iTunes asking for backup password???

I am upgrading my iphone 4 to iOS 5. I backed up my phone (via iTunes 10.5) and downloaded and installed iOS 5. I am now going through the setup process and it is at the "Restore from iTunes Backup" step. I connect to iTunes and iTunes is prompting me for a password to "unlock your iPhone backup file." No I did not encrypt the iPhone backup, nor is it or was it checked in iTunes. I have tried my iTunes password, my 4 digit unlock code for the iPhone, and several other passwords. When I did the backup an hour ago I was not asked for a password. I am at a loss as to what it is.

iPhone 4

Posted on Oct 12, 2011 1:11 PM

Reply
Question marked as Top-ranking reply

Posted on Jul 24, 2012 10:46 AM

Guys, here is our experience with this bug (and yes Apple this is a bad bug not a bad memory) and here is how we got around it.


My wife recently attempted to upgrade her iPhone to 5.1.1 and iTunes advised her that she would need to do a complete backup and restore process on her iPhone which she agreed to and let it start. So it did the backup, upgraded her iPhone and then when it attempted to restore the backup it halted and asked her for the password for her encrypted backup. As other folks have indicated, she hadn't requested this backup or any other backup in the past to be encrypted, but regardless we could not proceed beyond this point. We tried every combination of password she or I had ever used with no avail. We also spent hours with the Genius Bar folks and the online Apple support folks and received plenty of empathy but no results. You really are left with the impression that this is your fault and that somewhere in your dark past you or someone in your family encrypted a backup with a password.


So we went the Elcomsoft password breaker route which some folks here have used with success. i would like to share my experiences here because I feel I owe this forum a favour and also to make sure you know how to get this software to best work for you ,because even though its very powerful, its not totally intuitive.


First Attempt - We downloaded the Elcomsoft free trial version of the software, told it to run, asked it to go against our iPhone backup file, selected the most recent iPhone backup (btw this wasn't that days but instead was one from 2 weeks ago - another bug Apple) and told it to start. When it starts, it will tell you how long it expects to take and in this case it said 4 hours. As the Elcomsoft software is running it says what its "attack rate" is of approximately 700 password attempts per second and it displays its current attempt every second so you can see it work through the possibilities. In this case, under their "task" I had accepted the default "english dic - no mutations" So with this default it just attacked with standard unicase dictionary words and after about 2 hours it finished with no success.


Next Attempt - I wasn't suprised and decided to look deeper. If you double click on "english-dic" it will open a box showing your selection and displaying the mutations options "disabled". if you click that, you can see that you also have the options of minimal, average or maximal mutations. I chose "maximal" and it in turn advised me that it could take up to 4 days to run this attack! So I quickly backed off from that and chose "minimal" and it in turn advised me that it would take up to 30 hours to run this attack. I chose this solution, but before running it on my wife's backup, I ran it on my iPad's backup on a separate computer where I intentionally protected it with a password of "1234". Off it went, and you could see it apply different combinations of numbers, letters and special characters. In was kind of fun to see and in less than 2 minutes, it found the password and came back showing 12**. If you want to see the ** characters, you then need to buy the application at around $80 and get a registration key.


Successful attempt - So with that little success under my belt, I started the "minimal" attack on my wife's computer and her iPhone backup. And 25.5 hours (it said it took 91,871 seconds) later it was successful and showed the result as Pr*****. So at this stage, you could try variations of Pr and 5 characters, but since we had never encrypted our backup and also never used a password beginning with Pr, and because Elcomsoft was going to save us a lot of grief if we had to leave the iPhone at factory settings, we elected to register the software and proceed with payment. Success!! Her phone is now on 5.1.1, all her application data is in place and we have a happy household and I am a hero!


Learnings - #1 - Encrypt your iPhone/ iPad backup intentionally with a password you selected vs. letting some bug somewhere select it for you. #2 - Make sure all your important passwords such as your PC or MAC signon and your online banking software are secure and complex, because this type of software is very powerful and there are a lot of bad guys out there that will use it for the wrong reason. Elcomsoft has provisions to protect it from being used for the wrong purpose, but others might not. During those 25.5 hours, I estimate it attempted over 64 million attacks! #3 Elcomsoft is in Russia! So it will take a few hours to process your payment since they don't seem to work 24/7. So kinda of scary, but it worked.


