New system vulnerability makes iOS 10 easier to break into, Apple says it has started fixing it

New system vulnerability makes iOS 10 easier to break into, Apple says it has started fixing it

Recently, according to foreign media reports, Apple's iPhone was exposed to the latest iTunes backup password verification mechanism used in iOS 10, which makes its system particularly vulnerable to attacks, but Apple now says it has begun repair work.

According to the latest investigation and testing results of Elcomsoft, a company specializing in designing software to gain access to iPhone data, the new iTunes backup password authentication mechanism used in iOS 10 makes the system easier to crack.

It is understood that encrypted iTunes backups on Macbooks or PCs can be protected by passwords, but according to previous data surveys, it is still possible for some password cracking software to force crack them. The current iTunes backup mechanism in the iOS system skips some specific security checks, which makes the cracking work of Elcomsoft easier, and the speed can crack iOS 9 and earlier system versions about 2,500 times faster.

If an attacker obtains the iTunes backup password, it means that they can freely access all data on the phone, including all passwords and other sensitive information stored in the keychain.

At this time, according to previous survey data, it can be found that the attack speed of iOS 10 is about 2500 times that of iOS 9. Here are the specific test results of Elcomsoft:

iOS 9 (CPU): 2400 times per second (Intel i5)

iOS 9 (GPU): 150,000 times per second (NVIDIA GTX 1080)

iOS 10 (CPU): 6,000,000 times per second (Intel i5)

According to the above data, Per Thorsheim, a security analyst from Peerlyst, said: Apple changed the original PBKDF hash algorithm to the SHA256 algorithm in the latest system. The former has 10,000 iterations, while the latter has only one. This situation leads to a significant increase in the speed at which attackers can brute-force attack the mobile phone system.

Apple recently issued a statement to Forbes, in which they said: Apple is aware of this problem and has begun repair work and is working hard to solve this problem. "We know that the latest iTunes backup password authentication mechanism used in iOS 10 is vulnerable to brute force cracking. We are currently working to fix this problem. But this will not affect the security of iCloud backups." An Apple spokesperson said, "We recommend that users set up settings that can only be accessed by authorized users to ensure the password protection of Macs and PCs. For additional security, you can use FileVault full disk encryption."

Apple has updated iOS 10 and Mac OS Sierra, so the issue will likely be fixed in a patch to the new versions of the software. It is understood that iOS 10.1 and Mac Sierra 10.12.1 have been beta tested earlier this week.

As a winner of Toutiao's Qingyun Plan and Baijiahao's Bai+ Plan, the 2019 Baidu Digital Author of the Year, the Baijiahao's Most Popular Author in the Technology Field, the 2019 Sogou Technology and Culture Author, and the 2021 Baijiahao Quarterly Influential Creator, he has won many awards, including the 2013 Sohu Best Industry Media Person, the 2015 China New Media Entrepreneurship Competition Beijing Third Place, the 2015 Guangmang Experience Award, the 2015 China New Media Entrepreneurship Competition Finals Third Place, and the 2018 Baidu Dynamic Annual Powerful Celebrity.

<<:  Observation on Thailand's new energy vehicle industry: a bridgehead in Southeast Asia for China's technology and production capacity transfer

>>:  SEMI Vision: Cloud giants' GPU capital expenditure is expected to exceed US$320 billion in 2025. TSMC and others are accelerating production expansion to cope with the supply-demand gap

Recommend

How to find accurate drainage methods?

There is a cruel fact: the online traffic dividen...

The best things in life happen when you are alone

Leviathan Press: Being alone forces you to think ...

Why have domestic mobile phones made a comeback?

Global mobile phone market landscape Data from th...

10 keywords for brand marketing

I have talked about some of these before, but nev...

When there is only one Java programmer left in the world

[[236202]] In the year 2050, there is only one Ja...

Uncovering the Violent Pornography on WeChat

“You can never cheat the Chinese out of their mon...

Top command line tips from Linux experts

Speaking of fun, nothing beats sitting around the ...

The same old story: TV versions of video sites undergo a name change trend

Since June this year, the State Administration of...

Greedy UIButton in Swift

1. Contents Buttons are very important components...

Be aware that feeling tired for no reason may be a sign of illness!

Some people are full of energy every day, while o...

New efficacy of artemisinin, promising for treating this common disease

In 2015, Tu Youyou's team won the Nobel Prize...

How to master bidding promotion?

The number of consultations has not decreased, bu...