https://developer.apple.com/documentation/security/certifica...
AFAIK that means it'll take more than a jailbreak to get to them, although I don't know if OTP apps are using that capability or not.
https://developer.apple.com/documentation/security/certifica...
AFAIK that means it'll take more than a jailbreak to get to them, although I don't know if OTP apps are using that capability or not.
[1] https://developer.apple.com/documentation/security/certifica...
You (as an attacker) could then recover the key if you had full control of the OS and could trick the user into authenticating so the secure enclave decrypts the key, but would presumably have more trouble if you (as as attacker) simply stole the device.
sure, you wouldn't be able to extract the keys, but what's preventing you from generating thousands of codes and extracting those instead? since they're time based, you could easily generate lots of them for a long time into the future (eg. 10 per day for the next 5 years). that should afford you plenty of opportunities to do a login attempt.