Skip to main content

iOS 10 was not great for Apple’s backup security, experts say

In love with the new iOS 10? If you’re a hacker, you probably are. That’s because the newest operating system allegedly makes it “considerably easier” to hack iTunes logins for backup passwords stored on a Mac or PC. According to software company (and iPhone expert) Elcomsoft, the backup method used in iOS 10 “skips certain security checks,” which allowed professional hackers to test backup passwords “approximately 2500 times faster” when compared to iOS 9 and previous generations.

In a blog post detailing its findings, Elcomsoft wrote, “We discovered a major security flaw in the iOS 10 backup protection mechanism. This security flaw allowed us developing a new attack that is able to bypass certain security checks when enumerating passwords protecting local (iTunes) backups made by iOS 10 devices.”

Recommended Videos

If you’re asking how serious of a problem this is, the software company says it’s “severe.” In fact, the company said, widely accessible tools achieved an 80 to 90 percent chance of successfully hacking a backup password — these are tools that can be purchased by just about anyone, not just law enforcement officials.

The problem, security expert Per Thorsheim wrote in a blog on Peerlyst, is that Apple is now using a weaker weaker hashing algorithm when it comes to iPhone data kept on PCs. As Forbes explained, “In iOS 9 and prior versions back to iOS 4, Apple used what’s known as a PBKDF2 algorithm and had the password run through it 10,000 times, so a hacker would have to run their plaintext guess through the algorithm 10,000 times too and repeat the process until a match was found. In the iOS 10 alternative version, a different algorithm known as SHA256 was used but with just one iteration.”

Apple, for its part, has admitted to this shortcoming. “We’re aware of an issue that affects the encryption strength for backups of devices on iOS 10 when backing up to iTunes on the Mac or PC. We are addressing this issue in an upcoming security update. This does not affect iCloud backups,” a spokesperson said. “We recommend users ensure their Mac or PC are protected with strong passwords and can only be accessed by authorized users. Additional security is also available with FileVault whole disk encryption.”

Lulu Chang
Former Digital Trends Contributor
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
Apple iPhone owners urged to download new update now as a security must
An iPhone showing the Apple Password app.

The new iPhone software update, iOS 18.4, could be more critical than is being talked about when it comes to security.

While there are lots of new features added in the latest release, out yesterday, what's less talked about is the 62 security updates and fixes that roll out with this version. Some are quite serious.

Read more
iOS 18.4 is here already and it’s bringing these new emoji
iOS 18 logo on the iPhone 16 Pro

Apple has already released the latest iOS 18.4 update and it's available to download and install now.

Why would you want to do that? Well there are a whole host of new additions, but, surely eight brand new emoji are enough of a draw on their own.

Read more
The iPad doesn’t need AI, but Apple must fix something else
Top view of the rear shell on the 11th Gen iPad.

I just finished testing the new entry-level iPad, and so far, I am fairly impressed by the tablet. You can’t get a better value than this slate for $349. From the external hardware to the innards, there is hardly any alternative from the Android side that can deliver a superior experience.
This year, Apple delivered a couple of surprises, in addition to the expected chip upgrade. You now get twice the storage for the same ask, and the RAM has also been bumped up. In a nutshell, it’s faster, better at multi-tasking, and without any storage headaches, even if your budget is tight.
Apple, however, hasn’t fixed the software situation with iPadOS, which continues to bother with its fair share of quirks in tow. This year, however, the software gulf is even wider between the baseline iPad and every other tablet in Apple’s portfolio. Stage Manager has been the big differentiator so far, but in 2025, we have another deep chasm.

A good riddance with AI

Read more