Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

do they actually enforce these limits? I couldn't find any google UI which says "2 tries left or your data will be permanently erased".

One can't implement brute force protections without such a UI...

"You need to wait 5 minutes" isn't sufficient for a 4 digit pin...



I can't speak to Pixels personally but every Samsung phone I've owned that I can remember has exactly that.

https://www.reddit.com/r/samsung/comments/13nnphc/delete_pho...


The waiting time increases after failed attempts.


In general that isn't secure unless the security chip has access to a secure time server to know that the required amount of time has passed.

Otherwise you can simply say "yeah, we power cycled you and now the year is 100,000, can I have another guess?"

I don't see any mention of that functionality in any public documentation.


I'm not sure how different devices implement it, but the security chip can simply count the time it was powered on, it doesn't have to rely on wall clock time.

(Relying on wall clock time caused a bug in an early iOS version of this feature, where it would show a really long delay when the clock was reset, and there was no way to set the clock correctly)


So now you just need to fake a cell tower and a GPS constellation so that the phone gets a new time on power cycle. Which would be about 60s minimum, to boot and acquire.

And that’s with a power cycle, so 14,000 a day? I’ll not going to assume the button will last more than 100,000 presses, so I don’t see many combinations being tried.


You can spoof GPS with a hackrf so this is not actually that crazy, I wouldn’t be surprised if certain 3 letter agencies have tried this already.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: