4 ms·
"Our initial analysis indicates that the IP Box is able to bypass this restriction by connecting directly to the iPhone’s power source and aggressively cutting
by therealwill 12y ago
"Our initial analysis indicates that the IP Box is able to bypass this restriction by connecting directly to the iPhone’s power source and aggressively cutting the power after each failed PIN attempt, but before the attempt has been synchronized to flash memory"
My guess is that Apple is only synchronizing after the failure animation completes. Should be easy to patch.
- rando3826 12y agoI highly doubt it. And I doubt they will patch it.
- madeofpalk 12y agoWhy would you doubt they would patch it? Everything indicates that Apple takes this type of security somewhat seriously.
- urda 12y agoYeah Apple is pretty serious on security honestly. I expect to see a patch or write up here shortly.
- dan1234 12y agoLooks like it might have been patched already. FTA: >Further research suggests this could be the issue detailed in CVE-2014-4451 but this has yet to be confirmed. We plan to test the same attack on an 8.2 device and will update with our progress.
- Usu 12y agoThe article was posted a week ago, but there are no updates about iOS 8.2 as of today and since it shouldn't be too long to just upgrade iOS and see if after 10 attempts the device gets wiped I'm guessing that the fix for CVE-2014-4451 actually patched this but the news wasn't as interesting as it would've been "iOS 8.2 vulnerable too" to update the post with
- ikeboy 12y agohttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4451 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4451 https://www.youtube.com/watch?v=2Bok9Zgas6g https://www.youtube.com/watch?v=2Bok9Zgas6g It was fixed in 8.1.1