Apple corrects the record on reported iPhone vulnerability
Full article695 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The brute force comes at a time when the debate over law enforcement unlocking iPhones is flaring up once again.
Correction: The original testing and report about the iPhone vulnerability was made in error. The security researcher amended his findings a day after the original report. An Apple spokesperson told CyberScoop: “The recent report about a passcode bypass on iPhone was in error, and a result of incorrect testing.”
The researcher’s comment explaining the error is below followed by our corrected story.
It seems @i0n1c maybe right, the pins don't always goto the SEP in some instances (due to pocket dialing / overly fast inputs) so although it "looks" like pins are being tested they aren't always sent and so they don't count, the devices register less counts than visible @Apple
— hackerfantastic.x (@hackerfantastic) June 23, 2018
While Apple strives to make iPhones harder and harder to breach, a security researcher published a brute-force vulnerability for iOS devices that he said cracked the security measures built into the system. However, Apple denied the researcher’s findings and the researcher acknowledged an error.
Researcher Matthew Hickey, co-founder of the cybersecurity firm Hacker House, published what at first appeared to be an exploit on Friday, allowing brute forcing of iOS device passcodes. The exploit bypassed the security that is intended to wipe a device clean if the passcode entry is wrong more than ten times in a row.
By Saturday, after a slew of security experts inside and outside of Apple got involved, Hickey corrected the record. His full explanation of the error is below:
“It’s basically a feature of the devices,” he explained. “If you send pin codes too quickly or send lots of duplicate entries, the devices don’t actually test the pin codes – they appear to on the user interface but under the hood it never uses the pin. So it appears you send 20 or more pins to a device for instance, but in reality, it has only processed 3 or 4 of those pins.”
“I still believe that the advice should be to all consumers to use a seven-digit or more pin code or complex password, as there is still unknown attacks from GrayKey which function in a similar manner. I was able to double check my work after speaking with Stefan Esser and Apple, it seems even though I was sending lots of PINs to the device, it only ever processed a small number of them due to this feature. It’s intended to stop people pocket dialing and wiping their phones.”
The issue comes at a time when the debate over law enforcement unlocking iPhones is once again at a fever pitch. As a result of iOS 12’s new security, companies like Cellebrite and Grayshift are working to make sure their core business — cracking open phones for law enforcement — stays intact.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/iphone-brute-force-passcode-matthew-hickey/