Skip to content

Comment on IOS 6.1 hack lets users see your phone app, place calls

Comments

The question is how did anyone figure out this method? I know it was first exposed in a similar manner on iOS 4.1 but is there someone deliberately trying to break the passcode lock? Is the recent jailbreak helping?

To answer the question in the middle: yes, there are tons of people attempting to break the passcode lock system. One of these groups are police departments and the forensics experts they hire, who really hate it when the victim's cell phone might give them the vital clues they need to solve the murder, if only it weren't locked. (You may argue with the morals of this: I am just reporting that these groups actively work on this, and you can buy books and tools and even hire them as consultants for these purposes... I am not saying it is "right" or "wrong".)

Passcode locks are a barrier only for domestic uses, and wouldn't be a problem for a forensics expert. It's not like the pass code would encrypt the filesystem.

Actually the PIN code is the key (to the key) to the encrypted filesystem. http://www.technologyreview.com/news/428477/the-iphone-has-p...

That's why on modern devices, a full remote wipe / secure wipe takes seconds instead of hours - only the master filesystem encryption key needs to be zeroed.

How hard is it to brute-force 10k keys?

http://helpdesk.bradley.edu/howto/images/iOS/erase.jpg

also, if you need it you can enable passwords of any length and with more than just digits.

From the extracted phone image, obviously.

Obviously, except the phone won't talk over USB unless it's unlocked. Unless of course you really want that data and take it apart and read the NAND directly. As always, security is not binary, you decide how much you need. If you are that concerned about your data you can enable real passwords.

I believe the file system key is stored in a special area of storage nearly inside the system-on-chip, making this even more difficult than you'd even have assumed.

If your phone is set to hard reset after five or ten, pretty damn hard.

Thanks, my bad, i don't know that.

Trying to figure out what difference that makes, or why you bring up jailbreaking at all.

It appears he's suggesting flaws exploited in the jailbreak are related to flaws that allow you to bypass the passcode.

Seems unlikely, but still :)

Well just out of curiosity. I mentioned the jailbreak because now people can have root access which could be useful, I don't know. Maybe the timing is just an coincident.

I believe this bug applies to all devices running 6.1, which includes the iPhone 4; we have a permanent jailbreak for the iPhone 4, due to the limera1n bootloader exploit, and thereby have had people using jailbroken 6.1 iPhone 4's (which are quite popular, even still being sold new) for a while.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.