3 ms·
This was my understanding too, but I believe the wording in their (Apple's) whitepaper is unclear now. See this comment chain on HN: https://news.ycombinator.co
by sebk 4y ago
This was my understanding too, but I believe the wording in their (Apple's) whitepaper is unclear now. See this comment chain on HN: https://news.ycombinator.com/item?id=33900004 https://news.ycombinator.com/item?id=33900004 , with the relevant bit being If two-factor authentication is enabled for the user’s account, the device passcode is used to recover an escrowed keychain. (https://support.apple.com/guide/security/secure-icloud-keychain-recovery-secdeb202947/web https://support.apple.com/guide/security/secure-icloud-keych...). I think there must be some misunderstanding here because I can't believe a PIN would be stored by itself, hashed or not, off-device.
Interesting that 1Password switched to GCM. They were previously using CBC with E-t-M HMAC-SHA256.