iOS 14 Forensics: What Has Changed Since iOS 13.7?
iOS 14 is officially out. It’s a big release from the privacy protection standpoint, but little had changed for the forensic expert. In this article, we’ll review what has changed in iOS 14 in the ways relevant for the forensic crowd.
👉 https://blog.elcomsoft.com/2020/09/ios-14-forensics-what-has-changed-since-ios-13-7/
#ios14 #iphone #mobilesecurity #dfir #mobileforensics #eift
iOS 14 is officially out. It’s a big release from the privacy protection standpoint, but little had changed for the forensic expert. In this article, we’ll review what has changed in iOS 14 in the ways relevant for the forensic crowd.
👉 https://blog.elcomsoft.com/2020/09/ios-14-forensics-what-has-changed-since-ios-13-7/
#ios14 #iphone #mobilesecurity #dfir #mobileforensics #eift
Using Screen Time Password to Protect iPhone Local Backups
The iOS backup system is truly unrivalled. The highly comprehensive, versatile and secure backups can be created with Apple iTunes. For the user, local backups are a convenient and easy way to transfer data to a new device or restore an existing one. In malicious hands, the backup becomes a dangerous weapon. Logins and passwords from the Keychain allow hackers accessing the user’s social accounts, messages, and financial information. A backup password can be set to protect local backups, but it can be removed just as easily shall the hacker have access to the physical iPhone and know its passcode. Let's discuss how the Screen Time password can be used to further strengthen the protection of local backups.
👉 https://blog.elcomsoft.com/2020/09/using-screen-time-password-to-protect-iphone-local-backups/
#iphone #ios #itsecurity #backups #mobilesecurity
The iOS backup system is truly unrivalled. The highly comprehensive, versatile and secure backups can be created with Apple iTunes. For the user, local backups are a convenient and easy way to transfer data to a new device or restore an existing one. In malicious hands, the backup becomes a dangerous weapon. Logins and passwords from the Keychain allow hackers accessing the user’s social accounts, messages, and financial information. A backup password can be set to protect local backups, but it can be removed just as easily shall the hacker have access to the physical iPhone and know its passcode. Let's discuss how the Screen Time password can be used to further strengthen the protection of local backups.
👉 https://blog.elcomsoft.com/2020/09/using-screen-time-password-to-protect-iphone-local-backups/
#iphone #ios #itsecurity #backups #mobilesecurity
The Issue of Trust: Untrusting Connected Devices from Your iPhone
When connecting an iPhone to a computer for the first time, you’ll see the prompt asking you whether to trust the computer. Trusting a computer enables your phone and computer to exchange information. However, should the trusted computer fall into the wrong hands, the pairing record from that computer could be used to pull information from your iPhone. Learn about the risks associated with pairing records and how to block unwanted connections by untrusting connected computers from your iPhone.
👉 https://blog.elcomsoft.com/2020/09/the-issue-of-trust-untrusting-connected-devices-from-your-iphone/
#ios #iphone #iossecurity #dfir #mobileforensics
When connecting an iPhone to a computer for the first time, you’ll see the prompt asking you whether to trust the computer. Trusting a computer enables your phone and computer to exchange information. However, should the trusted computer fall into the wrong hands, the pairing record from that computer could be used to pull information from your iPhone. Learn about the risks associated with pairing records and how to block unwanted connections by untrusting connected computers from your iPhone.
👉 https://blog.elcomsoft.com/2020/09/the-issue-of-trust-untrusting-connected-devices-from-your-iphone/
#ios #iphone #iossecurity #dfir #mobileforensics
Playing devil’s advocate: iPhone anti-forensics
Everyone’s iPhones contain overwhelming amounts of highly sensitive personal information. Even if some of that data is not stored on the device, the iPhone itself or the data inside can work as a key to other many things from bank accounts to private family life. While there are many possible vectors of attack, the attacker will always try exploiting the weakest link. Learn to think like one, find the weakest link and eliminate the potential vulnerabilities before they are exploited. This guide comes from the forensic guys making tools for the law enforcement, helping the good guys break into the bad guys’ iPhones.
👉 https://blog.elcomsoft.com/2020/09/playing-devils-advocate-iphone-anti-forensics/
#dfir #mobilesecurity #iossecurity #antiforensics #icloud #password #iphone
Everyone’s iPhones contain overwhelming amounts of highly sensitive personal information. Even if some of that data is not stored on the device, the iPhone itself or the data inside can work as a key to other many things from bank accounts to private family life. While there are many possible vectors of attack, the attacker will always try exploiting the weakest link. Learn to think like one, find the weakest link and eliminate the potential vulnerabilities before they are exploited. This guide comes from the forensic guys making tools for the law enforcement, helping the good guys break into the bad guys’ iPhones.
