iOS 10 Vulnerability Makes Bruteforcing Backup Passwords Up To 2,500 Times Faster (Updated)

ElcomSoft, a Russian digital forensics and IT security firm, announced that it found a flaw in iOS 10’s backup password mechanism that allows its password cracking tools to bruteforce a password 2,500 times faster compared to when the old iOS 9 mechanism was being used.

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • Felix_20
    A 12 character password with lower case, upper case, digit and special character (&PassWord10&) would still take 26 385 years to crack @ 6 000 000pwd/sec. Just use strong password, end of the story.

    http://lastbit.com/pswcalc.asp
    Reply
  • derekullo
    "Despite the fact that a single dual core Intel Core i5 CPU was being used"

    Thought all i5 were quad core, at least for desktop when Intel isn't trying to confuse laptop users.

    I could disable 2 of the cores of an i5, but what would be the point?
    Reply
  • Superman_
    Dude, do you even use a 12 character password with lower case, upper case, digit and special character (&PassWord10&) on your phone???
    Reply
  • Felix_20
    Of course! I use a strong password to lock my phone and icloud account then touch id :)
    Reply
  • tom10167
    Lucian is still my favorite writer on this site but thinking an i5 is a dual core (it's 2016!) is pretty bad.
    Reply
  • memadmax
    All of my passwords have a uppercase, a number, and a special in it.... The rest of it is common words however in order to ease memorization...
    Even then it would take 3 million years to crack my password:
    https://howsecureismypassword.net/
    Reply
  • jverboon
    @tom10167 or it was a mobile i5...
    Reply