Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think the missing information here is how the phone is encrypted. If it's done with the 4-digit numeric PIN, then the software could be built; it would take 10000 tries, but at less than .1 seconds per try, it would be able to crack the code in about 15 minutes. The current iPhone has a protection for this; after some number of tries, it will lock you out for increasing time intervals.

This is the only way that their claims might possibly be valid.

And a reminder, then: change your iPhone's password to a more complex one. If apple doesn't make this fake OS, someone will.

Edit: to expand on this, Apple's PR goal was to take advantage of the NSA mass surveillance scare. On-device encryption is not very relevant to that. iCloud security is much more important, and they've been quietly granting data from it to the Feds. Including iPhone backups which contain most of the data they're looking for.



Check out this comment where Adam Stew explains how the phones are secured: http://slashdot.org/comments.pl?sid=8756397&cid=51524693


That's really cool, thanks for the link


I mean this sincerely: has the government used one of its 10 tries on the attacker's birth year? I hope the government has burned a couple tries on low-hanging guesses before going through this legal hassle.


You don't want to burn any tries in case the Apple developers would need a few?


Is there a way to know how many attempts remain before trying a key?


Also note that new iPhones default to 6 digit pins. Still possible, but harder.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: