Re: Keychain best practice
jerry porter <jep9816-/[email protected]> Fri, 10 Dec 2010 10:16:20 -0800 (PST)
| Newsgroups | gmane.comp.macosx.devel |
|---|---|
| Message-ID | <[email protected]> |
The forensics company used Elcomsoft iPhone Password Breaker, broke encryption of iTunes backup which provided recovery of username and password. This was their comment: One risk inherent in using a platform such as the iPhone is that the vendor must properly implement security measures offered to application developers. In the case of iPhone backup encryption, Apple has erred in the newest versions of iOS by failing to encrypt the keychain contents with a key separate from the backup. Thus when backup encryption is used, and the passcode is cracked, keychain passwords are revealed. This vulnerability is inherited by any applications leveraging the keychain. And their recommendation: Do not use Appleās keychain for username and password management. Instead, employ custom encrypted storage directly within your application. If custom encrypted storage is leveraged, the algorithm and key must be sufficiently strong to withstand a brute-force attack. <AppName> currently uses a 4-digit PIN chosen by the user to secure authentication which, if used as the encryption key, would be easily defeated. Jerry Porter - - - When told the reason for daylight saving time the old Indian said ... "Only a white man would believe that you could cut a foot off the top of a blanket and sew it to the bottom of a blanket and have a longer blanket." - - - - - - Seen on a T-shirt: "Remember you are unique and special... Just like everyone else" - - - ----- Original Message ---- From: Hamish Allan <[email protected]> To: James Montgomerie <[email protected]> Cc: MacOSX-Dev List <[email protected]> Sent: Fri, December 10, 2010 11:28:03 AM Subject: Re: Keychain best practice On 10 December 2010 15:53, James Montgomerie <[email protected]> wrote: > On 10 Dec 2010, at 15:37, Christiaan Hofman wrote: >> On Dec 10, 2010, at 15:40, jerry porter wrote: >>> We hired a forensics company to test an app I wrote for my company and they >>> broke the keychain in a matter of moments. > > I'd be interested to hear how. I was under the impression that keychain was >very secure. I'd also be interested to hear more about this. 3DES apparently has 80 bits of security in the worst case (chosen plaintext attacks) for which brute-forcing is not a "matter of moments", so perhaps this was through a vulnerability in the Security Server? H _______________________________________________ MacOSX-dev mailing list [email protected] http://www.omnigroup.com/mailman/listinfo/macosx-dev