Earlier quoted context omitted.
It’s not at odds with it - it’s pretty obviously using a vulnerability to run a crack against the passcode. Once the passcode is found, that is used to unlock the phone and this the Secure Enclave.
I agree it’s not at odds with it, but it’s not even that simple - the passcode is enforced by the Secure Enclave itself. It’s not a case of “try passcodes until you find the right one then tell the SEP” - it has to be exploiting a vulnerability in the SEP itself, assuming what we know of the design and attack is true.
GrayKey iPhone unlocker poses serious security concerns
61–70 of 97 posts
Re: GrayKey iPhone unlocker poses serious security concerns
#62Earlier quoted context omitted.
>or even better --- not leaving your brain at all. The faintest of ink will outlast the best of memory, or something like that.
"A dull pencil is better than the sharpest mind." Thats the way I've always heard it.
Re: GrayKey iPhone unlocker poses serious security concerns
#63Re: GrayKey iPhone unlocker poses serious security concerns
#64Earlier quoted context omitted.
The DMCA specifically criminalises the circumvention of copyright protection methods , not all access controls.
I’m not a lawyer, but quoting from the Wikipedia article the DMCA “also criminalizes the act of circumventing an access control, whether or not there is actual infringement of copyright itself.” You could argue that you hold copyright on for example a photo you’ve taken, and the passcode is the access control method.
Re: GrayKey iPhone unlocker poses serious security concerns
#65I thought iPhone were electronically secure, it seems they are not. I thought the FBI had to just do some Xray of some chip to read some ROM thing. Sometimes I wonder if real security is really and theoretically possible, or if it's just engineers who never manage to achieve it because designers want things to be usable for consumers. What ever happens it doesn't seem really secure, consumer oriented device do exist.…
Are you willing to pay $500k for a phone? Is there a vendor who is willing to put R&D investment of $20mil so you can buy one? How much more phones they would sell? If you would be Ed Snowden would you even trust that company?
Are you going to buy a safe to keep family photos in it?
What does it even mean for you to have absolutely secure phone if you are going to be hit by a bus tomorrow?
Re: GrayKey iPhone unlocker poses serious security concerns
#66I bet there is lawsuit in works by Apple et al! I mean if they truly broke and iPhone lock, then it means they had to be tampering with a true Apple device (not a dummy) in order to make their device work. Therefore, they violate Apple TOS that I am sure forbids any sort of backdooring. I doubt they will go after a rouge chinese jailbreaker sitting in moms basement and trying to make a name for him/herself, but here…
Re: GrayKey iPhone unlocker poses serious security concerns
#67Passphrases are always going to be the strongest, but you can have more than 6 digits in your pincode. Select "Custom Alphanumeric Code" in Passcode Options[1], but only enter digits using the keyboard. iOS will display a pin pad on the lock screen that will accept any number of digits[2]. I picked this up from the delicious iOS 11 security whitepaper[3]. [1] https://i.imgur.com/KEEC71B.png [2] https://i.imgur.com/Yr…
But of course alphanumerical would be even safer.
Re: GrayKey iPhone unlocker poses serious security concerns
#68If this actually works there has to be some huge, embarrassing vuln in Apple's Secure Enclave Processor on par with the "CTS Labs" AMD secure coprocessor hoopla that hit the news just this week.[1][2] The SEP is supposed to enforce a time delay between passcode attempts to prevent this sort of brute forcing. The timer could be defeated in older models by cutting power at just the right time, but Apple's whitepaper sa…
It seems like they don't have the exponential delays, but they do have delays. Why else would it take 3 days to unlock the phone if it has a 6-digit passcode? Apple's security paper says it would take more than 50 years to brute-force an alphanumeric 6-digit passcode at 80ms per iteration. I suspect that's still correct here (if “3 days or more” is for 6 numeric digits).
Re: GrayKey iPhone unlocker poses serious security concerns
#69Can Apple sue the makers of this program under DMCA anti-circumvention acts?