4 ms·
Not only do they hide it under a group policy even when you enable an "Enhanced PIN" there is a maximum length of 20.
by CircleSpokes 3y ago
Not only do they hide it under a group policy even when you enable an "Enhanced PIN" there is a maximum length of 20.
- cma 3y agoWhy do they do this, Samsung does the same tiny length limit for Secure Folder. Is it law enforcement requested?
- bflesch 3y agoyes
- copper-float 3y agoSource? That would be very shocking.
- wyager 3y agoWould it? Apple crippled iCloud image encryption for years at the request of federal LEAs.
- _georgesim_ 3y agoCan you share a source for this please? Not finding anything useful.
- wyager 3y agoI have no idea if anyone has covered it. It's industry knowledge. Source: me I figured it would be generally known at this point, especially with the whole perceptual hash debacle (intended to satisfy LEAs despite the plan to finally enable image encryption). I'm not sure what the internal politics looked like after the perceptual hash snitch got axed - my friends who would know quit Apple by then.
- asldkfjaslkdj 3y ago[flagged]
- Spooky23 3y agoWhy? The FBI pitched a fit over access to a shooter’s phone in the press a few years ago, then stopped. Now, you have a multiple products on the market that can crack passcodes by utilizing flaws that allow you to brute force PINs, which are by default 6 digit numbers. (Despite most guidance demanding 8)
- rasz 3y agoCellebrite UFED Cellphone Forensic Extraction Device Teardown https://www.youtube.com/watch?v=7LLGGCXH9MQ https://www.youtube.com/watch?v=7LLGGCXH9MQ UFED, get it? its right in the name :] Video has little demonstration with older phones, one click bypass for all passcodes.
- halJordan 3y agoDespite the "hurr, durr; I'm cynical" responses, you're not insane, it would in fact be shocking.
- rasz 3y agohttps://en.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States https://en.wikipedia.org/wiki/Export_of_cryptography_from_th... >Later provision was added to allow export of 56-bit encryption if the exporter promised to add "key recovery" backdoors by the end of 1998. First SSL crippled to 40-bit RC2/RC4 First 802.11 wireless protocol WEP "64" key length shortened to 40 bits https://en.wikipedia.org/wiki/A5/1 https://en.wikipedia.org/wiki/A5/1 vs https://en.wikipedia.org/wiki/A5/2 https://en.wikipedia.org/wiki/A5/2 >to allow the British secret service to eavesdrop more easily. The British proposed a key length of 48 bits, while the West Germans wanted stronger encryption to protect against East German spying, so the compromise became a key length of 54 bits >Documents leaked by Edward Snowden in 2013 state that the NSA "can process encrypted A5/1"
- halJordan 3y agoIt's because tpms are small and have small storage. The outrageous "its a secret cabal" voices are a prime example of what people cook up when faced with something they cant explain due to ignorance but feel the need to have an answer. Its as outrageous as a Republican saying "Q did it."
- Dylan16807 3y agoWondering if something was requested by law enforcement isn't implying a cabal, chill. Also a couple kilobytes of flash costs basically nothing. And you could hash keys over a certain length, which is much better than having such a short limit on a human-typed string.
- bootsmann 3y agoA couple of kilobytes of flash also doesn't come with the protections the tpm offers (or at least is supposed to offer, considering the article in the OP)
- salawat 3y agoIf you'd like to provide schemata, open standards and source code for them, then don't keep the class waiting. Don't/can't? Then you're a fool trusting someone else to do something you yourself cannot inspect. Then again, most people seem to be oddly fine with that. I am not of that number.
- intelVISA 3y agoas a 1337 pwn3r the TPMs are fine source: just trust me bro
- jasonjayr 3y agoSure they are small little embedded chips, supposedly physically hardened from tampering. but argon2($string_of_any_length) should produce a fixed-length byte string, no?
- 3y ago
- IYasha 3y agoAny key strength limitation is mandated by... certain forces. This is not a secret (anymore). "If anything in consumer tech can be weakened, make sure it is".