#1 it's the most plausible given that it's impossible to be patched upstream and apple aren't slouches regarding crypto. #2 I saw a demo a while back of such a mechanism, and it was obviously brute-forcing. Rest assured, I'm not working for cellebrite selling fake assurances; it's obvious alphanumerics aren't less secure than numeric PINs, and you shouldn't store anything actually sensitive on a biometric-enabled phone anyway.
Because (ideally) without your input the locked device is as hard to break as some blob encrypted with a random and sizable key. So it's more likely someone's found a way to brute force your input than a way to brute force a big random key or break cryptography.
Comments
What makes you so certain of that?
#1 it's the most plausible given that it's impossible to be patched upstream and apple aren't slouches regarding crypto. #2 I saw a demo a while back of such a mechanism, and it was obviously brute-forcing. Rest assured, I'm not working for cellebrite selling fake assurances; it's obvious alphanumerics aren't less secure than numeric PINs, and you shouldn't store anything actually sensitive on a biometric-enabled phone anyway.
Because (ideally) without your input the locked device is as hard to break as some blob encrypted with a random and sizable key. So it's more likely someone's found a way to brute force your input than a way to brute force a big random key or break cryptography.
Math.