Thread about numeric passcode strength on iPhones. And *this* is why I consider my rooted Android phone to be more secure than iPhones under a whole category of attack scenarios. Because I can use separate 25-character full ASCII *startup* password and an 8-digit *unlock* code.https://twitter.com/matthew_d_green/status/985885001542782978 …
-
Show this thread
-
Sure, you can try to attack my phone from a powered-but-locked state, but if you screw up and it reboots, or if you attempt any boot chain attacks, or if the battery runs out, you are *not* getting in. Period.
1 reply 1 retweet 7 likesShow this thread -
I don't know why nobody offers this option of split FDE/unlock codes by default (neither iPhones nor stock Android). It's such a massive no-brainer to increase security to basically "unbreakable" under an entire class of practical attack scenarios.
3 replies 1 retweet 18 likesShow this thread -
Replying to @marcan42
If it were more common, then attackers would think very carefully before allowing the phone to reach a state where they need to go through boot. You're also assuming there's no alternate (remote/0click) way in under lock.
1 reply 0 retweets 2 likes
I'm not saying there is no other way in, I'm saying this eliminates the entire class of boot chain exploits.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.