Intelligent Load Balancing: Optimizing Password Recovery Across Heterogeneous Units

November 14th, 2024 by Oleg Afonin

In the latest update of Elcomsoft Distributed Password Recovery (EDPR), we’ve introduced a revamped load-balancing feature. The new feature aims to enhance resource utilization on local workstations across diverse hardware configurations. This update has drastically reduced the time required to break passwords in certain hardware configurations, thanks to a refined load distribution algorithm. In this article, we’ll share some technical details on how load balancing leverages a mix of GPUs and CPU cores.

Read the rest of this entry »

iOS vs. Android: Physical Data Extraction and Data Protection Compared

October 20th, 2017 by Oleg Afonin

Today’s mobile devices are getting increasingly more resistant to physical imaging, mostly due to the use of full-disk encryption. Full-disk encryption makes useless some low-level acquisition techniques of yesterday, which includes JTAG and chip-off.

Read the rest of this entry »

Obtaining Detailed Information about iOS Installed Apps

October 3rd, 2017 by Oleg Afonin

Accessing the list of apps installed on an iOS device can give valuable insight into which apps the user had, which social networks they use, and which messaging tools they communicate with. While manually reviewing the apps by examining the device itself is possible by scrolling a potentially long list, we offer a better option. Elcomsoft Phone Viewer can not just display the list of apps installed on a given device, but provide information about the app’s version, date and time of acquisition (first download for free apps and date and time of purchase for paid apps), as well as the Apple ID that was used to acquire the app. While some of that data is part of iOS system backups, data on app’s acquisition time must be obtained separately by making a request to Apple servers. Elcomsoft Phone Viewer automates such requests, seamlessly displaying the most comprehensive information about the apps obtained from multiple sources.

Read the rest of this entry »

Accessing iOS Saved Wi-Fi Networks and Hotspot Passwords

September 28th, 2017 by Oleg Afonin

In this how-to guide, we’ll cover the steps required to access the list of saved wireless networks along with their passwords.

Read the rest of this entry »

Android 8.0 Oreo: Your Text Messages Are in the Cloud Now

September 21st, 2017 by Oleg Afonin

In each major Android update, Google improves security on the one hand, and moves a few more things to the cloud on the other. The recently finalized and finally released Android 8.0 Oreo adds one important thing to all devices running the newest build of Google’s OS: the ability to back up SMS text messages into the user’s Google Account.

Read the rest of this entry »

Elcomsoft Phone Breaker 8, New Apple Devices and iOS 11

September 14th, 2017 by Oleg Afonin

With all attention now being on new iPhone devices, it is easy to forget about the new version of iOS. While new iPhone models were mostly secret until announcement, everyone could test iOS 11 for months before the official release.

Read the rest of this entry »

iOS 11: jailbreaking, backups, keychain, iCloud – what’s the deal?

September 14th, 2017 by Vladimir Katalov

iOS 11 is finally here. We already covered some of the issues related to iOS 11 forensics, but that was only part of the story.

Read the rest of this entry »

iOS 11 Does Not Fix iCloud and 2FA Security Problems You’ve Probably Never Heard About

September 11th, 2017 by Vladimir Katalov

In the US, Factory Reset Protection (FRP) is a mandatory part of each mobile ecosystem. The use of factory reset protection in mobile devices helped tame smartphone theft by discouraging criminals and dramatically reducing resale value of stolen devices. Compared to other mobile ecosystems, Apple’s implementation of factory reset protection has always been considered exemplary. A combination of a locked bootloader, secure boot chain and obligatory online activation of every iPhone makes iCloud lock one exemplary implementation of factory reset protection.

Read the rest of this entry »

New Security Measures in iOS 11 and Their Forensic Implications

September 7th, 2017 by Oleg Afonin

Apple is about to launch its next-generation iOS in just a few days. Researching developer betas, we discovered that iOS 11 implements a number of new security measures. The purpose of these measures is better protecting the privacy of Apple customers and once again increasing security of device data. While some measures (such as the new S.O.S. sequence) are widely advertised, some other security improvements went unnoticed by the public. Let us have a look at the changes and any forensic implications they have.

Read the rest of this entry »

iOS 9.3.5 Physical Acquisition Made Possible with Phoenix Jailbreak

August 24th, 2017 by Oleg Afonin

If you watch industry news, you are probably aware of the new Phoenix jailbreak… or not. During the last several years, getting news about iOS jailbreaks from reliable sources became increasingly difficult. The sheer number of fake Web sites mimicking the look of well-known resources such as Pangu and TaiG made us extra careful when trying newly published exploits.

Read the rest of this entry »

How to Extract iCloud Keychain with Elcomsoft Phone Breaker

August 22nd, 2017 by Olga Koksharova

Starting with version 7.0, Elcomsoft Phone Breaker has the ability to access, decrypt and display passwords stored in the user’s iCloud Keychain. The requirements and steps differ across Apple accounts, and depend on factors such as whether or not the user has Two-Factor Authentication, and if not, whether or not the user configured an iCloud Security Code. Let’s review the steps one needs to take in order to successfully acquire iCloud Keychain.

Read the rest of this entry »