Notification Center

This is our new notification center. Inside, you will find updates on the most important things happening right now.

Notifications

Hmm, push notifications seem to be disabled in your browser. You can enable them from the 'Settings' icon in the URL bar of your browser.

www.phonearena.com

iOS 10 iTunes backups less secure than iOS 9 and much easier to crack, security experts report

6
iOS 10 iTunes backups less secure than iOS 9 and much easier to crack, security experts report
Traditionally, iOS grows more secure with every subsequent release. But this doesn't appear to be the case with iOS 10 – rather, it's the contrary. Russian cybersecurity firm Elcomsoft reports that Apple has implemented a new password verification mechanism for iOS 10 backups, which makes brute-force password attacks (guessing passwords by characters, or running through a dictionary with a huge number of potential phrases to get to the one that sticks) some 2500 times faster. Apparently, the new mechanism skips certain security checks, which were in place in iOS 9.

Another security researcher, Per Thorsheim, explained that Apple has downgraded the hashing algorithm for iOS 10 from SHA1 with 10K iterations to plain SHA256 with a single iteration, which potentially allows for brute-forcing the password via a common desktop computer processor. Using an Intel Core i5 CPU, Elcomsoft managed to achieve a 6 million passwords per second cracking operation. With the weaker security in place, brute force attacks are up to 40 times faster than GPU-assisted attacks on iOS 9 backups.

Elcomsoft says the brute force attack is only applicable to iOS 10 backups, which are difficult, if not impossible to obtain for attackers unless they have direct access to the victim's mobile device, Apple account credentials, and personal computer.  Apple has not addressed the report yet.

source: Elcomsoft, Per Thorsheim

New reasons to get excited every week

Get the most important news, reviews and deals in mobile tech delivered straight to your inbox

FCC OKs Cingular\'s purchase of AT&T Wireless