7 ms·
This $200 3D printed bot can crack your phone's PIN in 20 hours
- viennacoder 13y agoYou can set an iPhone to auto wipe after 10 wrong tries. Probably a prudent safeguard.
- drakeandrews 13y agoMost android phones have the option to require the user to log into the google account paired with the phone after X failed attempts.
- lucian1900 13y agoAnd that has been the default on all Android phones I've used so far.
- Tyrannosaurs 13y agoThat's quite nice. Escalating to a stronger password after 5 failed attempts seems like a good measure which would got a long way to nullifying this sort of brute force attack. How does logging into the Google account work if the phone is in Airplane mode or whatever where there will be no data connection?
- drakeandrews 13y agoI think at that point the technical term is that you're screwed.
- Tyrannosaurs 13y agoI'm guessing it must be covered - either it won't escalate to the account login or something similar.
- afreak 13y agoThe phone does not need to be unlocked to go out of airplane mode.
- lanstein 13y agoWhat about two-factor auth?
- Tyrannosaurs 13y agoThis is for a smartphone PIN code. Are you suggesting a separate second factor to the physical phone itself?
- JoshTriplett 13y agoPersonally, I'd like the option to set an unlock pin that's weaker than my disk encryption password, and prompt for my disk encryption password (rather than a Google account) if I fail the pin a couple of times.
- rrreese 13y agoYou can also set a proper password on the iPhone (and presumably Android). You should probably have one of these safeguards set up if your phone has unfettered access to your email, social networks, contacts etc.
- LeeHunter 13y agoYes indeed. And even the pin number can be longer than 4 digits (contrary to the article)
- warcode 13y agoInteresting, but then again I get alerted after 3 failed attempts, and I'm pretty sure it locks down after ~10+. An automated version that does combination locks seems like the proper market.
- DrewAllyn 13y agoYou get alerted... on your phone?
- bashinator 13y agoI think it was Feynman who figured out that most combination locks actually have a +/- 1 digit slop on the dial. Between that and peoples' habit of leaving the last digit of the combination set, and you can open it in no more than 25*25=625 attempts for a 50-digit dial.
- k-mcgrady 13y agoYou can switch to using a more complex password on iOS for extra security. On Android pattern unlock would be the obvious solution. Also 20 hours should give you enough time to track down a device using Find My iPhone (or similar service) before they can unlock it and shut tracking down.
- mtgx 13y agoYou can do that with Android, too. It's actually right there in the list with the PIN and pattern locks. I think it has been there at least since Gingerbread, maybe earlier.
- milesokeefe 13y ago>Also 20 hours should give you enough time to track down a device using Find My iPhone (or similar service) before they can unlock it and shut tracking down. Couldn't you just put this whole operation in a faraday cage to bypass that?
- kalleboo 13y agoOr just remove the SIM card...
- Plutor 13y agoPattern unlock has 9 spots, and you need to select at least 4. So the possible number of patterns is: 9!/5! + 9!/4! + 9!/3! + 9!/2! + 9!/1! + 9!/0! Which is just 985,824. And you could certainly search the more likely combinations first -- people almost always select adjacent spots consecutively.
- milkshakes 13y agodoesn't that assume you can only select each pad once?
- jaredmcateer 13y agoYea and you can only select an adjacent spot so that also limits combinations.
- HarrietJones 13y agoiPhone also starts increasing the next allowed retry time after a certain number of incorrect guesses.
- nodata 13y agoI use the app from these guys (http://phonelocatorpro.com/ http://phonelocatorpro.com/) and set mine to wipe after ten tries.
- milesokeefe 13y agoGreat idea except that you just enabled anyone to delete all your data without your permission.
- nodata 13y agoThat's the whole point. If someone gets physical access to my phone, I don't want them to get access to my data.
- gk1 13y agoBut what if someone picks up your phone at a party while you're just a few feet away, and they decide to be a dick? It would take them just a minute to erase all your data.
- joeblau 13y agoAll it would have to do with my phone is swipe up which didn't seem to be programmed into it's actions.
- Recoil42 13y agoArticle is down, but if this is what I think it is... iPhones start increasing the time between allowed guesses geometrically after a few wrong ones, so this wouldn't actually work.
- gk1 13y agoFrom the article (which is back up now, it seems): > Not all phones are as susceptible to the R2B2's cracking. Apple's iOS, for example, increases the time between PIN attempts after each incorrect guess. But there is only 30 seconds delay after every five wrong guesses in Android phone
- tylermac1 13y agoThen after the 30 second delay, if you guess wrong again, it goes up to around 5 minutes. The same happens repeatedly and it can get up to a few hours. I tried on an old iPod touch and got it up to around 4 hours. However, it can be circumvented by restarting the phone.
- kunil 13y agoDoesn't sim card get blocked after 3 tries? Or is this different kind of pin?
- gambiting 13y agoYes, it's talking about the Android lockscreen pin.
- claudius 13y agoBut in the phone’s lockscreen, you are usually not bound by the 4-digit requirement of SIM card PINs, hence can use an arbitrary alphanumeric password (though likely rather short, as you have to enter it often on a small keyboard). 36^5 >> 10^4.
- TylerE 13y agoFor that matter, 36^3 > 10^4, by about a factor of 5.
