Skip to main content

Russian company releases commercial iOS decryption toolset


The first commercially available set of tools for cracking the encryption and passwords on iOS devices has been made available by Russian security company ElcomSoft. One part of their software is a password breaker, while another part, available only to law enforcement and forensic agencies, is able to extract numbers used to create the encryption keys for iOS data to render decrypted images of the device.
The decryption tool requires access to the device in question, but once it's in hand, a few different kinds of keys need can be scraped from it, including the unique device key (UID) and escrow keys calculated using the UID and escrow pairing records. If the device is only protected by a 4-digit passcode, the program then only needs to brute-force its way through that to get access to all of the decryptable information.
iOS was never much of a security fortress (as we've noted numerous times) and even this new tool uses a variation of a previously discovered method. Charlie Miller, of Pwn2Own fame and a principal research consultant with Accuvant, even pointed out to Ars that the Fraunhofer Institute for Secure Information Technology detailed a very similar method in a research paper they put out in February. However, their tools are not for sale.
If your phone or tablet regularly comes under scrutiny of the law, Miller adds that this commercially available toolset is fairly simple to route by using a long, complex password rather than a 4-digit code to protect your data. The ElcomSoft method comes with a password breaker, but much of its efficiency is derived from defining limits on the possible guesses, such as variations on a certain word.
While "beating it out of you" will remain the superior method of password obtainment for the average law enforcer, the password breaker could still come in handy for when you can't remember which characters in your leetspeak password were numbers, and which were letters.

Comments

Popular posts from this blog

The Most Useful Websites and Web Apps

The sites mentioned here, well most of them, solve at least one problem really well and they all have simple web addresses (URLs) that you can easily learn by heart thus saving you a trip to Google. 01.   screenr.com   – record movies of your desktop and send them straight to YouTube. 02.   ctrlq.org/screenshots   – for capturing   screenshots of web pages   on mobile and desktops. 03.   goo.gl   – shorten long URLs and convert URLs into   QR codes . 04.   unfurlr.come   – find the original URL that’s hiding behind a short URL. 05.   qClock   – find the local time of a city using a   Google Map . 06.   copypastecharacter.com   – copy special characters that aren’t on your keyboard. 07.   postpost.com   – a better search engine for twitter. 08.   lovelycharts.com   – create flowcharts, network diagrams, sitemaps, etc. 09.   iconfinder.com   – the best place to find icons of...

Entrepreneurial Mindset

Kurumsal Dijitalleşme mi yoksa Dijital Kurumsallaşma mı? (+Anket)

Eğer benim gibi siz de işinizin önemli bir bölümünü pazar araştırması yaparak geçiriyorsanız muhtemelen siz de en az benim kadar Türkiye'de pazar verisine ulaşmanın ne kadar zor olduğu hakkında defalarca şikayet etmiş ve sonunda yaratıcı yollar keşfetme yolunu tercih etmişsinizdir. Bunun sebebinin analitik düşünceye ihtiyacımızın olmaması mı, tembellik mi, kısa vadeli düşünmemiz mi yoksa insanüstü tahmin ve öngörü yeteneklerine sahip olmamız mı emin değilim. "Y  ou can’t manage what you can’t measure " - "Ö  lçemedeğiniz şeyi yönetemezsiniz " Her ne kadar bu söz, günümüze  yanlış  bir şekilde aktarılmış olsa da, kendi içerisinde kısmi bir doğruluk barındırmakta. Aslında bu söz ile anlatılmak istenen, ölçerek herşeyin yönetilemeyeceği fakat sonuçları iyileştirmek için süreçlerin ölçülmesi ve takip edilmesinin önemli olduğudur.  Sözün asıl sahibi W. Edward Deming, verinin ve gözlemin önemini aşağıdaki sözüyle çok güzel bir şekilde anlatmaktadır....