iOS 10 Backups Can Be Cracked 2,500 Times Faster Than iOS 9, Claims Security Researcher

Advertisement
By Ketan Pratap | Updated: 23 September 2016 18:13 IST
Highlights
  • Researcher claims security check in iOS 10 is 2,500 times weak than iOS 9
  • Elcomsoft says brute force attack can be carried on iOS 10 backups
  • New attack specific to password-protected local backups in iOS 10 devices

A security research company based in Moscow claims to have discovered a flaw in Apple's local password protected iTunes backups in iOS 10, a flaw that is said to weaken password security. According to ElcomSoft's Oleg Afonin, the security flaw lets attackers develop a new attack that can bypass certain security checks when tallying passwords protecting local backups in iOS 10 devices.

"The impact of this security weakness is severe. An early CPU-only implementation of this attack (available in Elcomsoft Phone Breaker 6.10) gives a 40-times performance boost compared to a fully optimised GPU-assisted attack on iOS 9 backups," writes Afonin.

Advertisement

Further detailing implementation of the attack, Elcomsoft claims that the new security check in iOS 10 is roughly "2,500 times weaker" compared to the one used in iOS 9 backups.

"Specifically they have changed from pbkdf2(sha1) with 10,000 iterations into using a plain sha256 hash with a single iteration only. This not only allows for a massive speed increase in password cracking, the change is so devastating that an early CPU-only cracking implementation is almost 40 times faster than a fully optimised GPU implementation for the old pbkdf2 version," writes Per Thorsheim, Security Adviser at God Praksis AS.

Advertisement

It's worth mentioning that the flaw discovered cannot be exploited remotely and needs the attacker to have access of the local backups in iOS 10.

Elcomsoft claims that brute force attack, which is a trial and error method used to decode encrypted data such as passwords, can only be carried on iOS 10 backups.

Advertisement

"This new vector of attack is specific to password-protected local backups produced by iOS 10 devices. The attack itself is only available for iOS 10 backups," notes Elcomsoft. The research firm however points that the "new" password verification method exists in parallel system as well with the "old" method though it doesn't affect the earlier versions.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: iOS 10, Apple
Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  2. Oppo Find X9s Pro Launched With 200-Megapixel Cameras: See Price, Features
  3. Poco M8s 5G Debuts Globally With 7,000mAh Battery: See Price, Features
  4. Oppo Pad 5 Pro With 13,380mAh Battery Debuts Alongside Pad Mini: See Prices
  5. Motorola Edge 70 Fusion Review
  6. Jailer 2 OTT Release Date Reportedly Revealed Online: When and Where to Watch it Online?
  7. Vivo X300 FE Roundup: Expected Price in India, Specifications
  8. Dyson Launches Supersonic Travel as Smaller, Lighter Hair Dryer
  1. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  2. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  3. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  4. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  5. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  6. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  7. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
  8. Oppo Find X9s Pro Launched With 200-Megapixel Cameras, 7,025mAh Battery: Price, Specifications
  9. OnePlus Ace 6 Ultra Geekbench Listing Reveals MediaTek Dimensity 9500 Chip, 16GB RAM
  10. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.