Latest News

    Hacker bypasses iOS passcode and it's surprisingly easy
    Monday, June 25, 2018 IST
    Hacker bypasses iOS passcode and it

    Passcodes have pretty much become the standard security measure of choice for most iPhone users. Even in the presence of more advanced biometric solutions, like Face ID, the sheer convenience and approachability of a four, six or even longer digit number, makes it the ideal fallback security measure. The way it works on iOS is simple, yet efficient - you get a total of 10 attempts to enter the code. Fail all of them and the data will get automatically wiped, for security. The number of input attempts is tracked by a hardware module, called the Secure Enclave, making it pretty impossible to actually disable the limit or circumvent it directly. As an extra any brute-force measure, each consecutive pin entry has a slightly longer processing time.

     
     

    Now for the magic. The way this attack works is by attaching an external input device to the iPhone. One simulation a keyboard, to be exact. A hacker, going by the name "Hickey", figured out that instead of entering codes one by one and then waiting for a validation, you can actually generate all the combinations in a single long string of inputs, without any spaces and send it over to the phone. Apparently, iOS will still attempt to process all the numbers. The other part of the trick stems from the fact that the keyboard input takes precedence over the wipe data command. So, in effect, the Secure Enclave is still counting your failed attempts, but the actual wipe can't occur before the phone is finished processing the inputs. That means that if you iterate through all the possible combinations, you will eventually unlock and cancel out the wipe command.
     
     
    Now, "eventually" is the operative word here. A four digit passcode typically takes between three and five seconds to process. That roughly equals an hour for just 100 combinations. And you do have 9999 to go through, in the worst case scenario. Things ramp up quickly with six digit codes - which is now the default length on iOS. Still, it is interesting to see that particular brute force attack has been executed successfully even on iOS 11.3.

     
     

    That being said, Apple hasn't remained oblivious to such issues, since this is far from the only method for circumventing iPhone security out there. Companies, like Grayshift have actually constructed an entire business model, based on such activities. To combat this, iOS 12 has, what is know as a USB Restricted Mode. It prevents the Lightning port from being used to communicate with other devices, if the phone hasn’t been unlocked for over an hour. That makes using methods, like Hickey's brute force attack a lot harder, but definitely not infeasible.

     
     
     
     
     

    Related Topics

     
     
     

    Trending News & Articles

     Article
    Tata Harrier’s 7-seater Version H7X Will Be Quite Different – Report

    Tata Harrier’s three-row seat version in works, details out  

    Recently posted . 2K views . 0 min read
     

     Article
    How to make you car as silent as a Rolls Royce inside

    Rolls Royce cars are extremely luxurious. While there are many expensive pieces of equipment in Rolls Royce cars, their most relaxing feature is the silence that ...

    Recently posted . 2K views . 2 min read
     

     Article
    India's Top 5 Mobile Charger manufacturer Brand 2019

    The following list of India's Top 5 Mobile Charger manufacture Brand 2019  

    Recently posted . 2K views . 0 min read
     

     Article
    Mahindra XUV300 vs Maruti Brezza, Ford EcoSport, Tata Nexon – Price

    XUV300 is the latest entrant in the compact SUV segment.

    Recently posted . 2K views . 0 min read
     

     
     

    More in Electronics & Gadgets

     Article
    OnePlus 3T Midnight Black Limited Edition Goes on Sale in India Today

    The OnePlus 3T Midnight Black colour variant is set to go on sale in India on Friday. Available only in a 128GB storage variant, the OnePlus 3T Midnight Bl...

    Recently posted. 739 views . 14 min read
     

     Article
    Here is how this latest feature from WhatsApp will allow you to use other apps

    The latest feature from WhatsApp has gained a lot of popularity in a very short span of time. WhatsApp recently rolled out the picture in picture (PiP) mode.

    Recently posted. 790 views . 1 min read
     

     Article
    Kia Seltos awarded 5-star ANCAP rating

    Kia’s smallest SUV in the Australian market scored 85 percent for adult occupancy and 83 percent for child occupancy

    Recently posted. 687 views . 0 min read
     

     Video
    Drill Hacking for Other Uses



    Recently posted . 999 views
     

     Reviews
    10 Best Welding Machines In India In 2019



    Recently posted . 988 views . 89 min read
     

     Article
    This smartphone has four cameras and it’s launching in India next week

    On the front, the smartphone has a combination of a 24-megapixel sensor and a 2-megapixel sensor.

    Recently posted. 779 views . 0 min read
     

     Article
    How Facebook suddenly went so wrong? Here are four possible explanations for what happened, and how bad it is

    That’s what many of Facebook Inc.’s investors — and I — have spent the last 18 hours wondering. On Wednesday, the company posted disappointi...

    Recently posted. 819 views . 1 min read
     

     
     
     

       Prashnavali

      Thought of the Day

    It's always best to have a positive outlook on life, it's easy to see all the bad around you, but there's always good in the world, be thankful you are alive to breathe, to love, to laugh, and to enjoy all the wonders life has to offer....Good Morning
    Anonymous

    Be the first one to comment on this story

    Close
    Post Comment
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST
    Shibu Chandran
    2 hours ago

    Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

    November 28, 2016 05:00 IST


    ads
    Back To Top