👉 https://blog.elcomsoft.com/2020/09/playing-devils-advocate-iphone-anti-forensics/
#dfir #mobilesecurity #iossecurity #antiforensics #icloud #password #iphone
Elcomsoft iOS Forensic Toolkit 6.51 adds support for iOS 14
Elcomsoft iOS Forensic Toolkit 6.51 adds forensic extraction support for devices running iOS 14. Full file system extraction with keychain decryption are available for devices supporting the checkra1n jailbreak, while extended logical acquisition is now compatible with all iOS 14 devices.
👉 https://www.elcomsoft.com/news/763.html
#ios14 #iphone #mobileforensics #dfir #ioskeychain #checkra1n
Elcomsoft iOS Forensic Toolkit 6.51 adds forensic extraction support for devices running iOS 14. Full file system extraction with keychain decryption are available for devices supporting the checkra1n jailbreak, while extended logical acquisition is now compatible with all iOS 14 devices.
👉 https://www.elcomsoft.com/news/763.html
#ios14 #iphone #mobileforensics #dfir #ioskeychain #checkra1n
Mobile Forensics: Are You Ready for iOS 14?
The number of iOS 14 users is on the raise, and we will see it running on most Apple devices pretty soon. Apple had already stopped signing the last version of iOS 13 on all but legacy hardware. Soon, we will only see it running on the iPhone 5s and iPhone 6 which didn’t get the update, and on a small fraction of newer devices. If you are working in the forensic field, what do you need to do to make yourself ready for iOS 14? Our software may help.
👉 https://blog.elcomsoft.com/2020/10/mobile-forensics-are-you-ready-for-ios-14/
#ios #iphone #checkra1n #mobileforensics #dfir #ios14 #jailbreak
The number of iOS 14 users is on the raise, and we will see it running on most Apple devices pretty soon. Apple had already stopped signing the last version of iOS 13 on all but legacy hardware. Soon, we will only see it running on the iPhone 5s and iPhone 6 which didn’t get the update, and on a small fraction of newer devices. If you are working in the forensic field, what do you need to do to make yourself ready for iOS 14? Our software may help.
👉 https://blog.elcomsoft.com/2020/10/mobile-forensics-are-you-ready-for-ios-14/
#ios #iphone #checkra1n #mobileforensics #dfir #ios14 #jailbreak
Elcomsoft Phone Breaker 9.63 – maintenance release
Elcomsoft Phone Breaker 9.63 fixes a number of small but annoying bugs, making the usage experience smoother. With support for iCloud backups and the largest number of synced data categories, Elcomsoft Phone Breaker remains an acquisition tool in a class of its own.
👉 https://www.elcomsoft.com/news/764.html
#ios #iphone #mobileforensics #dfir #icloud #passwords
Elcomsoft Phone Breaker 9.63 fixes a number of small but annoying bugs, making the usage experience smoother. With support for iCloud backups and the largest number of synced data categories, Elcomsoft Phone Breaker remains an acquisition tool in a class of its own.
👉 https://www.elcomsoft.com/news/764.html
#ios #iphone #mobileforensics #dfir #icloud #passwords
Apple Mobile Devices Cheat Sheet
When investigating iOS devices, you may have seen references to the SoC generation. Security researchers and developers of various iOS jailbreaks and exploits often list a few iPhone models followed by a note that mentions “compatible iPad models”. This is especially common when discussing iOS forensics, particularly referring to the chyeckra1n jailbreak. What do those references mean, and how are the iPhone and iPad models related? Can we count the iPod Touch and Apple TV, too? Let’s have a look.
👉 https://blog.elcomsoft.com/2020/10/apple-mobile-devices-cheat-sheet/
#ios #iphone #mobileforensics #checkm8
When investigating iOS devices, you may have seen references to the SoC generation. Security researchers and developers of various iOS jailbreaks and exploits often list a few iPhone models followed by a note that mentions “compatible iPad models”. This is especially common when discussing iOS forensics, particularly referring to the chyeckra1n jailbreak. What do those references mean, and how are the iPhone and iPad models related? Can we count the iPod Touch and Apple TV, too? Let’s have a look.
👉 https://blog.elcomsoft.com/2020/10/apple-mobile-devices-cheat-sheet/
#ios #iphone #mobileforensics #checkm8
Elcomsoft Phone Viewer 5.20 updated for iOS 14
Elcomsoft Phone Viewer gains preliminary support for the updated local and cloud backup formats introduced in iOS 14. The tool can now display the content of iTunes and iCloud backups and synchronized data produced by devices running the new OS.
