Thread about numeric passcode strength on iPhones. And *this* is why I consider my rooted Android phone to be more secure than iPhones under a whole category of attack scenarios. Because I can use separate 25-character full ASCII *startup* password and an 8-digit *unlock* code.https://twitter.com/matthew_d_green/status/985885001542782978 …
-
-
(And we can already do this exact thing for FDE on desktops/laptops, so it's not like it's novel)
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
I'd like it, but I'd guess it's human factors? If people only use the password when you turn on the phone, and they choose a more random/secure password for that, they tend to forget it and get locked out. Probably hard to keep the UI clear too.
-
Stick it under an advanced menu and put a big warning next to it then. Do it in the developer menu on Android if you must, that's already hidden by default.
End of conversation
New conversation -
-
-
If it were more common, then attackers would think very carefully before allowing the phone to reach a state where they need to go through boot. You're also assuming there's no alternate (remote/0click) way in under lock.
-
I'm not saying there is no other way in, I'm saying this eliminates the entire class of boot chain exploits.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.