Forensic Expert Questions Covert 'Backdoor' Services Included in iOS by Apple

iOS7-smallAs part of a recent Hackers On Planet Earth (HOPE/X) conference presentation, forensic scientist and iPhone jailbreak expert Jonathan Zdziarski detailed several backdoor security mechanisms that are secretly included in iOS by Apple. These mechanisms make covert data collection easier for Apple and governmental authorities, reports Zdziarski via ZDNet.

Zdziarski confirms that iOS is reasonably secure from attack by a malicious hacker, but notes that the mobile OS includes several forensic services and noticeable design omissions that make the OS vulnerable to snooping by forensic tools.

These services, such as "lockdownd," "pcapd" and "mobile.file_relay," can bypass encrypted backups to obtain data and can be utilized via USB, Wi-Fi and possibly cellular. They also are not documented by Apple and are not developer or carrier tools as they access personal data that would be not used for network testing or app debugging purposes.

While detailing these backdoors, Zdziarski makes it clear he is not a conspiracy theorist, but does want to know why Apple appears to be deliberately compromising the security of the iPhone and opening the door to professional, covert data access.

I am not suggesting some grand conspiracy; there are, however, some services running in iOS that shouldn’t be there, that were intentionally added by Apple as part of the firmware, and that bypass backup encryption while copying more of your personal data than ever should come off the phone for the average consumer. I think at the very least, this warrants an explanation and disclosure to the some 600 million customers out there running iOS devices. At the same time, this is NOT a zero day and NOT some widespread security emergency. My paranoia level is tweaked, but not going crazy. My hope is that Apple will correct the problem. Nothing less, nothing more. I want these services off my phone. They don’t belong there.

Zdziarski also notes that he isn't the only one aware of these backdoors. Several existing forensic software companies, such as Cellebrite and Elcomsoft, are already exploiting them as part of the forensic services they provide to law enforcement.

Consumers who want to limit access to these backdoor services are advised by Zdziarski to enable a complex passcode in iOS and use the enterprise Apple Configurator application to set Mobile Device Management (MDM) restrictions and enable Pair locking which will delete all pairing records. This solution will block third-party forensic software, but won't protect the device contents if it is sent to Apple for analysis.

Update 7:00 PM PT: Apple has released a statement to Tim Bradshaw of the Financial Times, denying Zdziarski's claims.

We have designed iOS so that its diagnostic functions do not compromise user privacy and security, but still provides needed information to enterprise IT departments, developers, and Apple for troubleshooting technical issues. A user must have unlocked their device and agreed to trust another computer before that computer is able to access this limited diagnostic data. The user must agree to share this information, and data is never transferred without their consent.

As we have said before, Apple has never worked with any government agency from any country to create a backdoor in any of our products or services.

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Top Rated Comments

Hustler1337 Avatar
90 months ago
There is no reason to believe Apple would ever do anything to deliberately compromise the security of our data. Apple is the one company that strives to do everything to protect us and our privacy from prying eyes.

This article says otherwise.
Score: 79 Votes (Like | Disagree)
ArtOfWarfare Avatar
90 months ago
I don't understand why people get so worked up about this sort of thing.

Those backdoors are there for your protection. They are put there for the exclusive use of the governments who we democratically elected. i.e.: the good guys.

We should all stop being so suspicious, and learn to fully trust the NSA and GCHQ. These guys are serious, trained professionals - not spotty nerds who are out to steal credit card numbers or pictures of your girlfriend!

As long as these backdoors are secure (and surely they are!), then we have nothing to fear.
Yes, and we should all follow the state issued curfews and hand in our sharp kitchen utensils without resistance. It's for our own protection.

----------------------------------------------------------------------------------

I have two things to say:
1 - If there's a backdoor for governments, there's a backdoor. It's not a matter of if but when the bad guys find out how to get in through it.
2 - What makes you think that the US election system produces good guys that care about you? We have two parties in control of the entire system. They decide who you can vote for. They make sure that if their person wins, the policies in the best interest of the party are implemented. The system doesn't produce the results that are best for the typical citizen - it produces the results that are best for the parties, and neither of them give a crap about your or me or any other typical citizen.
Score: 51 Votes (Like | Disagree)
TheHateMachine Avatar
90 months ago
There is no reason to believe Apple would ever do anything to deliberately compromise the security of our data. Apple is the one company that strives to do everything to protect us and our privacy from prying eyes.

Ignorance is bliss!
Score: 46 Votes (Like | Disagree)
elev8d Avatar
90 months ago
Yeah. No thanks. Get this crap off my phone.
Score: 46 Votes (Like | Disagree)
the Helix Avatar
90 months ago
Data mining...

If the information from this article is true, it's actually quite scary.
It's like selling a TV with a built-in, hidden webcam that can peer into your private life without you knowing it.
Score: 40 Votes (Like | Disagree)
TWSS37 Avatar
90 months ago
blah blah blah blah it's Apple so it's harmless

<if article was about Google/Android> thread burns
Score: 36 Votes (Like | Disagree)

Top Stories

16 inch macbook pro m2 render

When Can We Expect the Redesigned MacBook Pros Now?