👉 https://www.elcomsoft.com/news/765.html
#ios #iphone #mobileforensics #dfir
Elcomsoft Phone Viewer gains preliminary support for the updated local and cloud backup formats introduced in iOS 14. The tool can now display the content of iTunes and iCloud backups and synchronized data produced by devices running the new OS.
👉 https://www.elcomsoft.com/news/765.html
#ios #iphone #mobileforensics #dfir
Everything You Wanted to Ask About Cracking Passwords
Making tools for breaking passwords, I am frequently asked whether it’s legal, or how it works, or what one can do to protect their password from being cracked. There are people who have “nothing to hide”. There are those wearing tin foil hats, but there are a lot more people who can make a reasonable effort to secure their lives without going overboard. This article is for them.
👉 https://blog.elcomsoft.com/2020/10/everything-you-wanted-to-ask-about-cracking-passwords/
#passwords #cybersecurity #itsecurity
Making tools for breaking passwords, I am frequently asked whether it’s legal, or how it works, or what one can do to protect their password from being cracked. There are people who have “nothing to hide”. There are those wearing tin foil hats, but there are a lot more people who can make a reasonable effort to secure their lives without going overboard. This article is for them.
👉 https://blog.elcomsoft.com/2020/10/everything-you-wanted-to-ask-about-cracking-passwords/
#passwords #cybersecurity #itsecurity
Elcomsoft breaks VMware, Parallels, and VirtualBox encryption
New Elcomsoft Distributed Password Recovery 4.30 helps forensic experts gain access to evidence stored in encrypted virtual machines. The new release breaks VMware, Parallels, and VirtualBox encryption with high-speed attacks. In addition, the update adds support for multi-volume 7Zip archives, and brings advanced rule editing directly to the user interface.
👉 https://www.elcomsoft.com/news/766.html
#virtualmachines #passwordsecurity #parallels #vmware #virtualbox #computerforensics
New Elcomsoft Distributed Password Recovery 4.30 helps forensic experts gain access to evidence stored in encrypted virtual machines. The new release breaks VMware, Parallels, and VirtualBox encryption with high-speed attacks. In addition, the update adds support for multi-volume 7Zip archives, and brings advanced rule editing directly to the user interface.
👉 https://www.elcomsoft.com/news/766.html
#virtualmachines #passwordsecurity #parallels #vmware #virtualbox #computerforensics
Breaking Encrypted Virtual Machines: Recovering VMWare, Parallels, and VirtualBox Passwords
Virtual machines use a portable, hardware-independent environment to perform essentially the same role as an actual computer. Activities performed under the virtual umbrella leave trails mostly in the VM image files and not on the host computer. The ability to analyze virtual machines becomes essential when performing digital investigations.
Many types of virtual machines used in the criminal world feature secure encryption. Evidence stored in encrypted VM images can be only accessed if one can produce the original encryption password. We built a tool to enable experts run hardware-accelerated distributed attacks on passwords protecting encrypted VM images created by VMWare, Parallels, and VirtualBox.
👉 https://blog.elcomsoft.com/2020/10/breaking-encrypted-virtual-machines-recovering-vmware-parallels-and-virtualbox-passwords/
#vmware #virtualmachines #dfir #virtualbox #parallels #passwords
Virtual machines use a portable, hardware-independent environment to perform essentially the same role as an actual computer. Activities performed under the virtual umbrella leave trails mostly in the VM image files and not on the host computer. The ability to analyze virtual machines becomes essential when performing digital investigations.
Many types of virtual machines used in the criminal world feature secure encryption. Evidence stored in encrypted VM images can be only accessed if one can produce the original encryption password. We built a tool to enable experts run hardware-accelerated distributed attacks on passwords protecting encrypted VM images created by VMWare, Parallels, and VirtualBox.
👉 https://blog.elcomsoft.com/2020/10/breaking-encrypted-virtual-machines-recovering-vmware-parallels-and-virtualbox-passwords/
#vmware #virtualmachines #dfir #virtualbox #parallels #passwords
Ruling Out the Encryption
We all have habits. Morning coffee (no sugar, just some milk), two eggs (sunny side up), reading mail wile you are not completely awaken, and a lot more. We all follow some kind of rules we have set for ourselves. We all have some favorites: names, cities and even numbers; maybe an important date or place. Can we exploit people’s habits to break their passwords effectively instead of using brute force? We can, and here’s the how-to.
