In addition, it’s in the human nature to reduce the number of things to remember. Multiple researches confirm it’s a given fact that most people, if not enforced by a security policy, will choose simple, easy to remember passwords such as ‘abc’, ‘password1’ or their dog’s name. These price points clearly suggest that Apple is targeting the consumer market, not government agencies and not corporations with established security policies enforcing the use of long, complex, strong passwords. Mac customers can purchase the suite for $79. Apple iWork is sold to mobile users for $9.99. Brute-forcing is still not a good option, but ElcomSoft’s advanced dictionary attack with customizable masks and configurable permutations is very feasible if we consider one thing: the human factor. Indeed, using multiple computers connected to a large cluster gives us more speed, breaking the barrier of unreasonable and promising realistic recovery timeframe. With as slow a recovery, a distributed attack on the password would be the only feasible one. When starting considering the addition of Apple iWork to the list of supported products, we quickly recognized the speed bottleneck. This is extremely slow considering the number of possible password combinations. While it takes only a hundredth of a second to verify a single password, an attack would be speed-limited to about 500 passwords per second on today’s top hardware. Apple used the PBKDF2 algorithm to derive an encryption key from plain-text passwords, with some 4000 iterations of a hash function (SHA1). However, recovering that plain-text password is also very slow. The original, plain-text password has to be recovered in order to decrypt protected iWork documents. Brute-forcing a 128-bit number on today’s hardware remains impossible. This owes to Apple’s implementation of encryption: the company used an industry-standard AES algorithm with strong, 128-bit keys. The reason for the lack of a password recovery solution for the iWork format is extremely slow recovery speed. Yet, for all this time, no one came out with a feasible password recovery solution for the iWork document format. The iWork suite consists of three apps: Numbers, Pages, and Keynotes, and gained quite some popularity among Apple followers. Apple iWork, an inexpensive office productivity suite for the Mac and iOS platforms, has been around since 20 respectively.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |