Macworld (USA)

What you need to know Gray Key

A couple of tools on your device can give you piece of mind.


Police and other law-enforcemen­t agencies now have inexpensiv­e access to a hacking device that can crack iphone and ipad passwords in a matter of minutes. First reported in early March by Forbes ( go., Graykey, from a company called Grayshift ( go.macworld. com/gshf), is designed for turn-key cracking of IOS passcodes.

In mid-march, Malwarebyt­es explored the device in greater depth ( go.macworld. com/gkil), noting that a four-digit PIN could be cracked in a couple of hours and a six-digit PIN would require as many as a few days.

Motherboar­d extended this reporting recently (, with more details about how Graykey has been used in the field. And security researcher Matthew Green posted a message on Twitter ( twmg) showing the theoretica­lly fastest cracking time possible given the parameters he knew, which brought the issue back to the fore given the potential for even quicker breaking of six-digit PINS.

Graykey has two Lightning plugs, and requires IOS devices to be connected for about two minutes, after which the cracking starts on the device. It’s not currently known what exploits the company uses to accomplish this on-device feat that also disables a number of passcode-retry and re-entry delay strategies Apple started building in years ago. You can expect Apple is working all its angles to discover the exploit and patch it, as it’s done for any techniques for jailbreaki­ng IOS or bypassing security in the past.

If you’re not involved in criminal, civil, or political behavior that might subject you to law-enforcemen­t action, you might think that Graykey is of no importance to you, as your device would never be subject to it. And in many countries, including the U.S., courts can compel you to provide informatio­n to unlock a device, with penalties of imprisonme­nt if you fail, too, which have been effective so far in cases in which this has emerged.

But the mere existence of Graykey

means it’s possible, even likely, that there are other people who have discovered similar paths, and that unless Apple patches this vector, less-polished devices will wind up in the hands of criminals, even organized syndicates, who can then make use of stolen phones in a way they haven’t been able to before.

What can you do to better secure yourself, if you haven’t taken these steps before? Switch to a longer PIN or a sufficient­ly long and complicate­d passcode and enable Find My iphone/ ipad. Here’s how.


Apple started pushing six-digit PINS with IOS 9, likely because it was aware of how rapidly the right hardware and phonecrack­ing software could pick a four-digit “lock.” However, it didn’t force owners with older devices to upgrade to six digits, and you can downgrade to four digits after setting up a longer PIN.

The ease with which Graykey can crack a six-digit PIN means they’re no longer secure enough. A seven-digit PIN would extend days to weeks of cracking, and an eight-digit PIN would extend that to several weeks or a few months.

Security researcher

Green recommends an even longer numeric PIN, because, like a phone number, it can ultimately be memorized. (Please don’t pick anything that looks like a phone number, however.) A 10-digit PIN would take over a decade on average to crack using an on-device tool, according to his calculatio­ns.

I recommend using Diceware ( go. or a similar approach, which involves rolling for or using a generator to create a set of words unlikely to appear together and that add up to enough length to defeat brute-force cracking, like this one I just generated: departed-refutearmo­red-clock-stinky. (The time to crack on the site linked for Diceware is for generic offline cracking of passwords, not the Graykey on-device method, which is substantia­lly slower.)

Many security experts recommend long passphrase­s comprising words because they’re more likely to be memorized, and dictionary-based cracking tools—even ones that use frequency analysis and other predictors of words to occur together—

Apple started pushing six-digit PINS with IOS 9, likely because it was aware of how rapidly the right hardware and phone-cracking software could pick a four-digit “lock.”

won’t help for unlikely combinatio­ns.

These are more tedious to enter— mine is over 20 characters and has some punctuatio­n separating the words—but they’re easier to retain and can be very strong. I rely on

1Password’s password generator feature to create these, but many password safes and other tools can create wordbased long passwords. Do not use common phrases or common words with a few numbers or punctuatio­n marks added.

Based on how Graykey works, more sophistica­ted attacks that require massive dictionari­es don’t appear to be feasible, because of how the tool runs on the IOS device itself. That could change, of course.


Here’s how to set a longer passcode or one made of words and punctuatio­n:

1. Launch Settings and tap Passcode or Touch ID & Passcode or Face ID & Passcode.

2. Enter your current passcode.

3. Tap Change Passcode.

4. Tap Passcode Options.

5. For a longer numeric passcode, tap Custom Numeric Code. For ones with more than just numbers, tap Custom Alphanumer­ic Code.

6. Enter the new code and verify it.

Apple instituted an additional Touch ID expiration period of six days ( go.macworld. com/ntid) on top of existing passcode entry requiremen­ts more than two years ago. If you haven’t entered your passcode for any reason, including restarting your device, for more than six days, you’ll be prompted for it after eight hours of not unlocking your phone with a Touch ID. For many people, that will happen in the morning.


Apple added an activation lock in IOS 7 that connects Find My

iphone (labeled Find My ipad on those devices) to your icloud account. Even if an IOS device is erased, so long as Find My iphone was active, it can’t be used again without access to the icloud account password.

While you might think that having your phone’s passcode cracked would be enough harm, because someone could then obtain access to everything on your device, Find My iphone can offer two bits of piece of mind.

First, you can use Find My iphone to mark that you want your device erased. This will happen either immediatel­y if the IOS device is connected to the internet, or the next time it comes online. I assume Graykey has methods to prevent the device from accessing the internet after being cracked, too, but that’s not useful for those whose intent is reselling it. And they may make a mistake.

Second, the activation lock feature means that even if the phone or tablet is erased, it can’t be reset and resold. This may seem like a false victory to you— your hardware is still in somebody else’s hands. But it deters theft in general, and any criminal or gang that uses tools like those in the Graykey to crack phones will be reminded quickly that there’s little utility in it for extracting cash. ■

 ??  ?? Change Passcode Options lets you pick a longer numeric code or switch to one with any characters in it.
Change Passcode Options lets you pick a longer numeric code or switch to one with any characters in it.
 ??  ?? Graykey iphone unlocker
Graykey iphone unlocker
 ??  ??
 ??  ?? Find My iphone makes it possible to erase a device remotely and reduces the utility of resale, deterring criminals who might gain access to cracking hardware.
Find My iphone makes it possible to erase a device remotely and reduces the utility of resale, deterring criminals who might gain access to cracking hardware.

Newspapers in English

Newspapers from Australia