iTunes Backup Passwords 'Much Easier' to Crack in iOS 10, Apple Working on Fix

iOS 10 uses a new password verification mechanism for iTunes backups that makes them easier to crack, according to testing performed by Elcomsoft, a company that specializes in software designed to access iPhone data.

Encrypted iTunes backups created on a Mac or PC are protected by a password that can potentially be brute forced by password cracking software. The backup method in iOS 10 "skips certain security checks," allowing Elcomsoft to try backup passwords "approximately 2500 times faster" compared to iOS 9 and earlier operating systems.

ios10
Obtaining the password for an iTunes backup provides access to all data on the phone, including that stored in Keychain, which holds all of a user's passwords and other sensitive information.

At this time, we have an early implementation featuring CPU-only recovery. The new security check is approximately 2,500 times weaker compared to the old one that was used in iOS 9 backups. At this time, we are getting these speeds:

iOS 9 (CPU): 2,400 passwords per second (Intel i5)
iOS 9 (GPU): 150,000 passwords per second (NVIDIA GTX 1080)
iOS 10 (CPU): 6,000,000 passwords per second (Intel i5)

In specific terms, security analyst Per Thorsheim of Peerlyst says Apple has switched from using a PBKDF2 hashing algorithm with 10,000 iterations to using a SHA256 algorithm with a single iteration, allowing for a significant speed increase when brute forcing a password.

ios10passwordcrackingelcomsoft

Image via Peerlyst

In a statement given to Forbes, Apple confirmed it is aware of the issue and is working on a fix.

"We're aware of an issue that affects the encryption strength for backups of devices on iOS 10 when backing up to iTunes on the Mac or PC. We are addressing this issue in an upcoming security update. This does not affect iCloud backups," a spokesperson said. "We recommend users ensure their Mac or PC are protected with strong passwords and can only be accessed by authorized users. Additional security is also available with FileVault whole disk encryption."

As Apple points out, this security oversight is limited to backups created on a Mac or PC and does not affect the security of iCloud backups. Most users likely do not need to worry about this issue as it requires access to the Mac or PC that was used to make the backup.

Apple has updates for iOS 10 and macOS Sierra in the works, and it's possible a fix will be included in the new versions of the software. iOS 10.1 and macOS Sierra 10.12.1 were seeded to developers and public beta testers earlier this week.

Related Forum: iOS 10

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Rumored to Use Same Rear Chassis as iPhone 16

Friday July 19, 2024 7:16 am PDT by
Apple will adopt the same rear chassis manufacturing process for the iPhone SE 4 that it is using for the upcoming standard iPhone 16, claims a new rumor coming out of China. According to the Weibo-based leaker "Fixed Focus Digital," the backplate manufacturing process for the iPhone SE 4 is "exactly the same" as the standard model in Apple's upcoming iPhone 16 lineup, which is expected to...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Just Two Months Away: Everything We Know

Monday July 15, 2024 4:44 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
bsod

Crowdstrike Says Global IT Outage Impacting Windows PCs, But Mac and Linux Hosts Not Affected

Friday July 19, 2024 3:12 am PDT by
A widespread system failure is currently affecting numerous Windows devices globally, causing critical boot failures across various industries, including banks, rail networks, airlines, retailers, broadcasters, healthcare, and many more sectors. The issue, manifesting as a Blue Screen of Death (BSOD), is preventing computers from starting up properly and forcing them into continuous recovery...
iphone 14 lineup

Cellebrite Unable to Unlock iPhones on iOS 17.4 or Later, Leak Reveals

Thursday July 18, 2024 4:18 am PDT by
Israel-based mobile forensics company Cellebrite is unable to unlock iPhones running iOS 17.4 or later, according to leaked documents verified by 404 Media. The documents provide a rare glimpse into the capabilities of the company's mobile forensics tools and highlight the ongoing security improvements in Apple's latest devices. The leaked "Cellebrite iOS Support Matrix" obtained by 404 Media...
Apple Watch Series 9

2024 Apple Watch Lineup: Key Changes We're Expecting

Tuesday July 16, 2024 7:59 am PDT by
Apple is seemingly planning a rework of the Apple Watch lineup for 2024, according to a range of reports from over the past year. Here's everything we know so far. Apple is expected to continue to offer three different Apple Watch models in five casing sizes, but the various display sizes will allegedly grow by up to 12% and the casings will get taller. Based on all of the latest rumors,...
tinypod apple watch

TinyPod Turns Your Apple Watch Into an iPod

Wednesday July 17, 2024 3:18 pm PDT by
If you have an old Apple Watch and you're not sure what to do with it, a new product called TinyPod might be the answer. Priced at $79, the TinyPod is a silicone case with a built-in scroll wheel that houses the Apple Watch chassis. When an Apple Watch is placed inside the TinyPod, the click wheel on the case is able to be used to scroll through the Apple Watch interface. The feature works...

Top Rated Comments

joshwenke Avatar
102 months ago
Physical access to ANY machine is a security risk, no matter how strong password encryption is.
Score: 20 Votes (Like | Disagree)
cicalinarrot Avatar
102 months ago
They must hurry up. Yahoo was lucky enough their stocks were already worth nothing before the hacking.
Score: 17 Votes (Like | Disagree)
dwsolberg Avatar
102 months ago
I love Apple, but this sort of thing is so frustrating from a company that is trying to make privacy be such a huge part of its brand. Without security, privacy cannot exist. It doesn't have a huge effect on me, but it lowers my level of trust that Apple knows what it's doing.

As a developer, this is a pretty glaring flaw, so I can only assume (or hope, rather) it was a temporary implementation that accidentally got through to a release version. Whatever happened, it's bizarre.
Score: 17 Votes (Like | Disagree)
Hanzu Lao Avatar
102 months ago
Pretty lazy on their part.
Score: 13 Votes (Like | Disagree)
asleep Avatar
102 months ago
Lowered security threshold because hacking is becoming less of an issue in 2016...?
Score: 12 Votes (Like | Disagree)
Northgrove Avatar
102 months ago
But this is NOT physical access to the iPhone. They are talking about decrypting the BACKUP data. This data is typically on e hard drive on a PC or Mac or maybe in Apple's iCloud
This is iTunes backups. Most don't use iTunes backups these days, even fewer would have had time to make one for iOS 10. While this doesn't demand physical access to an iPhone, it seems to me like it would demand physical access to a PC or Mac (and only a PC or Mac, not an iPhone or iPad).
Score: 12 Votes (Like | Disagree)