{"id":26621,"date":"2014-10-08T21:42:23","date_gmt":"2014-10-09T01:42:23","guid":{"rendered":"http:\/\/www.opensource.im\/?p=26621"},"modified":"2014-10-08T21:42:23","modified_gmt":"2014-10-09T01:42:23","slug":"four-digit-passcodes-remain-a-weak-point-in-ios-8-data-encryption","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/encryption\/four-digit-passcodes-remain-a-weak-point-in-ios-8-data-encryption.php","title":{"rendered":"Four-digit passcodes remain a weak point in iOS 8 data encryption"},"content":{"rendered":"<p><p>    The    strength of Apples revised encryption scheme in iOS 8 hinges    on users choosing a strong passcode or password, which they    rarely do, according to a Princeton University fellow.  <\/p>\n<p>    Apple    beefed up the encryption in its latest mobile operating system,    protecting more sensitive data and employing more protections    within hardware to make it harder to access. The new system has    worried U.S. authorities, who fear it may make it more    difficult to obtain data for law enforcement since Apple has no    access to it.  <\/p>\n<p>    Despite    the new protections, data is still vulnerable in certain    circumstances,     wrote Joseph    Bonneau, a fellow at theCenter For Information Technology    Policy at Princeton, who studies password security.  <\/p>\n<p>    Users    with any simple passcode have no security against a serious    attacker whos able to start guessing with the help of the    devices cryptographic processor, he wrote.  <\/p>\n<p>    If an    iPhone is seized when its turned off, its unlikely that the    keys can be derived from its cryptographic co-processor called    the Secure Enclave, which does the heavy lifting to enable    encryption.  <\/p>\n<p>    But if    an attacker can boot the phone and get access to the Secure    Enclave, it would be possible to start guessing passwords in a    brute-force attack, and thats where the weakness lies.  <\/p>\n<p>    Apple    doesnt make it easy to completely copy all of the data on a    device and boot it up using external firmware or another    operating system, which would be an attackers first step,    Bonneau wrote.  <\/p>\n<p>    His    theory of how easy it would be to obtain the data from a device    is dependent on an attacker being able to bypass the    complicated secure boot sequence of an iOS 8 device.  <\/p>\n<p>    Well    assume this can be defeated by finding a security hole,    stealing Apples key to sign alternate code or coercing Apple    into doing so, he wrote.  <\/p>\n<p>    If that    is possible, the attacker can begin guessing passcodes or    passwords against the Secure Enclave. Apples documentation    suggests that such guesses could be conducted at a rate of    either 12 guesses per second or 1 guess every five    seconds.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read more from the original source:<br \/>\n<a target=\"_blank\" href=\"http:\/\/www.pcworld.com\/article\/2824292\/fourdigit-passcodes-remain-a-weak-point-in-ios-8-data-encryption.html\/RK=0\/RS=Fl0XkrBRAooluCTGPQrn3Q1c0VU-\" title=\"Four-digit passcodes remain a weak point in iOS 8 data encryption\">Four-digit passcodes remain a weak point in iOS 8 data encryption<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The strength of Apples revised encryption scheme in iOS 8 hinges on users choosing a strong passcode or password, which they rarely do, according to a Princeton University fellow. Apple beefed up the encryption in its latest mobile operating system, protecting more sensitive data and employing more protections within hardware to make it harder to access. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[],"class_list":["post-26621","post","type-post","status-publish","format-standard","hentry","category-encryption"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/26621"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=26621"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/26621\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=26621"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=26621"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=26621"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}