Elcomsoft, a company that creates and sells password-breaking software, says Apple added an alternative password verification mechanism for iTunes backups in iOS 10 that is 2,500 times weaker than the one used in iOS 9.
The new iTunes backup password verification system does not replace the original system, which uses a much stronger algorithm, but it coexists with it.
The company says this new system allows a password-cracking app to try more passwords per second than the older system used for iOS 9 devices and earlier.
What this means is that an attacker can gain access to a password-protected iTunes backup file created in iOS 10 and can brute-force the password using this “new” alternative system to crack the file much faster.
Elcomsoft says it was able to test 6 million passwords per second using only CPU processing power on an iOS 10 backup file. Previously, for backups created with iOS 9, the company was only able to test 2,400 passwords per second, which is 2,500 times fewer passwords.
Researchers said they are working on a password cracking attack for iOS 10 backup files that will use the processing power of a GPU (graphics card). For iOS 9 devices, this allowed the researchers to try 150,000 passwords per second.
If the same 62.5 amplification factor is maintained (not likely, though), an attacker would be able to try about 375 million passwords per second for iOS 10 backups.
Combining attacks with dictionaries of frequently used passwords will speed up brute-force even further by trying the most common passwords first.
Gaining access to an iTunes backup allows an attacker to compromise all of a user's data - including Keychain content that includes passwords from online accounts, credit card information, Wi-Fi network information and more.

