Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,195,592 members, 7,958,825 topics. Date: Thursday, 26 September 2024 at 04:07 AM

Apple Weakens Ios 10 Backup Encryption; Now Can Be Cracked 2,500 Times Faster - Phones - Nairaland

Nairaland Forum / Science/Technology / Phones / Apple Weakens Ios 10 Backup Encryption; Now Can Be Cracked 2,500 Times Faster (313 Views)

How To Backup All Your Phone Data Without The Use Of A Laptop Before Formatting / Tecno Phantom 6 Is Millions Of Times Faster Than A Spacecraft / Glo Released New Data Plan #june #3,000- 12GB, 2,500 - 10GB E.t.c (2) (3) (4)

(1) (Reply)

Apple Weakens Ios 10 Backup Encryption; Now Can Be Cracked 2,500 Times Faster by Psoul(m): 6:54am On Sep 24, 2016
After the iPhone encryption battle between Apple and the FBI, Apple was inspired to work toward making an unhackable future iPhones by implementing stronger security measures even the company can't hack.
Even at that point the company hired one of the key developers of Signal — one of the world's most secure, encrypted messaging apps — its core security team to achieve this goal.
But it seems like Apple has taken something of a backward step.

Apple deliberately weakens Backup Encryption For iOS 10

With the latest update of its iPhone operating system, it seems the company might have made a big blunder that directly affects its users' security and privacy.

Apple has downgraded the hashing algorithm for iOS 10 from "PBKDF2 SHA-1 with 10,000 iterations" to "plain SHA256 with a single iteration," potentially allowing attackers to brute-force the password via a standard desktop computer processor.

PBKDF2 stands for Password-Based Key Derivation Function, is a key stretching algorithm which uses a SHA-1 hash with thousands of password iterations, which makes password cracking quite difficult.

In iOS 9 and prior versions back to iOS 4, PBKDF2 function generates the final crypto key using a pseudorandom function (PRF) 10,000 times (password iterations), which dramatically increases authentication process time and makes dictionary or brute-force attacks less effective.

Now Bruteforce 2,500 times Faster than earlier iOS Versions

Moscow-based Russian firm ElcomSoft, who discovered this weakness that is centered around local password-protected iTunes backups, pointed out that Apple has betrayed its users by deliberately downgrading its 6 years old effective encryption to SHA256 with just one iteration.

(1) (Reply)

How To Stop Videos From Playing In Poweram / Lsad NEWS! US Banned All Samsung Note 7s / Intel's Project Alloy , How Does It Affect Virtual Reality???

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 8
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.