5 ms·
For context, in 2016 Apple was claiming the six digit passcode would need 5.5 years of brute forcing[0]. Not sure if they still claim the same. [0] https://www
by loteck 3y ago
For context, in 2016 Apple was claiming the six digit passcode would need 5.5 years of brute forcing[0]. Not sure if they still claim the same.
[0] https://www.washingtonpost.com/news/wonk/wp/2016/02/17/how-long-it-takes-to-crack-an-iphone/ https://www.washingtonpost.com/news/wonk/wp/2016/02/17/how-l...
- MiddleEndian 3y ago>“This means it would take more than 5 ½ years to try all combinations of a six-character alphanumeric passcode with lowercase letters and numbers,” Apple security guide says. So given that it took them three years, 3/5.5 means they went ≈54.5% of the way through all the possible combinations. That seems in line with the estimate (assuming all passwords are 6-char alphanumerics).
- rekabis 3y agoThis is why I use more than six numbers in my lock screen pin: the field itself turns from six slots into a single large field, such that you cannot tell if the password is seven digits or seventy. It massively increases the potential address space. Sure, you have an enter key you have to press to submit the pin instead of having it auto-submitted with the sixth digit, but that’s a small price to pay.
- postalrat 3y ago[flagged]
- csoups14 3y agoThe estimate isn't a guarantee of time to crack. If you chose "111111" it wouldn't take 5.5 years and that doesn't mean the estimate is incorrect.
- postalrat 3y agoSo was the estimate how long it would take 5.5 years or half that?
- clipsy 3y agoThe estimate was the time to try all possible combinations, per Apple: > “This means it would take more than 5 ½ years to try all combinations of a six-character alphanumeric passcode with lowercase letters and numbers,” Surely you understand that trying all combinations is not necessary to find an individual password -- you can stop after you've succeeded. Are you really not understanding this?
- postalrat 3y agoI understand that it's misleading.
- pjbeam 3y agoDo you keep searching your house for something after you find it? Apple's claim is an upper bound, it's pretty rare that the thing you're looking for is in the last possible place it could be.
- postalrat 3y agoIt's possible to brute force it in 2 seconds too. In fact just as likely to do that as it is to find the key in the last 2 seconds of a full search. And it would also be misleading for a security firm to say they could brute force it in 2 seconds.
- tinus_hn 3y agoIf it takes 5.5 years to try all combinations, on average it will take half that to find the correct one, because you can stop looking once you found it.
- firecall 3y agoNo, you might get it right within seconds, or it might be the very last number you try. You could flip a coin for a decade and always get heads. The odds don’t change however.
- comprev 3y ago"When searching for something you will always find it in the last place you look"
- firecall 3y agoLOL - I now realise what I've said :-)
- sweetjuly 3y ago> or it might be the very last number you try Well, I would hope it's the last number you try! No use checking more after you've got it :)
- firecall 3y agoOoops LOL Rookie human mistake :-) I of course meant the last number in the sequence....
- quickthrower2 3y agoAny observation from what is a probability distribution is a lie.
- loteck 3y agoI was thinking this through as well but if you were Apple estimating this number, wouldn't you have already done the averaging math to arrive at an estimate of 5.5? Seems to me more likely that speed of Greykey brute forcing improved or Apple's estimate was off.
- MiddleEndian 3y agoI get what you mean, but the quote said "all combinations" specifically. I think they'd choose that wording because that's the biggest number they could report truthfully.
- nanidin 3y agoShouldn’t they technically write “all permutations” for the biggest number?
- furyofantares 3y agoAssuming they started at 000000 this also puts the passcode itself somewhere in the 545000 range. I hope it was 543210.
- bspammer 3y agoIf they really just incremented from 0 they could have done a lot better. I bet the distribution of 6 digit passcodes in the population is far from uniform: * A ton of people just take their 4 digit PIN and append 00 or 01 * Passcodes that are easily convertible to dates. Bonus points for targeting their particular birthday, their family’s birthdays, their pet’s birthday, significant historical dates etc * Passcodes that make a nice pattern on the keypad like 084265 * Passcodes that have a numerical pattern like 024680
- furyofantares 3y agoYeah you'd definitely want to do an intelligent pass before brute force. Might be fun to write something that attempts to sort all the 6 digit numbers based on some heuristics "how likely is this as a human generated passcode"
- spacetime_cmplx 3y agoAs a serious security person, this is why I use 999999 as my passcode
- op00to 3y agoI use 999997. You'd think they'd try 999999, and 999998 and go "fuck this" and try something else.
- SketchySeaBeast 3y agoAll of the best security practices rely on the attacker being easily bored. Thank you attention economy!
- Alifatisk 3y agoWould the probability of guessing all the possible combinations be higher than brute-forcing from 000000 to 999999?