Thanks

Fred

423 replies

Aug 25, 2015 1:05 PM in response to wsucoug95

I just ran into this issue, and all of these crazy forum threads. I just want to turn off that encrypt local backup checkbox -- I don't care about the prior backup. Almost 4 years later and there is no fix to this? I am imagining Apple picks one major bug at random and refuses to not fix it just to maintain an edgy image, and their team building events they get popcorn and read these forum posts. I hope I entertain you, Apple.

Aug 25, 2015 3:13 PM in response to rockmyplimsoul

"That demonstrates that you don't get it ... if I had access to your stuff and wanted to unencrypt your backup, and all I had to do was delete the existing (encrypted) backup and make a new (unencrypted) one from what's on your iPhone,that would completely defeat the purpose of passwords and encryption. Think about what you're proposing and you'll see the flaw in your logic."

In your example here, you have access to my iPhone. In the normal computer world, if you had access to my device, then you should be able to access all the data on it. It would be my responsibility to either encrypt the device to make it inaccessible, or else make sure it doesn't fall into your hands.

The Apple iTunes user interface makes no mention that it is making my device inaccessible when I encrypt a local backup stored on my computer, therefore Apple is clearly in the wrong, UX-wise.

In the normal computer world, if I make a backup of something, and encrypt that backup, that does not lock me out of whatever I encrypted. That would be bizarre. Yet here we are.

Aug 25, 2015 5:14 PM in response to rockmyplimsoul

rockmyplimsoul wrote:


jared275 wrote:

In the normal computer world, if you had access to my device, then you should be able to access all the data on it.

If I had your device there's no way I'm getting any information out of it without your passcode or finger. Sure there are tools out there to hack into the device

Actually, since iOS 7, there are no tools to hack into an iPhone. Which has the FBI and CIA upset, and some congresscritters want to pass laws making it illegal to sell unhackable devices.

Aug 25, 2015 5:41 PM in response to Csound1

Csound1 wrote:


Your iPhone has not been crippled, can you stay in reasonable proximity to the facts?

My phone (iPad actually) has not been entirely crippled, nor did I claim it was -- I said I have been using it daily for years. However, it has been crippled in regards to the feature I am trying to use (making backups to my local computer), because Apple did not warn me that my device would be crippled in this way if I happened to some day not remember the password of a local computer backup that I no longer needed.


If backup software for servers crippled servers in any way, without telling the owner of the server, especially if it is was something that was not immediately apparent, the users of the software would rightfully raise a bug report.

Aug 25, 2015 6:50 PM in response to Lawrence Finch

Lawrence Finch wrote:


I am confident that servers have competent administrators that understand how security should be implemented. That's why there are tests and certifications for server administrators.


Server backup software works as expected: it doesn't cripple your server when you make an encrypted backup. You don't even need to prepare for a test or certification to know that!


I am confident that server & PC & every other backup software have competent UI designers that understand that users should not be locked out of device features without warning by doing something as innocuous as making an encrypted backup. That's why they don't have 20 page forum threads when users discover they are negatively impacted by a hidden "feature".


Unlike Apple, backup software companies are usually too boring to have a cult following. They just fix misleading user interfaces and move on, instead of living in their own "Apple can do no wrong" bubble for 6 years while the outsiders are infuriated. How wrong does Apple have to be before any of you will admit that their user interface is misleading and lacks sufficient warnings?

Aug 25, 2015 7:13 PM in response to jared275

jared275 wrote:


Lawrence Finch wrote:


I am confident that servers have competent administrators that understand how security should be implemented. That's why there are tests and certifications for server administrators.


Server backup software works as expected: it doesn't cripple your server when you make an encrypted backup. You don't even need to prepare for a test or certification to know that!

Did you need to take a test in order not to understand the need for preserving a password? maybe writing it down?

Aug 25, 2015 7:16 PM in response to Csound1


Did you need to take a test in order not to understand the need for preserving a password? maybe writing it down?


Normally, the only thing that should require a password after encrypting something is when you want to decrypt it. Since I don't want to decrypt what I encrypted (the backup on my local computer), I shouldn't have to enter the encryption password.