Wednesday June 16, 2021 7:11 am PDT by
With no sign of redesigned MacBook Pro models at this year's WWDC, when can customers expect the much-anticipated new models to launch? A number of reports, including investor notes from Morgan Stanley and Wedbush analysts, claimed that new MacBook Pro models would be coming during this year's WWDC. This did not happen, much to the disappointment of MacBook Pro fans, who have been...
maxresdefault

Apple CEO Tim Cook: Sideloading Apps Would 'Destroy the Security' of the iPhone

Wednesday June 16, 2021 10:49 am PDT by
Apple CEO Tim Cook this morning participated in a virtual interview at the VivaTech conference, which is described as Europe's biggest startup and tech event. Cook was interviewed by Guillaume Lacroix, CEO and founder of Brut, a media company that creates short-form video content. Much of the discussion centered on privacy, as it often does in interviews that Cook participates in. He...
2021 back t0 school

Apple Launches 2021 Back to School Promotion: Free AirPods With Eligible Mac or iPad Purchase

Thursday June 17, 2021 4:56 am PDT by
Apple today launched its seasonal back-to-school sale for the upcoming school year in the United States and Canada, offering students free AirPods alongside purchases of select Macs and iPad models. Similar to last year's promotion, this year's offer includes free AirPods alongside the purchase of a MacBook Air, MacBook Pro, the new 24-inch iMac, the Mac Pro, Mac mini, and the new M1-powered ...
m1 imac back

Some M1 iMac Models Shipping With Crooked Mountings

Monday June 14, 2021 12:50 pm PDT by
Some M1 iMacs appear to have a manufacturing defect that causes the display to be mounted on the stand in a way that's not perfectly aligned, leading to a crooked display. YouTuber iPhonedo over the weekend published a review of the M1 iMac, and he found that his machine appeared to be tilted on one side, a mounting disparity that was visibly noticeable and proved with a ruler. Another...
apple watch 6s 202009

Bloomberg: Apple Watch Series 7 to Feature Thinner Screen Bezels, Faster Processor, and Updated Ultra Wideband Tech

Monday June 14, 2021 3:41 am PDT by
This year's Apple Watch Series 7 is likely to have thinner display bezels and use a new lamination technique that brings the display closer to the front cover, according to Bloomberg's Mark Gurman. From the report: The Cupertino, California-based tech giant is planning to refresh the line this year -- with a model likely dubbed the Apple Watch Series 7 -- by adding a faster processor,...
files app ipados 15

iPadOS 15: Files App Gains NTFS Support, Progress Indicator, and More

Tuesday June 15, 2021 3:41 am PDT by
Apple in iPadOS 15 has added the ability to access NTFS-formatted media from within the Files app. The additional support for the Windows-related format, first discovered by YouTuber Steven Fjordstrøm, is read-only, so like on macOS you can't modify files stored on NTFS devices, but you can at least copy any data on them for working on elsewhere on your iPad. The Files app has also gotten a...
applecare lower prices

Apple Lowers Prices of AppleCare+ Plans for M1 MacBook Air and MacBook Pro

Thursday June 17, 2021 7:33 am PDT by
Apple today lowered the prices of AppleCare+ plans for MacBook Air and 13-inch MacBook Pro models equipped with the M1 chip. Coverage offered by the plans, as well as accidental damage fees, appear to remain unchanged. In the United States, AppleCare+ for the MacBook Air now costs $199, down from $249. The new price applies to both M1 and Intel-based MacBook Air models, although Apple no...
maxresdefault

Demo: Check Out AirPlay 2 on a Mac in macOS Monterey

Tuesday June 15, 2021 11:57 am PDT by
With macOS Monterey, Apple has introduced expanded AirPlay 2 support, so you can AirPlay content from an iPhone, iPad, or even another Mac to your main Mac. We thought we'd do a quick demo of this handy new feature in our latest YouTube video. Subscribe to the MacRumors YouTube channel for more videos. With AirPlay to Mac, you can extend or mirror an Apple device's display to a Mac, and since ...
apple new iphone case colors

Apple Releases New Sunflower, Cloud Blue and Electric Orange iPhone 12 Cases

Monday June 14, 2021 11:12 am PDT by
Apple today released silicone iPhone cases for the iPhone 12, 12 Pro, 12 Pro Max, and 12 mini in a series of new colors that include sunflower, cloud blue, and electric orange. Sunflower is a bright yellow shade, cloud blue is a soft, light blue, and electric orange is a bright orange that's darker than the kumquat color and more orange than pink citrus. The new cases are priced starting...
apple watch edition series 5 ceramic black prototype

Apple Planned Black Ceramic Apple Watch Edition Series 5

Wednesday June 16, 2021 5:45 am PDT by
Apple considered offering a black version of the ceramic Apple Watch Edition Series 5, according to newly-shared images of the prototype casing. The images, shared on Twitter by the prototype collector and leaker known as "Mr. White," show a prototype black ceramic Apple Watch casing, alongside the white ceramic version. The ceramic Apple Watch Edition Series 5 was never available in a...