Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My understanding is that the entire storage device is transparently encrypted/decrypted on the iPhone 3GS and up. Unfortunately all this means is that if someone pulls your phone apart they can't pull the data, but if they jailbreak it they can. If your phone is PIN-locked, you're secure.

This is why 'erase all content and settings' takes only a few seconds on newer devices, vs. hours on the iPhone and iPhone 3G - all it has to do is erase the decryption key and the entire partition is effectively garbage.



That's not what this Apple KB cites [1]: "This provides an additional layer of protection for your email messages and attachments. Third-party applications can use the data protection APIs in iOS 4 and later to further protect application data."

That does not imply all data is encrypted - in fact, it implies it requires app-level support and not even all first-party app data is encrypted.

[1] http://support.apple.com/kb/HT4175


There are at least two different kinds of encryption at work on Apple mobile products. The one that this knowledge base is discussing, is a crypto accelerator framework that allows you to quickly do high-quality encryption on a segment of data.

However there is also fundamental encryption placed on the solid-state flash assembly that drives all iOS devices. It is not user accessible, it does not rely on user visible passwords, and guarantees that when the device is off, the filesystem cannot be read.

The first generation of Windows 7 devices did not offer hardware file system encryption, ironically keeping them from connecting to most Microsoft exchange installations.


This PDF put out by apple is fairly accessible and describes these measures in some depth if you're interested.

http://images.apple.com/ipad/business/docs/iOS_Security_May1...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: