Apple’s iOS 4 hardware encryption has been cracked
geek.com
geek.com
Also, the tool seems to perform an online attack with the phone connected, which means that Apple will be able to stop this from going on.
Seing that only an online attack can be done hints at the fact that the key derivation method that turns the 4 digit passcode into the AES key isn't known (yet).
I'd say that you are (still) pretty save if you use the longer password instead of the passcode and as long as the tool requires the phone to be connected, we can count on Apple patching the issue.
It's funny how these articles always talk about having "cracked the AES encryption" when all they do is brute-forcing a password.
- Extract hardware-dependent keys, file system keys and escrow keys from the device; - Recover the passcode (subject to passcode length and complexity); - Obtain bit-to-bit copy of device storage.
The difference between the simple passcode and the complex password is the difference between a little padlock and a vault door. It shouldn't be news, except that the fundamentals of encryption aren't well-known by the public.
You can use a longer alphanumeric pass code if you'd rather, it's an option in settings.
As with all security convenience is played off against security. For most people (who in reality aren't likely to be targeted by such an attack and aren't storing much in the way of critical data on their phones) a four digit pass doesn't seem completely unreasonable.
If it gets wiped, just reimage and start where you left off.
Apple really needs to embrace a non-PIN style password and make a way to login that's not a pain in the ass. A friend has an iPhone with a 9-character pass.. it's secure but impossible to use since it takes about 10 seconds to unlock each time... if the user can't be bothered to put a master password because it's not usable to do so, then it almost doesn't matter if there's hardware encryption anyway.
Compared with Google, Apple's views on security are weak. It's like comparing Google's "customer support" to Apple's... demonstrably weaker.
Android uses a nine cell unlock pattern which gives you roughly 16 bits. A four digit numeric key gives you between 13 and 14.
So while it's better it's not moving it into the realms where a brute force attack of this nature is off the table, it just goes from about 40 minutes to about 4 hours.
Given that in most instances where this sort of attack is being used the attacker will have stolen the phone and therefore there's no practical time limit, that's not a useful improvement.
iTunes has a special file on your computer that when you plug in your phone will allow it to start syncing data to and from your phone (including making backups) without requiring you to unlock it.
What I believe they are doing is actually brute-forcing the required entry code for that. Once you get that code (and there is no limit to how many times you can try) you get full access to the phone, including that bit-for-bit copy they are talking about.
Apparently the key space is small enough that it is easy enough to brute-force.
In that case it doesn't matter what kind of protection you use, whether it is the pass code lock, or the alphanumeric that they introduced on the iPhone 4 (IIRC).
Note that all of this is speculation, I have no inside knowledge, but that is how I would go about attacking the iPhone.
put nothing on the internet that you don't want exposed
IMHO, it's not the exposure I'm worried about, but the discrimination that follows. Getting drunk at a party and posting pictures on Facebook should not be grounds for you getting rejected at an interview.Also, talking about exposure, companies that found/asked for my social security number or home address, then exposed it on the Internet, should not be surprised when I sue them for huge amounts of money (I'm doing it right now and the only question is how much money I can win).
I agree with the OP - If you don't want to be discriminated against, keep it off the internet, or it can be used against you.
The only exceptions that I can think of would be those aspects that are considered "protected" - I'm in the rather liberal (but at-will-employment) California, so that includes (at last count, they've probably added more, "age (if over 35), ancestry, color, race, sex (gender), religion, national origin, marital status, physical or mental disability, medical condition, or sexual orientation." - Everything else is fair game. And certainly, drunk pictures of you on facebook would fall within the realm that an employer might reasonably discriminate against you.
If you don't want it used against you, don't place it on the internet, despite the level of protection/encryption/privacy policy you think you have protecting you. The elcomsofts of the world are likely to make your private information less so more quickly than you would think.
it just provides additional information about you - type of drinks, environment, your friends/girls ... - i mean looking at some pictures one may want to join the party, while looking at others - "thanks, no".
This is why I don't sync my phone to my work email. It's just not worth it.
This seems to do decryption on its own, so this setting wouldn't have an effect. If you have the data sitting there and have the encrypted key, there's nothing stopping you from directly decrypting the key with every possible passcode and checking it for validity.
It seems like this is reading the encrypted data and then brute forcing it, but there's no need to give access to even the 'secure' data without asking the user to enter the passcode. Then you can check for 10 incorrect codes and wipe the device if necessary. (I believe this is how the Blackberry handles things)
Does Apple's iOS provide for encryption of all user data? Or is it the case that the app's developer has to avail himself of an API to make this happen?
If you're paranoid, you can make most data reasonably secure by using the built-in apps and apps like StashPro (which does use the hardware crypto API). This includes putting a decent length password, which is also hard to use.
Full-device encryption backed by hardware would be really great. IIRC, that's not possible on either iOS or Android right now (not sure about other platforms).