Show simple item record

dc.contributor.authorSkorobogatov, Sergeien
dc.date.accessioned2018-07-25T08:42:49Z
dc.date.available2018-07-25T08:42:49Z
dc.identifier.urihttps://www.repository.cam.ac.uk/handle/1810/278432
dc.description.abstractThis paper is a short summary of a real world mirroring attack on the Apple iPhone 5c passcode retry counter under iOS 9. This was achieved by desoldering the NAND Flash chip of a sample phone in order to physically access its connection to the SoC and partially reverse engineering its proprietary bus protocol. The process does not require any expensive and sophisticated equipment. All needed parts are low cost and were obtained from local electronics distributors. By using the described and successful hardware mirroring process it was possible to bypass the limit on passcode retry attempts. This is the first public demonstration of the working prototype and the real hardware mirroring process for iPhone 5c. Although the process can be improved, it is still a successful proof-of-concept project. Knowledge of the possibility of mirroring will definitely help in designing systems with better protection. Also some reliability issues related to the NAND memory allocation in iPhone 5c are revealed. Some future research directions are outlined in this paper and several possible countermeasures are suggested. We show that claims that iPhone 5c NAND mirroring was infeasible were ill-advised.
dc.titleThe bumpy road towards iPhone 5c NAND mirroringen
dc.typeConference Object
dc.identifier.doi10.17863/CAM.23095
dcterms.dateAccepted2016-09-14en
rioxxterms.versionAM*
rioxxterms.licenseref.urihttp://www.rioxx.net/licenses/all-rights-reserveden
rioxxterms.licenseref.startdate2016-09-14en
dc.contributor.orcidSkorobogatov, Sergei [0000-0001-9414-6489]
rioxxterms.typeConference Paper/Proceeding/Abstracten
cam.issuedOnline2016-09-14en
cam.descriptionPaper presented at the HardwearIO, Hague, Netherlands, September 2017


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record