3 ms·
Are you sure you can brute force the PIN? I thought the iPhone will enforce a waiting period after too many bad entries.
by tocomment 13y ago
Are you sure you can brute force the PIN? I thought the iPhone will enforce a waiting period after too many bad entries.
- miles 13y agoAre you sure you can brute force the PIN? Yep: Elcomsoft iOS Forensic Toolkit[1] * Instant passcode recovery for all iOS versions up to iOS 3 * Simple 4-digit iOS 4/5/6 passcodes recovered in 10-40 minutes [1] http://www.elcomsoft.com/eift.html http://www.elcomsoft.com/eift.html
- objclxt 13y ago> Yep: Elcomsoft iOS Forensic Toolkit[1] I think you missed the fairly huge disclaimer hidden away at the bottom of the page: > iPhone 4S, iPhone 5, iPad 2+, iPad Mini and iPod Touch 5th gen support is limited to jailbroken devices only (iOS 5 and 6). The chances of a target device being jailbroken are not particularly large. This should, of course, serve as a reminder that if you are running a jailbroken device you should probably have a passcode a little more complex than four digits!
- miles 13y agoThere are many other forensic acquisition products for iOS[1] as well as a number available to law enforcement only; I think it's safe to say that relying on your iPhone's PIN code for protection is probably not a good idea. [1] http://www.appleexaminer.com/iPhoneiPad/iOSAnalysisTools/iOSAnalysisTools.html http://www.appleexaminer.com/iPhoneiPad/iOSAnalysisTools/iOS... EDIT: This device was found on the AppleExaminer page: http://www.cellebrite.com/forensic-solutions/ios-forensics.html http://www.cellebrite.com/forensic-solutions/ios-forensics.h... "Using UFED Physical Analyzer, physical and file system extractions, decoding and analysis can be performed on locked iOS devices with a simple or complex passcode. Simple passcodes will be recovered during the physical extraction process and enable access to emails and keychain passwords. If a complex password is set on the device, physical extraction can be performed without access to emails and keychain. However, if the complex password is known, emails and keychain passwords will be available."
- mpyne 13y agoNot only does it enforce a waiting period, but it will even lock up permanently (can only be reset via iTunes) if there are too many failed attempts. My son has verified this personally...
- jlgreco 13y agoI believe the idea is that if the encryption key is protected with only 4-digits, you could brute-force it offline (if you cracked open the phone and de-soldered stuff). If the encryption key is protected with a secure passphrase (as, for example, PGP private keys typically are) then that attack becomes a lot less feasible.
- dobbsbob 13y agoYeah, the online attack defence like a short password is sufficient to defeat most attacks so long as root is not enabled, and Google/Apple don't comply to remotely unlock the device or reset the password (or you have all google framework apk's ripped out, or not built). The phone should reboot or wipe itself, or timeout or do something besides allowing unlimited attempts. The offline attack you need a password suitable for protecting against police GPU cloud running john the ripper. Android you can set this up (2 different passwords), but should then make a script that deletes adb and su, add it to rc.local and reboot. Also helps to sabotage the recovery partition so it deletes user data should anybody try to flash something to system image There's also mobiflauge, which is experimental deniable encryption and has 2 passwords, one to open a decoy install and one for your secret files full of stolen government intel you took pictures of to fool casual searches, and not ripped apart JTAG forensics.