iTunes Backup Passwords 'Much Easier' to Crack in iOS 10, Apple Working on Fix

iOS 10 uses a new password verification mechanism for iTunes backups that makes them easier to crack, according to testing performed by Elcomsoft, a company that specializes in software designed to access iPhone data.

Encrypted iTunes backups created on a Mac or PC are protected by a password that can potentially be brute forced by password cracking software. The backup method in iOS 10 "skips certain security checks," allowing Elcomsoft to try backup passwords "approximately 2500 times faster" compared to iOS 9 and earlier operating systems.

ios10
Obtaining the password for an iTunes backup provides access to all data on the phone, including that stored in Keychain, which holds all of a user's passwords and other sensitive information.

At this time, we have an early implementation featuring CPU-only recovery. The new security check is approximately 2,500 times weaker compared to the old one that was used in iOS 9 backups. At this time, we are getting these speeds:

iOS 9 (CPU): 2,400 passwords per second (Intel i5)
iOS 9 (GPU): 150,000 passwords per second (NVIDIA GTX 1080)
iOS 10 (CPU): 6,000,000 passwords per second (Intel i5)

In specific terms, security analyst Per Thorsheim of Peerlyst says Apple has switched from using a PBKDF2 hashing algorithm with 10,000 iterations to using a SHA256 algorithm with a single iteration, allowing for a significant speed increase when brute forcing a password.

ios10passwordcrackingelcomsoft

Image via Peerlyst

In a statement given to Forbes, Apple confirmed it is aware of the issue and is working on a fix.

"We're aware of an issue that affects the encryption strength for backups of devices on iOS 10 when backing up to iTunes on the Mac or PC. We are addressing this issue in an upcoming security update. This does not affect iCloud backups," a spokesperson said. "We recommend users ensure their Mac or PC are protected with strong passwords and can only be accessed by authorized users. Additional security is also available with FileVault whole disk encryption."

As Apple points out, this security oversight is limited to backups created on a Mac or PC and does not affect the security of iCloud backups. Most users likely do not need to worry about this issue as it requires access to the Mac or PC that was used to make the backup.

Apple has updates for iOS 10 and macOS Sierra in the works, and it's possible a fix will be included in the new versions of the software. iOS 10.1 and macOS Sierra 10.12.1 were seeded to developers and public beta testers earlier this week.

Related Forum: iOS 10

Popular Stories

iphone 17 models

No iPhone 18 Launch This Year, Reports Suggest

Thursday January 1, 2026 8:43 am PST by
Apple is not expected to release a standard iPhone 18 model this year, according to a growing number of reports that suggest the company is planning a significant change to its long-standing annual iPhone launch cycle. Despite the immense success of the iPhone 17 in 2025, the iPhone 18 is not expected to arrive until the spring of 2027, leaving the iPhone 17 in the lineup as the latest...
apple intelligence black

Report: Apple's AI Strategy Could Finally Pay Off in 2026

Tuesday December 30, 2025 9:01 am PST by
Apple's restrained artificial intelligence strategy may pay off in 2026 amid the arrival of a revamped Siri and concerns around the AI market "bubble" bursting, The Information argues. The speculative report notes that Apple has taken a restrained approach with AI innovations compared with peers such as OpenAI, Google, and Meta, which are investing hundreds of billions of dollars in data...
apple fitness 2026 1

Apple Teases 'Something Big' Coming Soon to Apple Fitness+

Tuesday December 30, 2025 2:11 pm PST by
The Apple Fitness+ Instagram account today teased that the service has "big plans" for 2026. In a video, several Apple Fitness+ trainers are shown holding up newspapers with headlines related to Apple Fitness+. What's Apple Fitness+ Planning for the New Year? Something Big is Coming to Apple Fitness+ The Countdown Begins. Apple Fitness+ 2026 is Almost Here 2026 Plans Still Under ...
iphone 17 pro dark blue 1

iPhone 17 Pro and Pro Max Users Report Static Speaker Noise While Charging

Tuesday December 30, 2025 10:39 am PST by
iPhone 17 Pro and Pro Max owners are having trouble with the speakers of their devices, and have complained about a static or hissing noise that occurs when the iPhone is charging. There are multiple discussions about the issue on Reddit, the MacRumors forums, and Apple's Support Community, where affected users say there is a noticeable static noise "like an old radio." Some people report...
maxresdefault

