Apple to fix backup security vulnerability in iOS 10
Apple plans to fix a vunerability in iOS 10 discovered by controversial Russian forensics company Elcomsoft that puts iPhones’ security at risk.
Apple added an alternative password verification mechanism to iOS 10, inadvertently weakening the security of local backups, the company said.
Elcomsoft, which produces iPhone probing tools that are available to any buyer, claims to have discovered a “major security flaw” in the iOS 10 backup protection mechanism. According to security researcher Per Thorsheim, the mechanism uses a simpler algorithm than the previous password-based key derivation function 2 (PBKDF2) with SHA1 (secure hash algorithm), which uses 10,000 iterations to obfuscate credentials.
