Skip to content

Comment on Cellebrite claims it can unlock any iPhone, many new Android phones for policeparent

Comments

isn't this a solved problem?

It’s only a solved problem if you’re using high entropy passwords (6 digit pins are not). Otherwise you’re relying on some sort of anti-hammering/auto erase to make up for it.

iPhones have anti-hammering already. The Secure Enclave counts password attempts and enforced a lockout period (and wipes the keys after 10 attempts if configured to do so).

There was an attack years ago, where you could kill power to the device after failing the attempt but before it incremented the attempt counter, but they fixed that, and that may have predated the Secure Enclave anyway (and required taking apart the phone, which I assume this on-premises device doesn’t do).

Right, they have it, but whether it's secure/bug free is uncertain. Much more uncertain than say, wether AES-CBC is secure/bug free.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.