Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> On Android, way way easier, due to lack of secure device storage.

FYI: you can encrypt the boot flash drive in ICS and Jellybean; you need to type a passphrase to unlock/boot the phone.



Right, but the weakness vs. iOS and Blackberry is that it's all software encryption. You can get an encrypted image and then search the relatively short feasible password length (people use shorter passcodes, and often numeric, on mobile devices, vs. desktops or online, due to the limitations of the input device, and the need to unlock the device fairly frequently).

On iOS and Blackberry, you're authenticating to a security chip which has a device-specific key (long, random). On an iPad 2 or iPhone 4S or later, you can't make attempts without being physically on the phone, and this is limited to no more than 8 per second on the fastest iPad 3 CPU. This makes a 4 digit passcode on iPhone 4S (with wipe after 10 tries) potentially more secure than an 8 character random alphanumeric on Android. Online (well, device-online) vs. offline attack. I'm not sure about the latest Blackberry OS security chip status, but a few years ago it was similar, so I hope it hasn't gotten worse.

(There are ways, even on the latest devices, to prevent the device wipe on 10 tries, but no known public ways to do attacks without doing them on the device itself, or physically tampering with the device (which isn't impossible, but requires physical access and chip-level attacks. If your passcode is long enough, you'd have time to detect your loss and presumably invalidate any credentials stored on the iPhone)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: