iOS 10 iTunes backups less secure than iOS 9 and much easier to crack, security experts report

6
Luis D.
By
iOS 10 iTunes backups less secure than iOS 9 and much easier to crack, security experts report
Traditionally, iOS grows more secure with every subsequent release. But this doesn't appear to be the case with iOS 10 – rather, it's the contrary. Russian cybersecurity firm Elcomsoft reports that Apple has implemented a new password verification mechanism for iOS 10 backups, which makes brute-force password attacks (guessing passwords by characters, or running through a dictionary with a huge number of potential phrases to get to the one that sticks) some 2500 times faster. Apparently, the new mechanism skips certain security checks, which were in place in iOS 9.

Another security researcher, Per Thorsheim, explained that Apple has downgraded the hashing algorithm for iOS 10 from SHA1 with 10K iterations to plain SHA256 with a single iteration, which potentially allows for brute-forcing the password via a common desktop computer processor. Using an Intel Core i5 CPU, Elcomsoft managed to achieve a 6 million passwords per second cracking operation. With the weaker security in place, brute force attacks are up to 40 times faster than GPU-assisted attacks on iOS 9 backups.

Recommended For You
Elcomsoft says the brute force attack is only applicable to iOS 10 backups, which are difficult, if not impossible to obtain for attackers unless they have direct access to the victim's mobile device, Apple account credentials, and personal computer.  Apple has not addressed the report yet.

source: Elcomsoft, Per Thorsheim

Get Visible as low as $20/mo for 1 year. Limited time offer with code: FRESHSTART

$20 /mo
$25
$5 off (20%)
Offer Ends 6.1.2026 at 11.59pm ET. New members get $5/mo off the $25/mg Visible plan, $35/mo Visible+ plan, or $45/mo Visible+ Pro plan for the first 12 months. Promo code FRESHSTART required at checkout.
Buy at Visible
Recommended For You
COMMENTS (6)
Latest Discussions
by readdriver • 2
by ECPirate37 • 1
by menooch18 • 2