Hands-On With a Rough iPhone Fold Mockup

Monday December 29, 2025 10:55 am PST by
Apple is rumored to be introducing a foldable iPhone in September 2026, and since it will bring the biggest form factor change since the iPhone was introduced in 2007, curiosity about the design is high. A 3D designer created an iPhone Fold design based on rumors, and we printed it out to see how it compares to Apple's current iPhones. Subscribe to the MacRumors YouTube channel for more ...
maxresdefault

Where's the New Apple TV?

Monday December 22, 2025 11:30 am PST by
Apple hasn't updated the Apple TV 4K since 2022, and 2025 was supposed to be the year that we got a refresh. There were rumors suggesting Apple would release the new Apple TV before the end of 2025, but it looks like that's not going to happen now. Subscribe to the MacRumors YouTube channel for more videos. Bloomberg's Mark Gurman said several times across 2024 and 2025 that Apple would...
Mac Pro Feature Blue

What's Happening With the Mac Pro?

Wednesday December 31, 2025 9:59 am PST by
Apple hasn't updated the Mac Pro since 2023, and according to recent rumors, there's no update coming in the near future. In fact, Apple might be finished with the Mac Pro. Bloomberg recently said that the Mac Pro is "on the back burner" and has been "largely written off" by Apple. Apple apparently views the more compact Mac Studio as the ideal high-end pro-level desktop, and it has almost...
macbook air march 2020

Apple Says Final Intel MacBook Air and Apple Watch Series 5 Now 'Vintage'

Wednesday December 31, 2025 8:39 am PST by
Apple today added the final 13-inch MacBook Air powered by Intel processors, the Apple Watch Series 5, and additional products to its vintage products list. The iPhone 11 Pro was also added to the list after the iPhone 11 Pro Max was added back in September. The full list of products added to Apple's vintage and obsolete list today: MacBook Air (Retina, 13-inch, 2020) iPhone 8 Plus 128GB ...

Top Rated Comments

joshwenke Avatar
121 months ago
Physical access to ANY machine is a security risk, no matter how strong password encryption is.
Score: 20 Votes (Like | Disagree)
cicalinarrot Avatar
121 months ago
They must hurry up. Yahoo was lucky enough their stocks were already worth nothing before the hacking.
Score: 17 Votes (Like | Disagree)
dwsolberg Avatar
121 months ago
I love Apple, but this sort of thing is so frustrating from a company that is trying to make privacy be such a huge part of its brand. Without security, privacy cannot exist. It doesn't have a huge effect on me, but it lowers my level of trust that Apple knows what it's doing.

As a developer, this is a pretty glaring flaw, so I can only assume (or hope, rather) it was a temporary implementation that accidentally got through to a release version. Whatever happened, it's bizarre.
Score: 17 Votes (Like | Disagree)
Hanzu Lao Avatar
121 months ago
Pretty lazy on their part.
Score: 13 Votes (Like | Disagree)
asleep Avatar
121 months ago
Lowered security threshold because hacking is becoming less of an issue in 2016...?
Score: 12 Votes (Like | Disagree)
Northgrove Avatar
121 months ago
But this is NOT physical access to the iPhone. They are talking about decrypting the BACKUP data. This data is typically on e hard drive on a PC or Mac or maybe in Apple's iCloud
This is iTunes backups. Most don't use iTunes backups these days, even fewer would have had time to make one for iOS 10. While this doesn't demand physical access to an iPhone, it seems to me like it would demand physical access to a PC or Mac (and only a PC or Mac, not an iPhone or iPad).
Score: 12 Votes (Like | Disagree)