TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Apple iOS Hardware Assisted Screenlock Bruteforce

214 pointsby allendingabout 10 years ago

15 comments

therealwillabout 10 years ago
&quot;Our initial analysis indicates that the IP Box is able to bypass this restriction by connecting directly to the iPhone’s power source and aggressively cutting the power after each failed PIN attempt, but before the attempt has been synchronized to flash memory&quot;<p>My guess is that Apple is only synchronizing after the failure animation completes. Should be easy to patch.
评论 #9223499 未加载
im2w1labout 10 years ago
So it cuts power before the iPhone can store that a failed attempt occurred. It&#x27;s such a simple, stupid, wonderful idea. I love it. Kudos to whoever came up with it.
评论 #9223873 未加载
danielmiesslerabout 10 years ago
This is a legit issue, and you can definitely expect it to be patched quite soon. Not sure how&#x2F;why someone would think it wouldn&#x27;t get patched.<p>Many, many enterprises bet their data on passcodes combined with the 10-guess wipe defense. You can bet that they&#x27;ve already called Apple many times about this.<p>It&#x27;ll be patched very soon.
评论 #9224560 未加载
matthewmcgabout 10 years ago
&quot;As such, each PIN entry takes approximately 40 seconds, meaning that it would take up to ~111 hours to bruteforce a 4 digit PIN&quot;<p>This is where a longer pass-code + TouchID is valuable.
LeoPantheraabout 10 years ago
I have a 9-digit PIN. So I guess I&#x27;m immune from this type of attack? (In any reasonable time, at least.)
评论 #9223877 未加载
评论 #9226410 未加载
azinman2about 10 years ago
Can someone explain to me how the power cut off works? The battery can&#x27;t be removed... And something like this requires precision timing. How can they cut it off then turn it back on without charging the battery? Furthermore, how can it be done every 10 seconds? My iPhone 6 takes longer to boot from scratch.
评论 #9224189 未加载
priz3about 10 years ago
Article mentions brute forcing would take ~111 hrs. That looks like it&#x27;s (10^4 * 40) &#x2F; (60*60) which would be the maximum time needed to brute force.<p>Note for those not good at dividing hours by 24 in your head: 111 hrs is 4.65 days
评论 #9223290 未加载
评论 #9223327 未加载
评论 #9223560 未加载
grecyabout 10 years ago
Why does iOS accept entry of that PIN over the cable and not require it to be &quot;input&quot; on the screen?
评论 #9224409 未加载
评论 #9224043 未加载
评论 #9223932 未加载
评论 #9227202 未加载
评论 #9227070 未加载
评论 #9224749 未加载
padmanabhan01about 10 years ago
Well, one can still remote wipe if the phone is lost. So, while this may still be an issue, it&#x27;s not as bad as what it would have been if that weren&#x27;t an option..
评论 #9223890 未加载
allendingabout 10 years ago
OP here. Devious. Cuts off the power source after failed attempts to get around 10 attempts restriction.
评论 #9223151 未加载
评论 #9224356 未加载
tlrobinsonabout 10 years ago
Can this be used by thieves to unlock iPhones in the Find My iPhone &quot;Lost Mode&quot;?<p>Perversely, &quot;Lost Mode&quot; incentivize thieves to do whatever necessary to unlock your phone, since they can&#x27;t just wipe it and resell it. Apparently it&#x27;s common for thieves to phish the contact phone number displayed on a &quot;Lost Mode&quot; iPhone: <a href="http://www.symantec.com/connect/blogs/cybercriminals-phish-icloud-credentials-victims-iphone-ipad-theft" rel="nofollow">http:&#x2F;&#x2F;www.symantec.com&#x2F;connect&#x2F;blogs&#x2F;cybercriminals-phish-i...</a>
snowwrestlerabout 10 years ago
A five-letter password is not much harder&#x2F;slower to type than a 4-digit PIN, but makes this attack entirely impractical.<p>Even using just lowercase letters, the maximum time expands from 111 hours to about 132,000 hours (15 years) per passcode.<p>Going to six letters expands it to about 390 years.
baneabout 10 years ago
Out of curiosity, anybody know the resolution of the fingerprint reader? I&#x27;m assuming it&#x27;s some kind nxm scanner that could also be brute forced if needed, just take longer.
评论 #9223330 未加载
j0e1about 10 years ago
Anyone know of such a hack on Android phones?
dendoryabout 10 years ago
It takes over 100 hours to brute force a 4 digit PIN.. I&#x27;m not impressed. For further security, everyone should use a longer PIN along with Touch ID, that is what I do.
评论 #9223352 未加载