YouTube home Comedy Week on YouTube
Upload

Lost iPhone? - Lost passwords!

FraunhoferSITDA FraunhoferSITDA·19 videos
121
830,906
Like     Dislike 35

Sign in to YouTube

Sign in with your Google Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to like FraunhoferSITDA's video.

Sign in to YouTube

Sign in with your Google Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to dislike FraunhoferSITDA's video.

Sign in to YouTube

Sign in with your Google Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to add FraunhoferSITDA's video to your playlist.

Uploaded on Feb 9, 2011

[UPDATE] SIM-PIN can be also extracted! Visit: http://www.youtube.com/watch?v=hpFdfv...
[UPDATE] iOS firmware versions up to iOS 6.0.1 are also affected. See FAQ with further information about the topic: http://sit4.me/ios-keychain-faq

The paper highlights risks that accompany losing a locked iOS device regarding confidentiality of passwords stored in the keychain. It presents results of handson tests that show the possibility for attackers to reveal some of the keychain entries. For the described approach, the knowledge of the user's secret passcode is not needed, as the protection provided by the passcode is bypassed.
http://www.sit.fraunhofer.de/en/forsc...

Loading icon Loading...

Loading icon Loading...

Loading icon Loading...

Loading icon Loading...

Ratings have been disabled for this video.
Rating is available when the video has been rented.
This feature is not available right now. Please try again later.

Top Comments

  • fenrriho

    ...so many limitations on the iphone, even security is limited...

    · 17

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate fenrriho's comment.

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate fenrriho's comment.
  • kopial

    That's what hackers do, break them. That's what street racers do, break them. That's what taxpayers do, fool them. That's what Steve Jobs do, rip them. Its these researcher-hackers who protect us by sending a clear message to corporations about their system weakness, then only u get a new firmware upgrade. Real hackers won't upload such video, its too valuable!

    · 10

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate kopial's comment.

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate kopial's comment.
    in reply to DeutscherGospel (Show the comment)

All Comments (175)

Sign in now to post a comment!
  • Monde Tuba

    cryptography is evolving to randomization to include time & location parameters via GPS; that adding the latter to the crypto-algorithm provides a degree of accountability within 3 meters of access time just in case the authorities should "need to know" your whereabouts.

    ·

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate Monde Tuba's comment.

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate Monde Tuba's comment.
  • Viet, Hoang Van

    ok

    ·

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate Viet, Hoang Van's comment.

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate Viet, Hoang Van's comment.
  • osnapitznot ari

    how do i get access to the filesystem?

    ·

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate osnapitznot ari's comment.

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate osnapitznot ari's comment.
  • Freddie Rice

    not necesarily setup his own password, but install a second certificate with a different password.

    ·

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate Freddie Rice's comment.

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate Freddie Rice's comment.
    in reply to redmoonice (Show the comment)
  • Freddie Rice

    Actually you can re-jailbreak. Restore the patched files and then reboot. Then jailbreak again.

    ·

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate Freddie Rice's comment.

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate Freddie Rice's comment.
    in reply to Danny Tan (Show the comment)
  • Freddie Rice

    No, they did not release any of the scripts used in the video. They only explained a basic security flaw in the system. The data in keychain-2.db is in sqlite3 format, well known by any database programmer. This security firm just wants apple to add the slightest bit of encryption to the account names when the device is unlocked.

    ·

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate Freddie Rice's comment.

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate Freddie Rice's comment.
    in reply to Cristo Nabarrete (Show the comment)
  • Alessandro Pagliuca

    How to do a ssh tunnel?!?!?!?!?!?!?

    ·

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate Alessandro Pagliuca's comment.

    Sign in to YouTube

    Sign in with your YouTube Account (YouTube, Google+, Gmail, Orkut, Picasa, or Chrome) to rate Alessandro Pagliuca's comment.
  • Loading comment...
Loading...
Loading...
Working...
Sign in to add this to Watch Later