Skip to main content

iOS 10 was not great for Apple’s backup security, experts say

ios 10 two thirds installed version 1476106688 0 2
Image used with permission by copyright holder
In love with the new iOS 10? If you’re a hacker, you probably are. That’s because the newest operating system allegedly makes it “considerably easier” to hack iTunes logins for backup passwords stored on a Mac or PC. According to software company (and iPhone expert) Elcomsoft, the backup method used in iOS 10 “skips certain security checks,” which allowed professional hackers to test backup passwords “approximately 2500 times faster” when compared to iOS 9 and previous generations.

In a blog post detailing its findings, Elcomsoft wrote, “We discovered a major security flaw in the iOS 10 backup protection mechanism. This security flaw allowed us developing a new attack that is able to bypass certain security checks when enumerating passwords protecting local (iTunes) backups made by iOS 10 devices.”

If you’re asking how serious of a problem this is, the software company says it’s “severe.” In fact, the company said, widely accessible tools achieved an 80 to 90 percent chance of successfully hacking a backup password — these are tools that can be purchased by just about anyone, not just law enforcement officials.

The problem, security expert Per Thorsheim wrote in a blog on Peerlyst, is that Apple is now using a weaker weaker hashing algorithm when it comes to iPhone data kept on PCs. As Forbes explained, “In iOS 9 and prior versions back to iOS 4, Apple used what’s known as a PBKDF2 algorithm and had the password run through it 10,000 times, so a hacker would have to run their plaintext guess through the algorithm 10,000 times too and repeat the process until a match was found. In the iOS 10 alternative version, a different algorithm known as SHA256 was used but with just one iteration.”

Apple, for its part, has admitted to this shortcoming. “We’re aware of an issue that affects the encryption strength for backups of devices on iOS 10 when backing up to iTunes on the Mac or PC. We are addressing this issue in an upcoming security update. This does not affect iCloud backups,” a spokesperson said. “We recommend users ensure their Mac or PC are protected with strong passwords and can only be accessed by authorized users. Additional security is also available with FileVault whole disk encryption.”

Editors' Recommendations

Lulu Chang
Former Digital Trends Contributor
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
iOS 18 may be a giant iPhone update. Here are 6 things it needs
iPhone 15 Pro display with iPhone 15 Pro Max in background.

A new year means new software updates. According to Bloomberg’s Mark Gurman, iOS 18 could be the “biggest” update for iOS in quite some time, though this is something we tend to hear every year. I’m not sure any iOS update has been as big as the jump from iOS 6 to iOS 7, as a lot of the features and design changes since then could be considered iterative.

Personally, I think the last “biggest” iOS update for me was iOS 14, as it allowed for home screen widgets and app icon customization without a jailbreak for the first time. Since then, there haven’t been as many new features in iOS that have been game changers for me, but this is all subjective. What was a big deal for me may not be the same for you, and vice versa.

Read more
I need this iOS concept feature on my iPhone right now
An iOS concept showing a Smart Stack of widgets below the app dock.

It's always fun to imagine and speculate what new smartphone operating systems will bring. With Apple's iOS 18 update launching later this year — and reported to be a big one — there's a lot of anticipation over what Apple's next iPhone update will bring to the table.

We don't know much about what the next iOS update will offer, but there is one feature that I now need it to have. Product designer Gavin Nelson recently shared an iOS concept feature on X (formerly Twitter) and Threads, and it looks incredible.

Read more
Security experts just found two giant smartphone privacy issues
The Apple iPhone 15 Pro Max's camera module.

Apple iPhone 15 Pro Max Andy Boxall / Digital Trends

This has been quite a stunning week in regard to the privacy and security of smartphone users. Specifically, two investigations have revealed troubling privacy concerns around smartphone advertising and iOS' notification system.

Read more