5y agoThat happens when you can’t access the Apple account that has the activation lock for the device. You don’t need the device passcode to reinstall it.
- dylan604 5y agoSeems like it would be safer to enable wipe device after 10 wrong entries than allowing the exponential time out to increase
- spideymans 5y agoThe lockout period progresses something like 60 seconds, 5 minutes, 30 minutes, 1 hour, 3 hours, 6 hours, 1 day and so on. This should only be possible if the child had sole possession of the phone for days. Not saying it’s impossible, but this appears to be an extreme edge case. I suspect most of these reports come from either bugs in the software (and some quick Googling suggests this has been the case), or perhaps that even someone (heck, even a savvy child) was trying using some sort of brute force exploit to unlock the phone.
- hunter-gatherer 5y agoThat's correct. I haven't used graykey for a year or so, so I can't speaj to any updates that have happened in that time. This article wasn't very interesting, and all this information can be found by calling grayshift sales support staff. Ay my shop we didn't actually have a ton of success with graykey because most the devices were BFU. Once the agent is loaded, you can plug the phone into a regular charger and let it brute force itself into the next millenia. But after it tries te first few hundred passcodes, the rate drops significantly.
- 2OEH8eoCRo0 5y agoIsn't this common? I think Intel TPMs use that as well. They have their own clocks. I wonder if you could tamper and inject your own faster clock signal though.
- gruez 5y ago>Any decent password would be uncrackable in that case most people don't use "decent passwords" on their phones, because they have to enter it multiple times a day.