- peroo 13y agoAndroid phones, and possibly iPhones as well, have multiple options for screen locks, one of which is a pin. That said, it will block pin entry after a set amount of failures after which you have to wait a set amount of time or log in with your Google account. I imagine the wait time scales if you continue guessing, rendering this bot quite useless.
- jaynos 13y agoThey could do it quicker by starting with the most common PINs [1]. This all assumes the build in locks to prevent brute force don't work. [1] http://www.datagenetics.com/blog/september32012/ http://www.datagenetics.com/blog/september32012/
- rpicard 13y agoIt looked like they did. If you watch the video, it starts with "1234" then goes to "0000" and others with no discernible order, other than the fact that they are common choices.
- cmsmith 13y agoThey hit 2580 and 1111 as well before the video cuts out.
- danielamitay 13y agoAs far as I know, they incorporated information from a similar dataset I created back in mid-2011 [1]. [1] http://danielamitay.com/blog/2011/6/13/most-common-iphone-passcodes http://danielamitay.com/blog/2011/6/13/most-common-iphone-pa...
- themstheones 13y agoThis is why only idiots lock their phones.
- 0003 13y agoWhile I try not to underestimate conniving boyfriends, girlfriends, spouses, friends, parents, siblings, children, and grandparents, I am reasonably confident they will not employ a cracker bot from def con when I have momentarily become separated from my phone. For this reason, I lock my phone.
- RutZap 13y agoOr because you might have to use your work email on it, and exchange forces you lock your screen if you want to sync emails. Company policy so that you have a bit of security in case your phone gets stolen. Not everyone would have a robot to try all the PIN numbers just to steal you funny-cat-pictures-work-emails.
- UnoriginalGuy 13y agoI treat pins/pattern as a way to keep casual pranksters and nosey people out of my phone, not as a real "security measure" in the typical sense. If I wanted actual security I would be using a full blown password and full drive encryption (both supported by Android). But then I'd have to turn off all my toys like sync, USB debugging, and unsigned package installation. Which I don't want to do. So therefore I just take my phone being relative insecure as a given, and try to keep out the casual pranksters and or nosey people.
- smackfu 13y agoIt's pretty scary how much damage people can do just by getting access to your email account on your phone though.
- steelaz 13y agoIt seems after loosing your phone you have a few hours to disable access to your email account.
- deleted 13y ago[deleted]
- JoshTriplett 13y agoSync doesn't introduce a security issue. Neither does unsigned package installation, as long as you don't install a package that introduces a security hole. USB debugging is obviously a huge security issue, but you can have USB connections not work with the phone locked, such that you have to enter the password and unlock the phone before you can attach. The real security problem: remote package installation, which Android allows without prompting for anyone signed into your Google account. So, that reduces the security of your full-disk-encrypted phone to that of your Google account, if you tie your phone to a Google account. You can avoid that by not using a Google account, but that means no Play store.
- kin3tic 13y ago
- bizarref00l 13y agoIt's like this hack to unlock a gps http://www.dashfest.com/?p=393 http://www.dashfest.com/?p=393
- taopao 13y agoAndroid has exponential backoff for retries, which would foil this attack, no?
- jamesaguilar 13y agoAccording to the article, they give you a thirty second timeout for each five wrong attempts. That's not enough to prevent this.
- dsl 13y agoiOS has exponential backoff, Android does not.
- maddddddddddddd 13y agohak5 solved this with a USB dongle that acted as a human interface device... it worked was faster too. this is just a dumb way to beat dumb security.
- yulaow 13y agoOnly in my country the simcard after 3 tries ask a PUK code of 8 digits and after 10 tries of it just block definitively the card and only your vendor can unlock it?
- jmah 13y agoThat's to unlock the SIM to start communicating with the network; this is for "screen lock" codes on (typically) smartphones, where the SIM is already unlocked and the phone is already on the network.
- 300bps 13y agoWindows Phone 8 locks for 1 minute after 5 wrong guesses and then doubles every wrong guess after that. So the 6th wrong guess is 2 minutes, the 7th is 4 minutes, etc.
- deleted 13y ago[deleted]
- tankbot 13y agoExcept my iPhone auto-wipes after 10 incorrect entries, and yes there are backups. Take that nosey robots!
- RandallBrown 13y agoI had some coworkers who had their iPads wiped by their children because of this. They didn't even know the feature existed or was turned on (turned on when they connected their work email) so they were pretty annoyed by it.
- qq66 13y agoAfter 5 tries they should make you do some task like drawing a line or sliding a button to allow you to do the second 5 tries, so that random button mashing doesn't wipe your phone.
- mistercow 13y agoI wonder how much the less versatile C3BO version costs to build. It seems to me that you could use a cheap MC, a grid of 10 solenoids, and a simple light sensor to build a version that would work on most touch screens and not have to deal with the hassle of building a 2D plotter, integrating a webcam, and controlling it with a relatively expensive Arduino.
- nrivadeneira 13y agoBecause of the last time a 3d printed cracker bot tried to hack my phone, I now use Android's text password option instead of a pin. Combined with the Swype keyboard, it's actually much easier to unlock my phone than before. You get the ease of the pattern unlock with many more possible permutations.
- antsam 13y agoHm. My phone lets me put the SIM lock up as my lock screen. I guess this would kill my phone pretty fast?