Hacker bypasses iOS passcode and it's surprisingly easy
Monday, June 25, 2018 IST
Passcodes have pretty much become the standard security measure of choice for most iPhone users. Even in the presence of more advanced biometric solutions, like Face ID, the sheer convenience and approachability of a four, six or even longer digit number, makes it the ideal fallback security measure. The way it works on iOS is simple, yet efficient - you get a total of 10 attempts to enter the code. Fail all of them and the data will get automatically wiped, for security. The number of input attempts is tracked by a hardware module, called the Secure Enclave, making it pretty impossible to actually disable the limit or circumvent it directly. As an extra any brute-force measure, each consecutive pin entry has a slightly longer processing time.
Now for the magic. The way this attack works is by attaching an external input device to the iPhone. One simulation a keyboard, to be exact. A hacker, going by the name "Hickey", figured out that instead of entering codes one by one and then waiting for a validation, you can actually generate all the combinations in a single long string of inputs, without any spaces and send it over to the phone. Apparently, iOS will still attempt to process all the numbers. The other part of the trick stems from the fact that the keyboard input takes precedence over the wipe data command. So, in effect, the Secure Enclave is still counting your failed attempts, but the actual wipe can't occur before the phone is finished processing the inputs. That means that if you iterate through all the possible combinations, you will eventually unlock and cancel out the wipe command.

Now, "eventually" is the operative word here. A four digit passcode typically takes between three and five seconds to process. That roughly equals an hour for just 100 combinations. And you do have 9999 to go through, in the worst case scenario. Things ramp up quickly with six digit codes - which is now the default length on iOS. Still, it is interesting to see that particular brute force attack has been executed successfully even on iOS 11.3.
That being said, Apple hasn't remained oblivious to such issues, since this is far from the only method for circumventing iPhone security out there. Companies, like Grayshift have actually constructed an entire business model, based on such activities. To combat this, iOS 12 has, what is know as a USB Restricted Mode. It prevents the Lightning port from being used to communicate with other devices, if the phone hasn’t been unlocked for over an hour. That makes using methods, like Hickey's brute force attack a lot harder, but definitely not infeasible.
Related Topics
Related News & Articles
DC fast charging will allow an 80 percent charge in an hour for the Wagon R EV, sources claim.
Recently posted . 725 views . 1 min read
Apple rolled out on Tuesday its much-anticipated iPhone X, a redesigned product of glass and stainless steel with an edge-to-edge display that Apple CEO Tim Cook ca...
Recently posted . 1K views . 13 min read
New Delhi Taxi driver Haricharan would not change his humble function phone for any hello-fi cellphone.
“I will start chats (on facebook Messenger)...
Recently posted . 772 views . 51 min read
Xiaomi's sub-brand Redmi is busy working on its next mid-rangers, the Redmi 8 series. The Redmi 8 itself was spotted in some hands-on images earlier today, an...
Recently posted . 608 views . 3 min read
Extending its FX-format DSLR camera range, imaging technology major Nikon India on Monday launched Nikon D850, which comes with a 45.7 MP BS...
Recently posted . 818 views . 9 min read
Trending News & Articles
Tata Harrier’s three-row seat version in works, details out
Recently posted . 2K views . 0 min read
Rolls Royce cars are extremely luxurious. While there are many expensive pieces of equipment in Rolls Royce cars, their most relaxing feature is the silence that ...
Recently posted . 2K views . 2 min read
The following list of India's Top 5 Mobile Charger manufacture Brand 2019
Recently posted . 2K views . 0 min read
XUV300 is the latest entrant in the compact SUV segment.
Recently posted . 2K views . 0 min read
More in Electronics & Gadgets
Today the Fossil Group has announced that it's entered an agreement to sell Google some secret still in development smartwatch technology for $40 million. The d...
Recently posted. 636 views . 2 min read
Microsoft India has finally launched the Surface Go tablet in the Indian market.
Recently posted. 699 views . 0 min read
For the past week, Xiaomi had been teasing the release of a new product in partnership with Intel at China Joy and we speculated the company to refresh its first-ev...
Recently posted. 841 views . 1 min read
Recently posted . 838 views
Recently posted . 1K views
Recently posted . 1K views
Recently posted . 1K views
Recently posted . 1K views . 33 min read
Recently posted . 1K views . 18 min read
In what may be largest data hack at an email provider, Yahoo says that hackers stole records from more than one billion person accounts in August 2013....
Recently posted. 598 views . 6 min read
It's late spring. The Indian Meteorological Department has given a hotness wave and Orange caution for quite a long time of the country. With temperature clim...
Recently posted. 815 views . 2 min read