👉 https://blog.elcomsoft.com/2020/10/ruling-out-the-encryption/
#encryption #GPU #password
We all have habits. Morning coffee (no sugar, just some milk), two eggs (sunny side up), reading mail wile you are not completely awaken, and a lot more. We all follow some kind of rules we have set for ourselves. We all have some favorites: names, cities and even numbers; maybe an important date or place. Can we exploit people’s habits to break their passwords effectively instead of using brute force? We can, and here’s the how-to.
👉 https://blog.elcomsoft.com/2020/10/ruling-out-the-encryption/
#encryption #GPU #password
The Rise of the Virtual Machines
Criminals are among the most advanced users of modern technology. They learned how to hide information in their smartphones and how to encrypt their laptops. They communicate via secure channels. Their passwords never leak, and they do their best to leave no traces. Forensic investigators encounter new challenges every other day. In this article, we will discuss yet another tool used by the criminals to cover their traces: the encrypted virtual machine.
👉 https://blog.elcomsoft.com/2020/10/the-rise-of-the-virtual-machines/
#GPU #vmware #virtualmachines #dfir #virtualbox #parallels #passwords
Criminals are among the most advanced users of modern technology. They learned how to hide information in their smartphones and how to encrypt their laptops. They communicate via secure channels. Their passwords never leak, and they do their best to leave no traces. Forensic investigators encounter new challenges every other day. In this article, we will discuss yet another tool used by the criminals to cover their traces: the encrypted virtual machine.
👉 https://blog.elcomsoft.com/2020/10/the-rise-of-the-virtual-machines/
#GPU #vmware #virtualmachines #dfir #virtualbox #parallels #passwords
Elcomsoft iOS Forensic Toolkit 6.52: plugging the last gap
Elcomsoft iOS Forensic Toolkit 6.52 fills the last gap for jailbreak-free extraction of previously unsupported versions of iOS. The new release expands the availability of the extraction agent, adding full file system and keychain decryption support for previously unsupported versions of iOS 12 on the iPhone 5s and 6.
👉 https://www.elcomsoft.com/news/767.html
#ios #iphone #agent #jailbreakfree #dataextraction
Elcomsoft iOS Forensic Toolkit 6.52 fills the last gap for jailbreak-free extraction of previously unsupported versions of iOS. The new release expands the availability of the extraction agent, adding full file system and keychain decryption support for previously unsupported versions of iOS 12 on the iPhone 5s and 6.
👉 https://www.elcomsoft.com/news/767.html
#ios #iphone #agent #jailbreakfree #dataextraction
iOS Extraction Without a Jailbreak: Finally, Zero-Gap Coverage for iOS 9 through iOS 13.5 on All Devices
We have plugged the last gap in the range of iOS builds supported on the iPhone 5s and 6. The full file system extraction and keychain decryption is now possible on these devices regardless of the version of iOS they are running – at least if that’s iOS 9 or newer. For all other iOS devices up to and including the iPhone 11 Pro Max, we can extract them without a jailbreak if they are running iOS 9 through 13.5 without exceptions. Read how we made this possible.
👉 https://blog.elcomsoft.com/2020/10/ios-extraction-without-a-jailbreak-finally-zero-gap-coverage-for-ios-9-through-ios-13-5-on-all-devices/
#ios #iphone #agent #jailbreakfree #dataextraction #keychain #ipad
We have plugged the last gap in the range of iOS builds supported on the iPhone 5s and 6. The full file system extraction and keychain decryption is now possible on these devices regardless of the version of iOS they are running – at least if that’s iOS 9 or newer. For all other iOS devices up to and including the iPhone 11 Pro Max, we can extract them without a jailbreak if they are running iOS 9 through 13.5 without exceptions. Read how we made this possible.
👉 https://blog.elcomsoft.com/2020/10/ios-extraction-without-a-jailbreak-finally-zero-gap-coverage-for-ios-9-through-ios-13-5-on-all-devices/
#ios #iphone #agent #jailbreakfree #dataextraction #keychain #ipad
13 Years of GPU Acceleration with AMD and NVIDIA
It was exactly 13 years ago when we invented GPU acceleration. The encryption was getting stronger year over year, and the rate of trying the password combinations was (and still is) of great importance. It is the attack rate that determines how long and how complex the password can be discovered after a reasonable wait ranging from a few hours to several weeks.
👉 https://www.elcomsoft.com/news/768.html
#gpucomputing #innovation #nvidia #amd #passwordrecovery
It was exactly 13 years ago when we invented GPU acceleration. The encryption was getting stronger year over year, and the rate of trying the password combinations was (and still is) of great importance. It is the attack rate that determines how long and how complex the password can be discovered after a reasonable wait ranging from a few hours to several weeks.
