TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Stop using 6-digit iPhone passcodes

26 点作者 sc90超过 4 年前

8 条评论

aeternum超过 4 年前
There&#x27;s no evidence the 6-digit passcode was the issue here. It is more likely the thieves immediately turned off the device then used an (offline) chain of vulnerabilities to pull sensitive data off the phone. That&#x27;s typically how these hacks go.<p>If no vulnerabilities are available, the thieves will often just keep the phone offline until one becomes available.
评论 #24280219 未加载
评论 #24278808 未加载
easton超过 4 年前
Why didn’t he click to wipe the device but keep it in lost mode? I could’ve sworn that was an option, and based on the attackers movements, they would have had to put the iPhone back on the internet at least for a couple minutes to get the Apple ID reset, which would’ve been enough time for the wipe command to process.
rvz超过 4 年前
This.<p>Use a complex password never written down just like you do with a master password for a password manager.<p>Also set it to wipe your phone after 10 tries so that thieves can never obtain your details like this.
评论 #24278443 未加载
salmon30salmon超过 4 年前
Wait. If his phone was unlocked while it was swiped, the thief could have simply kept it unlocked through interaction throughout the entire heist. Why make it more complex than that?
2OEH8eoCRo0超过 4 年前
Shouldn&#x27;t the security chip use it&#x27;s own timer to make you wait longer and longer between failed attempts?
评论 #24278386 未加载
jtsiskin超过 4 年前
Why spend $2,500 on in-app purchases? This makes it seem like this app is somehow colluding with the thieves?
评论 #24278825 未加载
RandomBacon超过 4 年前
Maybe the theives are on the lookout for anyone entering their passcode into the phone in public. If they manage to see the passcode or swipe pattern, then they&#x27;ll steal the phone.<p>I&#x27;ve never seen anyone take steps to prevent others from seeing their passcode or swipe pattern in public.
n3k5超过 4 年前
Grubby wrote about this yesterday:<p>&gt; <i>I [used a 6-digit passcode] thinking, basically, that even though a 6-digit passcode is less secure, anything truly dangerous like disabling Find My iPhone requires my iCloud password as well. It simply never occurred to me that if a thief (or law enforcement, or any adversary) has the device passcode, and your iCloud password is in your keychain, they can get your iCloud password from your keychain. All you need is the device passcode to access all of the passwords in iCloud keychain.</i><p>— <a href="https:&#x2F;&#x2F;daringfireball.net&#x2F;linked&#x2F;2020&#x2F;08&#x2F;24&#x2F;can-thieves-crack-6-digit-iphone-passcodes" rel="nofollow">https:&#x2F;&#x2F;daringfireball.net&#x2F;linked&#x2F;2020&#x2F;08&#x2F;24&#x2F;can-thieves-cra...</a><p>Btw., I&#x27;m sceptical about this part of the original Twitter thread:<p>&gt; <i>why [is a weak passcode] an acceptable alternative to biometric verification to decrypt your keychain</i><p>This assumes that biometric verification is better for this purpose. I don&#x27;t think that&#x27;s the case when the attacker grabbed the device right out of your hand and then gets to work on it for several hours. What your face or fingerprints look like isn&#x27;t all that secret. Fooling the device into accepting a clone as the real thing takes some expertise and special equipment and time — but so does “using some kind of device like the GrayKey”.<p>When it comes to somewhat sophisticated attacks (as opposed to keeping your shoulder-surfing kids from making in-app purchases), Touch ID and Face ID are merely improvements for people who would otherwise use <i>no</i> passcode (or ‘00000’). I hope what they&#x27;ll actually be used for, eventually, is sparing you from having to re-enter the same code you just unlocked your device with ten minutes ago in cases where you had it in your hand or in front of your face that whole time.<p>This would allow for more nuanced threat models. For example, just seeing your home screen and then opening your podcast feed could have a <i>way</i> longer time-out, whereas toggling ‘Find My …’ still requires a password every single time. That sort of convenience would convince me to use these features.<p>But for now, if you want an alternative to a 6-digit code that&#x27;s definitely more secure, use an alphanumeric passphrase. Quoting Gruber&#x27;s post once more:<p>&gt; <i>a 6-character alphanumeric passphrase would take on average 72 years to crack by brute force because it takes 80-milliseconds for the secure enclave to process each guess.</i>
评论 #24279479 未加载