Skip to main content

iOS 10 was not great for Apple’s backup security, experts say

ios 10 two thirds installed version 1476106688 0 2
Image used with permission by copyright holder
In love with the new iOS 10? If you’re a hacker, you probably are. That’s because the newest operating system allegedly makes it “considerably easier” to hack iTunes logins for backup passwords stored on a Mac or PC. According to software company (and iPhone expert) Elcomsoft, the backup method used in iOS 10 “skips certain security checks,” which allowed professional hackers to test backup passwords “approximately 2500 times faster” when compared to iOS 9 and previous generations.

In a blog post detailing its findings, Elcomsoft wrote, “We discovered a major security flaw in the iOS 10 backup protection mechanism. This security flaw allowed us developing a new attack that is able to bypass certain security checks when enumerating passwords protecting local (iTunes) backups made by iOS 10 devices.”

Recommended Videos

If you’re asking how serious of a problem this is, the software company says it’s “severe.” In fact, the company said, widely accessible tools achieved an 80 to 90 percent chance of successfully hacking a backup password — these are tools that can be purchased by just about anyone, not just law enforcement officials.

The problem, security expert Per Thorsheim wrote in a blog on Peerlyst, is that Apple is now using a weaker weaker hashing algorithm when it comes to iPhone data kept on PCs. As Forbes explained, “In iOS 9 and prior versions back to iOS 4, Apple used what’s known as a PBKDF2 algorithm and had the password run through it 10,000 times, so a hacker would have to run their plaintext guess through the algorithm 10,000 times too and repeat the process until a match was found. In the iOS 10 alternative version, a different algorithm known as SHA256 was used but with just one iteration.”

Apple, for its part, has admitted to this shortcoming. “We’re aware of an issue that affects the encryption strength for backups of devices on iOS 10 when backing up to iTunes on the Mac or PC. We are addressing this issue in an upcoming security update. This does not affect iCloud backups,” a spokesperson said. “We recommend users ensure their Mac or PC are protected with strong passwords and can only be accessed by authorized users. Additional security is also available with FileVault whole disk encryption.”

Lulu Chang
Former Digital Trends Contributor
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
There’s an easy way to follow election results on your iPhone. Here’s how
Screenshot of Apple News on an iPhone.

It’s Election Day in the U.S., and Apple is making it easier for people to check real-time results. The Apple News app will have a Live Activity feature that starts displaying results on your device as they come in tonight. The Live Activity on iPhone will appear on the Dynamic Island (if your iPhone has it) and the lock screen.

For the election, the Live Activity feature will provide up-to-date information, eliminating the need to refresh the Apple News app. You can expect results for the presidential, Senate, and House races to be posted.

Read more
iOS 18.2 just took another step toward its official release
iOS 18 logo on the iPhone 16 Pro

Yet another iOS update is ready, and this one is important. The iOS 18.2 beta 2 update is live, and it's a big deal for a couple of reasons. It's available to more people than the previous beta, and it indicates another step toward iOS 18.2's public launch.

The first version of this beta was only available to people whose phones supported Apple Intelligence, but this latest version works with any phone that can update to iOS 18. Addditionally, iOS 18.2 beta 2 is only available to developer beta testers. There isn't a public beta at the moment, and we have no word on when one might release. Still, it's good to see that more people are included this time around.

Read more
I already damaged my Apple Watch Series 10
i already damaged my apple watch series 10 dt 1

I don’t think I’m clumsy, but I swing my arms a lot and still grimace every time a smartwatch on my wrist hits an immovable object. Yet, for all this movement, I’ve never managed to deeply scratch or lightly crack an Apple Watch display … until now.

The Apple Watch Series 10 doesn’t have many compromises over the Apple Watch Ultra 2, and I even made the switch permanently before this happened. It’s big, thin, and beautiful, but the Apple Watch Series 10 also uses a less durable protective shield for its display.

Read more