4 ms·
> Are passwords/passcodes really the only form of entropy used when generating encryption keys for an iphone? I don't believe I ever claimed that. > I'd expec
by dataflow 2y ago
> Are passwords/passcodes really the only form of entropy used when generating encryption keys for an iphone?
I don't believe I ever claimed that.
> I'd expect that a longer password would only increase your security but that even the shortest password wouldn't leave the data encryption trivial to crack.
How short are you talking? Most people do like 4-6 digits. That's not going to protect you against anyone brute-forcing keys on the raw encrypted data. Your only real hope is the TPM holding the real key and being physically secure, which you have no way to ensure. And that still fails due to cameras etc. as mentioned.
> That's partly prevented by having keys randomize their position on the screen
That's almost security theater. It really only protects you from laymen, not state actors. It forces you to use numeric digits if you want that, which itself makes your key much weaker.
> Obviously if a camera is looking directly at the screen while you enter your password you're probably screwed.
Which is guaranteed to happen at some point when you're in public.