iOS Security for iOS 10

Apple released this month the new iOS Security for iOS 10.

For this release, Apple focused on:

  • System Security
  • Data protection classes
  • Security Certifications and programs
  • HomeKit, ReplayKit, SiriKit
  • Apple Watch
  • Wi-Fi,VPN
  • Single Sign-on
  • Apple Pay, Paying with Apple Pay on the web
  • Credit, debit, and prepaid card provisioning
  • Safari Suggestions

Full list of topics

System Security

  • Secure boot chain
  • System Software Authorization
  • Secure Enclave
  • Touch ID

Encryption and Data Protection

  • Hardware security features
  • File Data Protection
  • Passcodes
  • Data Protection classes
  • Keychain Data Protection
  • Access to Safari saved passwords
  • Keybags
  • Security certifications and programs

App Security

  • App code signing
  • Runtime process security
  • Extensions
  • App Groups
  • Data Protection in apps
  • Accessories
  • HomeKit
  • SiriKit
  • HealthKit
  • ReplayKit
  • Secure Notes
  • Apple Watch

Network Security

  • TLS
  • VPN
  • Wi-Fi
  • Bluetooth
  • Single Sign-on
  • AirDrop security

Apple Pay

  • Apple Pay components
  • How Apple Pay uses the Secure Element How Apple Pay uses the NFC controller Credit, debit, and prepaid card provisioning Payment authorization
  • Transaction-specific dynamic security code Contactless payments with Apple Pay Paying with Apple Pay within apps
  • Paying with Apple Pay on the web
  • Rewards cards
  • Suspending, removing, and erasing cards

Internet Services

  • Apple ID iMessage FaceTime iCloud
  • iCloud Keychain Siri
  • Continuity
  • Safari Suggestions, Spotlight Suggestions, Lookup, #images, and News
  • Widget in Non-News Countries

Device Controls

  • Passcode protection
  • iOS pairing model
  • Configuration enforcement
  • Mobile device management (MDM) Shared iPad
  • Apple School Manager
  • Device Enrollment
  • Apple Configurator 2
  • Supervision
  • Restrictions
  • Remote Wipe
  • Lost Mode
  • Activation Lock

Privacy Controls

  • Location Services
  • Access to personal data
  • Privacy policy

Apple Security Bounty