👉 https://www.elcomsoft.com/news/768.html
#gpucomputing #innovation #nvidia #amd #passwordrecovery
"PESKY RUSSIANS have come up with a novel way of using Nvidia’s graphics hardware – cracking passwords."
Today, we have an important date. It’s been 13 years since we invented a technique that reshaped the landscape of modern password recovery. 13 years ago, we introduced GPU acceleration in our then-current password recovery tool, enabling the use of consumer-grade gaming video cards for breaking passwords orders of magnitude faster.
With today’s proliferation of everything AI relying on GPU units our 13-year-old achievement seems obvious in retrospect. Back then, it was not only far from the obvious, but took us years to design and to implement.
👉 https://blog.elcomsoft.com/2020/10/13-years-of-gpu-acceleration/
#gpuacceleration #gpucomputing #passwordrecovery #innovation #technology
Today, we have an important date. It’s been 13 years since we invented a technique that reshaped the landscape of modern password recovery. 13 years ago, we introduced GPU acceleration in our then-current password recovery tool, enabling the use of consumer-grade gaming video cards for breaking passwords orders of magnitude faster.
With today’s proliferation of everything AI relying on GPU units our 13-year-old achievement seems obvious in retrospect. Back then, it was not only far from the obvious, but took us years to design and to implement.
👉 https://blog.elcomsoft.com/2020/10/13-years-of-gpu-acceleration/
#gpuacceleration #gpucomputing #passwordrecovery #innovation #technology
Extracting the iPhone: (No) Tools Required?
If the iPhone is locked with a passcode, it is considered reasonably secure. The exception are some older devices, which are relatively vulnerable. But what if the passcode is known or is not set? Will it be easy to gain access to all of the data stored in the device? And why do we have the countless forensic tools –is analysis and reporting the sole reason for their existence? Not really. If you’ve been wondering what this acquisition thing is all about, this article is for you.
👉 https://blog.elcomsoft.com/2020/10/extracting-the-iphone-no-tools-required/
#iphone #ios #dataacquisition #dataanalysis #mobileforensics
If the iPhone is locked with a passcode, it is considered reasonably secure. The exception are some older devices, which are relatively vulnerable. But what if the passcode is known or is not set? Will it be easy to gain access to all of the data stored in the device? And why do we have the countless forensic tools –is analysis and reporting the sole reason for their existence? Not really. If you’ve been wondering what this acquisition thing is all about, this article is for you.
👉 https://blog.elcomsoft.com/2020/10/extracting-the-iphone-no-tools-required/
#iphone #ios #dataacquisition #dataanalysis #mobileforensics
May the [Brute] Force Be with You!
Remember the good old times when there was a lot of applications with “snake oil” encryption? You know, the kind of “peace of mind” protection that allowed recovering or removing the original plaintext password instantly? It is still the case for a few “we-don’t-care” apps such as QuickBooks 2021, but all of the better tools can no longer be cracked that easily. Let’s review some password recovery strategies used in our software today.
👉 https://blog.elcomsoft.com/2020/10/may-the-brute-force-be-with-you/
#passwordcracking #passwords #bruteforce #encryption
Remember the good old times when there was a lot of applications with “snake oil” encryption? You know, the kind of “peace of mind” protection that allowed recovering or removing the original plaintext password instantly? It is still the case for a few “we-don’t-care” apps such as QuickBooks 2021, but all of the better tools can no longer be cracked that easily. Let’s review some password recovery strategies used in our software today.
👉 https://blog.elcomsoft.com/2020/10/may-the-brute-force-be-with-you/
#passwordcracking #passwords #bruteforce #encryption
The Forensic View of iMessage Security
Apple iMessage is an important communication channel and an essential part of forensic acquisition efforts. iMessage chats are reasonably secure. Your ability to extract iMessages as well as the available sources of extraction will depend on several factors. Let’s discuss the factors that may affect your ability to extract, and what you can do to overcome them.
👉 https://blog.elcomsoft.com/2020/10/the-forensic-view-of-imessage-security/
#ios #imessage #mobilesecurity #mobileforensics #dfir #icloud
Apple iMessage is an important communication channel and an essential part of forensic acquisition efforts. iMessage chats are reasonably secure. Your ability to extract iMessages as well as the available sources of extraction will depend on several factors. Let’s discuss the factors that may affect your ability to extract, and what you can do to overcome them.
👉 https://blog.elcomsoft.com/2020/10/the-forensic-view-of-imessage-security/
#ios #imessage #mobilesecurity #mobileforensics #dfir #icloud