Sep 4, 2015 4:55 PM in response to cafarrer

As I said in a previous reply to the same problem on a different page: I know all three passwords for apple and itunes. I write them down. I had three; two I had written down. The third I remember because I only recently changed it. The fix for cafarrer doesn't work for me. It's a shame.


I really hate these Apple forum discussions because I'm desperate when I come here, but mostly I get other people with the same problem, not a solution. What a shame.

Sep 5, 2015 6:18 AM in response to elvindeath

After 36 years of programming you should know that passwords on a computer are not stored in a way that they can be pulled from a password store without the cooperation of the user. And passwords are not stored in plain text anywhere on your computer; they are stored either encrypted or using an irreversible hash. So what you think happened is simply impossible.

Sep 5, 2015 1:58 PM in response to Lawrence Finch

With 36 years of programming, he would have also discovered that programmers, including programmers at Microsoft and Apple are infallible and never make mistakes. (Such as the iTunes programmers who might be referencing stored credentials in the Windows Credential Manager, many of which, due to the infallible wisdom of Microsoft, are stored in an unencrypted (or perhaps decrypted while the user is logged in), insecure way, perhaps referenced by iTunes by an index of an enumeration of credentials, or by a (repeatedly used) username, instead of by an application-unique identifier, and iTunes is either accessing the insecure unencrypted password directly, or else conducting a forward hash against an existing credential's hash in order to unlock the never-encrypted backup from the interface that iTunes locked without the user asking. I don't know exactly how this works, but I don't need to do further research since surely there has never been any security breaches regarding the storage of passwords, ever, in the history of computing, so this is simply impossible.)


Here I am now, looking at Nirsoft Password Recovery tool, seeing a whole bunch of my Windows passwords in clear text, without forward hashing, but since this is impossible, I must also be suffering delusions.


"Once you eliminate the impossible, whatever remains, no matter how improbable, must be the truth." And the truth must therefore be that this support forum should support its people by handing out medication for mass delusion. "Think different," indeed.


User uploaded file

Sep 5, 2015 1:50 PM in response to jared275

FWIW, I'm inclined to stick with Apple for mobile devices, and their stubbornly flawed and (partially) broken iTunes software because they do seem to take security more seriously than Android (or Microsoft, although they improved the credential storage in Windows 8.) However, the quality of support in this forum thread remains hostile to people having legitimate problems, so that doesn't speak well for the community of Apple users.

Sep 30, 2015 8:22 AM in response to elvindeath

I think that since Apple can lock down a computer that's halfway across the world using icloud, they could also offer an option to use that technology to give the necessary credentials to unencrypt a local file. Obviously many people are losing data because of the current situation, and whether they mistakenly input a password without realizing it or simply forgot it, there could be a method of resolving it using the icloud platform, if Apple were so inclined.

Sep 30, 2015 8:46 AM in response to Hotchili

Hotchili wrote:


I think that since Apple can lock down a computer that's halfway across the world using icloud, they could also offer an option to use that technology to give the necessary credentials to unencrypt a local file. Obviously many people are losing data because of the current situation, and whether they mistakenly input a password without realizing it or simply forgot it, there could be a method of resolving it using the icloud platform, if Apple were so inclined.

iTunes backups are local, nothing to do with the cloud.


The answer is not to forget the password, or if you are incapable of that, don't use one

Sep 30, 2015 8:54 AM in response to Hotchili

Hotchili wrote:


I think that since Apple can lock down a computer that's halfway across the world using icloud, they could also offer an option to use that technology to give the necessary credentials to unencrypt a local file. Obviously many people are losing data because of the current situation, and whether they mistakenly input a password without realizing it or simply forgot it, there could be a method of resolving it using the icloud platform, if Apple were so inclined.

Activation Lock does not touch your computer or iOS device. It marks it as locked in THEIR servers. Apple has no access to your computer at all, and the backup passcode is stored only on your computer. That is intentional, so no one can accuse Apple of stealing or accessing your data. And so Apple can legally refuse to unlock your backup for spy agencies or law enforcement, because it is technically impossible. If there were any way for Apple to decrypt your backup, it would just be a matter of time before some hacker figured it out. Be careful what you wish for. This is the whole political argument for "back door" access that the FBI, CIA, NSA, GCHQ some legislators want to mandate.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

iTunes asking for backup password???

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.