Apple has seriously weakened iOS 10 backups against password hackers
A flaw Apple introduced in iOS 10 has made it far easier for password crackers to brute-force data backed up to iTunes, including credentials stored in Keychain.
iOS 10 might be the most secure version of Apple's mobile OS, but Apple reportedly made a serious blunder in its implementation of password verifications for iOS 10 backups to iTunes on Mac and Windows PCs.
The claim comes from Russian forensics firm Elcomsoft, which reported on Friday that iOS 10's password security checks for backups are now 2,500 times weaker to password-crackers than previous versions of iOS. If the password to the backup is cracked, it would not only expose backed-up data and content but also allow the attacker to recover credentials from Apple's Keychain password manager, where passwords and authentication tokens are stored for Safari, credit-card data, and third-party apps.