ElcomSoft can now recover passwords protecting Apple iWork documents. This makes Distributed Password Recovery the first tool to recover passwords for Numbers, Pages and Keynote apps.
The recovery process is painfully slow”, comments Andy Malyshev, ElcomSoft CTO. “Apple used strong AES encryption with 128-bit keys, which makes password attack the only feasible solution. We’re currently able to try several hundred password combinations per second on an average CPU. This is slow, and thus only distributed attacks can be used to achieve a reasonable recovery time. However, the human factor and our product’s advanced dictionary attacks help recover a significant share of these passwords in reasonable timeframe.”
With strong encryption and long keys, an attack on encryption keys is not feasible as long as the encryption is properly implemented. Therefore, Elcomsoft Distributed Password Recovery handles the case by performing an attack against user- selectable passwords, attempting to recover the original plain-text password.
Considering the very nature of iWork as an inexpensive, simple-to-use, consumer-oriented product, chances of ‘guessing’ the right password soon by executing a distributed dictionary attack are very high.
Socialize