An Overlooked Security Feature of iOS / by Muhammad Amir Ayub

If you use an iOS device, read on.

Apparently there was a setting in the Touch ID & Passcode section that I never realize existed: "Erase Data - Erase all data on this iPhone after 10 failed passcode attempts" 

IMG_6F70575350F3-1.jpeg

At first glance, this sounds like a scary setting. Any parent has experienced times when you're locked out of your phone because your young child tried to unlock your phone and mashed some buttons, hopefully not followed by smashing of the said phone. Nevertheless, the outcome is a locked phone. And such a thing would be bad if once repeated enough times, your phone is wiped clean by your children, and not privacy-intruding authorities.

John Gruber found out that wiping out the phone is not so easy, as the timeout period becomes longer and longer, and hopefully you'll be holding your phone by then:

I had no idea until I looked into it last weekend, but it turns out this feature is far more clever than I realized, and it’s highly unlikely that your kids or jackass drinking buddies could ever trigger it. After the 5th failed attempt, iOS requires a 1-minute timeout before you can try again. During this timeout the only thing you can do is place an emergency call to 911. After the 6th attempt, you get a 5-minute timeout. After the 7th, 15 minutes. These timeouts escalate such that it would take over 3 hours to enter 10 incorrect passcodes.

I've turned it on and so should you. Especially in this age where privacy is more and more a concern, with multiple battlefronts and multiple viewpoints everywhere.