|
@marcan42 | |||||
|
Thread about numeric passcode strength on iPhones.
And *this* is why I consider my rooted Android phone to be more secure than iPhones under a whole category of attack scenarios. Because I can use separate 25-character full ASCII *startup* password and an 8-digit *unlock* code. twitter.com/matthew_d_gree…
|
||||||
|
||||||
|
Hector Martin
@marcan42
|
17. sij |
|
Sure, you can try to attack my phone from a powered-but-locked state, but if you screw up and it reboots, or if you attempt any boot chain attacks, or if the battery runs out, you are *not* getting in. Period.
|
||
|
|
||
|
Hector Martin
@marcan42
|
17. sij |
|
I don't know why nobody offers this option of split FDE/unlock codes by default (neither iPhones nor stock Android). It's such a massive no-brainer to increase security to basically "unbreakable" under an entire class of practical attack scenarios.
|
||
|
|
||
|
Hector Martin
@marcan42
|
17. sij |
|
(And we can already do this exact thing for FDE on desktops/laptops, so it's not like it's novel)
|
||
|
|
||
|
rcombs
@11rcombs
|
17. sij |
|
i mean… my unlock passcode is 20 chars
|
||
|
|
||
|
Hector Martin
@marcan42
|
17. sij |
|
My patience isn't that high :-)
|
||
|
|
||
|
Dean Herbert
@ppy
|
17. sij |
|
hmm i suddenly feel pretty safe with my 14 digit password
|
||
|
|
||
|
Mempler
@Mempler
|
17. sij |
|
I only have 32 digit passwords lol (doesn't work on every website though, as it's "too long")
|
||
|
|
||
|
Piero Ulloa
@piero512
|
17. sij |
|
But having a custom recovery doesn't kind of defeat the purpose?
|
||
|
|
||
|
Hector Martin
@marcan42
|
17. sij |
|
No, why would it? The FDE passphrase is cryptographically bound to the userdata partition, it doesn't matter if you can compromise all software. At most, if you break the TrustZone bit (which is separate from custom rec), you can speed up the cracking attempt, but not enough.
|
||
|
|
||
|
Bit Rot Farmer
@bitrotfarmer
|
17. sij |
|
out of curiosity - does rooted equal unlocked bootloader? How do you prevent somebody from backdooring the password dialog?
|
||
|
|
||
|
Hector Martin
@marcan42
|
17. sij |
|
You don't; I'm talking about people taking your phone, not evil maid attacks. I don't consider the latter in scope, because I don't really leave my phone unattended, basically ever.
|
||
|
|
||