This $200 3D printed bot can crack your phone's PIN in 20 hours
3ders.org
3ders.org
If I wanted actual security I would be using a full blown password and full drive encryption (both supported by Android).
But then I'd have to turn off all my toys like sync, USB debugging, and unsigned package installation. Which I don't want to do. So therefore I just take my phone being relative insecure as a given, and try to keep out the casual pranksters and or nosey people.
USB debugging is obviously a huge security issue, but you can have USB connections not work with the phone locked, such that you have to enter the password and unlock the phone before you can attach.
The real security problem: remote package installation, which Android allows without prompting for anyone signed into your Google account. So, that reduces the security of your full-disk-encrypted phone to that of your Google account, if you tie your phone to a Google account. You can avoid that by not using a Google account, but that means no Play store.
PINs are some of the best security devices we have when implemented right, they work great in eg. EMV payment cards. Passwords/phrases just aren't practical without keyboards when the use case require frequent and low barrier unlocking.
[1] http://danielamitay.com/blog/2011/6/13/most-common-iphone-pa...
Worst case: restore from backup.
> Not all phones are as susceptible to the R2B2's cracking. Apple's iOS, for example, increases the time between PIN attempts after each incorrect guess. But there is only 30 seconds delay after every five wrong guesses in Android phone
However, it can be circumvented by restarting the phone.
Escalating to a stronger password after 5 failed attempts seems like a good measure which would got a long way to nullifying this sort of brute force attack.
How does logging into the Google account work if the phone is in Airplane mode or whatever where there will be no data connection?
An automated version that does combination locks seems like the proper market.
Also 20 hours should give you enough time to track down a device using Find My iPhone (or similar service) before they can unlock it and shut tracking down.
Couldn't you just put this whole operation in a faraday cage to bypass that?
9!/5! + 9!/4! + 9!/3! + 9!/2! + 9!/1! + 9!/0!
Which is just 985,824. And you could certainly search the more likely combinations first -- people almost always select adjacent spots consecutively.
Consider the "spots" labeled in rows from left to right as 1 2 3, 4 5 6, and 7 8 9.
If I start at 1, I can go to 2, 4, 5, 6, and 8 directly. Also, if I have used all spots except 1 and 9, I can go to 1 then directly to 9.
123
456
789
you can't go directly from 1 to 3 unless 2 has been selected. I also don't think you can immediately backtrack, as in 213; you have to go 2513, for instance.With that in mind, I wrote a quick search:
Adjacent only (can't go from 1 to 6 or 8)
1 9
2 40
3 160
4 496
5 1208
6 2240
7 2984
8 2384
9 784
total: 10305
total with length >= 4: 10096
Non-adjacent (knight-moves) allowed (can go from 1 to 6 or 8)
1 9
2 56
3 304
4 1400
5 5328
6 16032
7 35328
8 49536
9 32256
total: 140249
total with length >= 4: 139880
Pass through previous spots, no immediate backtracking (2513 but not 213)
1 9
2 56
3 304
4 1464
5 6136
6 21344
7 57184
8 105376
9 100928
total: 292801
total with length >= 4: 292432
Pass through previous spots, with immediate backtracking allowed (213)
1 9
2 56
3 320
4 1624
5 7152
6 26016
7 72912
8 140704
9 140704
total: 389497
total with length >= 4: 389112
So, I believe the correct number is 292432. For comparison, that's less secure than a 6-digit PIN, or a 4-lowercase-letter password.More importantly, though, if you're using an unlock pattern, you can't be using disk encryption, so anyone who has physical possession of your phone need not bother brute-forcing the unlock pattern.
Take that nosey robots!