iOS 10 Backups Can Be Cracked 2,500 Times Faster Than iOS 9, Claims Security Researcher

Advertisement
By Ketan Pratap | Updated: 23 September 2016 18:13 IST
Highlights
  • Researcher claims security check in iOS 10 is 2,500 times weak than iOS 9
  • Elcomsoft says brute force attack can be carried on iOS 10 backups
  • New attack specific to password-protected local backups in iOS 10 devices

A security research company based in Moscow claims to have discovered a flaw in Apple's local password protected iTunes backups in iOS 10, a flaw that is said to weaken password security. According to ElcomSoft's Oleg Afonin, the security flaw lets attackers develop a new attack that can bypass certain security checks when tallying passwords protecting local backups in iOS 10 devices.

"The impact of this security weakness is severe. An early CPU-only implementation of this attack (available in Elcomsoft Phone Breaker 6.10) gives a 40-times performance boost compared to a fully optimised GPU-assisted attack on iOS 9 backups," writes Afonin.

Further detailing implementation of the attack, Elcomsoft claims that the new security check in iOS 10 is roughly "2,500 times weaker" compared to the one used in iOS 9 backups.

Advertisement

"Specifically they have changed from pbkdf2(sha1) with 10,000 iterations into using a plain sha256 hash with a single iteration only. This not only allows for a massive speed increase in password cracking, the change is so devastating that an early CPU-only cracking implementation is almost 40 times faster than a fully optimised GPU implementation for the old pbkdf2 version," writes Per Thorsheim, Security Adviser at God Praksis AS.

Advertisement

It's worth mentioning that the flaw discovered cannot be exploited remotely and needs the attacker to have access of the local backups in iOS 10.

Elcomsoft claims that brute force attack, which is a trial and error method used to decode encrypted data such as passwords, can only be carried on iOS 10 backups.

Advertisement

"This new vector of attack is specific to password-protected local backups produced by iOS 10 devices. The attack itself is only available for iOS 10 backups," notes Elcomsoft. The research firm however points that the "new" password verification method exists in parallel system as well with the "old" method though it doesn't affect the earlier versions.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: iOS 10, Apple
Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  2. Oppo F31 Series Launched With 7,000mAh Battery: Check Price, Features
  3. Xiaomi 17 Pro Max Tipped to Come With a Secondary Display
  4. Samsung Galaxy S25 FE With 50-Megapixel Camera Launched in India: See Price
  5. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  6. iPhone 18 Series to Feature a Smaller Dynamic Island, Tipster Claims
  7. Realme P3 Lite 5G With 6,000mAh Battery Launched in India at This Price
  8. iOS 26 Releases Today: Check Out the Notable Features
  9. iOS 26 Update for iPhone Releases Today: Everything You Need to Know
  10. Oppo Find X9 Launch Timeline Revealed: See Find X9 Pro Camera Samples
  1. Samsung Galaxy S25 FE Launched in India With 6.7-Inch AMOLED Screen, 50-Megapixel Camera: Price, Features
  2. iPhone 18 Series Tipped to Feature Smaller Dynamic Island, Might Launch Without Under-Display Face ID
  3. OnePlus 15 Leaked Image Hints at Redesigned Camera Module, Three Colourways
  4. Xiaomi 17 Pro Max Leaked Image Reveals Rear Display in a Nod to the 11 Ultra Ahead of September Debut
  5. Treasure Hunters Season 1 Now Streaming on JioHotstar: Everything You Need to Know
  6. London Stock Exchange Completes First Blockchain-Powered Fundraising via DMI Platform
  7. Zepto Fastest Sale Ever: Apple AirPods 4 Price Drops to Rs 9,999; Check Top Deals on Electronics, Accessories
  8. War 2 OTT Release Date Reportedly Revealed Online: When and Where to Watch it Online?
  9. MeitY Proposes 20-Year Tax Holiday for Data Centres to Boost Investment: Report
  10. Resident Evil Requiem, Resident Evil 7: Biohazard and Resident Evil Village Are Coming to Switch 2 Next Year
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.