Forensics Firm Offers Tools to Defeat iOS 4 Encryption - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Forensics Firm Offers Tools to Defeat iOS 4 Encryption

by

elcomsoft password breaker
Bright Side of News reports that Russian forensics firm Elcomsoft has discovered a method of cracking Apple's hardware encryption built into iOS 4, providing law enforcement and other parties with a way to access the protected data provided they have physical access to the device.

According to Vladimir Katalov from Elcomsoft, you have to have physical access to the device that is being cracked into:

"Decryption is not possible without having access to the actual device because we need to obtain the encryption keys that are stored in (or computed by) the device and are not dumped or stored during typical physical acquisition."

Elcomsoft offers a basic Phone Password Breaker for Windows priced at $79 for home use and capable of unlocking encrupted backups of BlackBerry and iOS devices. A much more advanced package for iOS 4 devices is available for government agencies, offering access to other information such as passwords, stored email messages, and deleted SMS messages and emails.

Additional details on the decryption processes are available in a blog post on Elcomsoft's site.

Top Rated Comments

munkery Avatar
196 months ago
Most of the actually valuable data, such as website logins and emails, is protected by keychain's tied to the user's passcode. This software still has to brute force the user's passcode which is trivial if the simple 4-digit passcode is used.

Even the non-simple passcode can be brute forced easily if the user doesn't follow basic secure password practices. Passwords should include at least one element from the upper case alphabet, lower case alphabet, numbers, and symbols while also being at least 8 characters long.

Using the escrow keys instead of brute forcing the passcode requires access to both the iOS device and a computer running iTunes with which that specific iOS device has been synced.

If you are really paranoid, just make sure that the passcode is sufficiently difficult to brute force and that you delete iTunes, making sure to remove any of it's associated files, after configuring (updating, etc) the iOS device.
Score: 1 Votes (Like | Disagree)
Doctor Q Avatar
196 months ago
The "other parties" we're talking about aren't just governments. I think it means "anybody".
Score: 1 Votes (Like | Disagree)

Popular Stories

airpods pro 3 pink

New Apple Card Holders Can Get Free AirPods Pro 3, But There's a Catch

Monday May 18, 2026 8:11 am PDT by
Apple today launched a new promotion offering new Apple Card holders the chance to earn back the cost of AirPods Pro 3 through monthly cash rebates, but there is a recurring spend requirement attached. Customers who open a new Apple Card account and purchase AirPods Pro 3 directly from Apple by June 15 will qualify. Starting July 1 and running through April 30, 2027, cardholders can earn $25 ...
Foldable iPhone 2023 Feature 1

Foldable iPhone Production Stalls Amid Hinge Issues

Monday May 18, 2026 7:29 am PDT by
Trial production of Apple's long-anticipated foldable iPhone, likely called the "iPhone Ultra," has run into a significant engineering hurdle centered on hinge reliability, according to a known leaker. The leaker known as "Instant Digital" posted on Weibo that the foldable device's hinge is consistently failing to meet Apple's quality control standards under conditions of prolonged,...
wwdc apple park in person

Apple Announces WWDC 2026 Schedule, Sends Media Invites

Monday May 18, 2026 10:23 am PDT by
Apple today provided a schedule for its 2026 Worldwide Developers Conference, which starts on June 8 and ends on June 12. Apple also sent out invites to members of the media who have been invited to attend an in-person keynote viewing at Apple Park. Both the invites and schedule confirm that the keynote will begin at the standard time, 10:00 a.m. Pacific Time or 1:00 p.m Eastern Time....