{"id":386,"date":"2013-04-11T22:10:08","date_gmt":"2013-04-12T05:10:08","guid":{"rendered":"http:\/\/seanmurphree.com\/blog\/?p=386"},"modified":"2013-04-11T22:10:08","modified_gmt":"2013-04-12T05:10:08","slug":"iphone-5-passcode-info-disclosure","status":"publish","type":"post","link":"https:\/\/seanmurphree.com\/blog\/?p=386","title":{"rendered":"iPhone 5 &#8211; Passcode Info Disclosure"},"content":{"rendered":"<p>Feature, information leak, same thing. \u00a0At least sometimes? \u00a0It turns out this is the fact with the iPhone 5 and strong passcodes.<\/p>\n<p>Many people are familiar with passcodes used to protect phones now-a-days. \u00a0These passcodes are used to unlock the phone for use after a period of disuse (such a minute, 5 minutes, or even instantly as soon as the screen is turned off). \u00a0The iPhone 5 supports two types of passcodes, &#8220;simple&#8221; and otherwise. \u00a0Simple passcodes are limited to numbers only, and always have a length of 4. \u00a0Non-simple passcodes can use letters and numbers and can be up to 10 characters long. \u00a0Since simple passcodes only involve numbers, the input screen shows a number pad for input. \u00a0However, with complex passcodes, the situation is different.<\/p>\n<p>With complex passcodes, if we have both letters and numbers in our passcode, the input screen shows the standard on screen QWERTY keyboard. \u00a0However, if a complex passcode only contains numbers (greatly reducing the complexity and attack space), the QWERTY keyboard is not shown, and only a number pad is shown. \u00a0This usability (?) choice (?) directly reveals that numeric-only complex passcodes are numeric-only to potential attackers without them having to know anything about the password and greatly reduces the security of numeric-only passcodes. \u00a0However, who wants to enter numbers on a QWERTY keyboard on a touch screen?<\/p>\n<p>Choices.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Feature, information leak, same thing. \u00a0At least sometimes? \u00a0It turns out this is the fact with the iPhone 5 and strong passcodes. Many people are familiar with passcodes used to protect phones now-a-days. \u00a0These passcodes are used to unlock the &hellip; <a href=\"https:\/\/seanmurphree.com\/blog\/?p=386\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/386"}],"collection":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=386"}],"version-history":[{"count":1,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/386\/revisions"}],"predecessor-version":[{"id":387,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/386\/revisions\/387"}],"wp:attachment":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}