Forensics Firm Offers Tools to Defeat iOS 4 Encryption - MacRumors
Skip to Content

Forensics Firm Offers Tools to Defeat iOS 4 Encryption

by

elcomsoft password breaker
Bright Side of News reports that Russian forensics firm Elcomsoft has discovered a method of cracking Apple's hardware encryption built into iOS 4, providing law enforcement and other parties with a way to access the protected data provided they have physical access to the device.

According to Vladimir Katalov from Elcomsoft, you have to have physical access to the device that is being cracked into:

"Decryption is not possible without having access to the actual device because we need to obtain the encryption keys that are stored in (or computed by) the device and are not dumped or stored during typical physical acquisition."

Elcomsoft offers a basic Phone Password Breaker for Windows priced at $79 for home use and capable of unlocking encrupted backups of BlackBerry and iOS devices. A much more advanced package for iOS 4 devices is available for government agencies, offering access to other information such as passwords, stored email messages, and deleted SMS messages and emails.

Additional details on the decryption processes are available in a blog post on Elcomsoft's site.

Top Rated Comments

munkery Avatar
196 months ago
Most of the actually valuable data, such as website logins and emails, is protected by keychain's tied to the user's passcode. This software still has to brute force the user's passcode which is trivial if the simple 4-digit passcode is used.

Even the non-simple passcode can be brute forced easily if the user doesn't follow basic secure password practices. Passwords should include at least one element from the upper case alphabet, lower case alphabet, numbers, and symbols while also being at least 8 characters long.

Using the escrow keys instead of brute forcing the passcode requires access to both the iOS device and a computer running iTunes with which that specific iOS device has been synced.

If you are really paranoid, just make sure that the passcode is sufficiently difficult to brute force and that you delete iTunes, making sure to remove any of it's associated files, after configuring (updating, etc) the iOS device.
Score: 1 Votes (Like | Disagree)
Doctor Q Avatar
196 months ago
The "other parties" we're talking about aren't just governments. I think it means "anybody".
Score: 1 Votes (Like | Disagree)

Popular Stories

Four iPhone 18 Pro Colors Mock Feature

iPhone 18 Pro Launching Later This Year With These 10 New Features

Tuesday May 26, 2026 6:32 am PDT by
While the iPhone 18 Pro and iPhone 18 Pro Max are not launching until September, there are already plenty of rumors about the devices. It was initially reported that the iPhone 18 Pro models would have fully under-screen Face ID, with only a front camera visible in the top-left corner of the screen. However, the latest rumors indicate that only one Face ID component will be moved under the...
apple wallet drivers license feature iPhone 15 pro

Apple Just Expanded iPhone Driver's License Feature to Arkansas

Wednesday May 27, 2026 9:41 am PDT by
In select U.S. states, residents can add their driver's license or state ID to the Apple Wallet app on the iPhone and Apple Watch, and then use it to display proof of identity or age at select airports and businesses, and in select apps. Starting today, the feature is available in Arkansas, which is the 14th state to offer it. However, it may take some time to roll out to all users. To...
Apple Watch Blood Glucose Monitoring Feature 2

Apple Watch for Diabetes: The Latest on Apple's Plans for Non-Invasive Blood Sugar Monitoring

Tuesday May 26, 2026 9:30 am PDT by
For many years now, it has been rumored that the Apple Watch will eventually gain non-invasive blood sugar monitoring capabilities, which would enable millions of people with diabetes to track their blood glucose levels without needing to prick their skin with a needle or wear a dedicated continuous glucose monitor. According to Bloomberg's Mark Gurman, Apple recently shifted oversight of...