* Wipe after 10 unsuccesful PIN attempts
* Be configured with a 6 digit numeric PIN code
* Be configured with an unlimited alphanumeric password
* Exponentially increase delay between PIN attempts after
unsuccessful entry - for example 3 attempts in 3 seconds,
next attempt after 10 seconds, next attempt after 60
seconds, next attempt after 4 hours, next attempt after
24 hours, next attempt after a week, next attempt in a
year (making up numbers to prove a point)And I don't know for sure, but I feel like that one was fixed at some point.
Edit: Yep, superuser2 links to the CVE: https://news.ycombinator.com/item?id=10423257, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4451
Yep, it was patched: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4451
That HSM is still just a physical machine, and it can be, with difficulty, modified or copied.
To be impossible it would have to be mathematically impossible (or at least not within human time scales).
"Disassemble phone, desolder security module, dissolve the outer layers in hydrochloric acid, cut the silicon into 16nm slices, scan each layer with an electron microscope" impractical.
I'm not sure you understand what an HSM is. It doesn't help to "emulate" one. An HSM performs cryptographic operations under certain conditions (such as correct PIN entry) using internally stored keys. The whole point is that you can't get the keys out, only use them. If you had another HSM, or a logical model of one, it wouldn't contain the right keys.
Certainly as engineered systems, it's possible for HSMs to contain vulnerabilities, but getting the key out of an HSM is a much more sophisticated task than cracking a keyspace of just 10,000 possibilities. Possible, maybe.
[0]http://www.apple.com/business/docs/iOS_Security_Guide.pdf
From a cold boot user data is not loaded into memory until a correct pin has been entered once, and since A5 nobody has managed to compromise their bootchain it is not really viable to exploit either.
http://blog.cryptographyengineering.com/2014/10/why-cant-app...
To break such a system is not impossible, but would require some heroic effort, even nation states would probably resort to some side channel or the proverbial five dollar wrench.
It's actually really impressive.
Of course, there is the potential that Secure Enclave could be updated with new microcode (I have no idea if that is actually possible).
If you actually care about security, use a long alphanumeric password. It's not a big hassle when you have Touch ID. If you are ever in trouble, try turning the iPhone off immediately or quickly touch your fingerprint reader a few times with a wrong finger or enter the passcode wrong five times (so that Secure Enclave discards the cached decryption key and no longer accepts fingerprints). Also, use Apple Configurator tool to make your iPhone "Supervised" and don't let it pair with any new computer. And disable iCloud backup entirely.
What worries me is that this will lead to laws being passed that will criminalize refusal to hand over passwords and encryption keys.
Seems more of a mechanical setup, rather than this guy's video. Like put a kill switch ON THE PATH (i.e. before signals reach) the "Okay iPhone, register this failed attempt" destination.
Other commentors have pointed out that the PIN/crypto stuff is handled by dedicated hardware designed to resist tampering, probably pretty much state-of-the-art. The issue before was a software issue. Now that it's fixed it's very hard to completely hack the hardware and would have to be done to each phone individually: https://news.ycombinator.com/item?id=10424439 I'm not an expert, but I imagine intercepting the signal would be just as hard, as the signal is contained within one tiny chip and it might not even be possible to reliably modify a circuit on that scale. You can't just replace the chip with a no-PIN version either, because it contains a unique crypto key to the data you presumably want from the phone. This also makes modifying the chip difficult, because if you screw up you could lose the key.
[0] https://www.mdsec.co.uk/2015/03/apple-ios-hardware-assisted-... [1] http://forum.gsmhosting.com/vbb/10720367-post1.html