Researcher Claims iOS Backdoor; Apple Says for 'Diagnostics' Only

Advertisement
By NDTV Correspondent | Updated: 22 July 2014 10:27 IST
The question of 'who has access to data on our smartphones?' has reared its ugly head again, with security researcher highlighting 'backdoors' in iOS devices that can potentially be used by Apple - or any third-party agency like the NSA - to 'spy' on users.

Jonathan Zdziarski, an iOS forensic examiner, gave a presentation at the HOPE X hacker conference last Friday detailing hidden data-collection processes that run on iOS devices. This data can then be seen by a 'trusted' computer that has been 'paired' with the iOS device via USB. and How would someone connect to these mechanisms on an iPhone? Zdziarski explained the trick has to do with iOS "pairing." Once the pairing has been done, the keys and certificates that identify this element of 'trust' are stored on both the iOS device as well as the desktop.

Anyone with access to this pairing data, the researcher claims, can then locate the specific iOS device on a Wi-Fi network. However, perhaps the most interesting bit is what happens once the pairing relationship has been established. Tools like com.apple.mobile.file_relay - which Zdziarski describes as a "undocumented file-relay service that really only has relevance to purposes of spying and/or law enforcement" - are allegedly given automatic access to data, allowing copying and relay of all data stored on iOS device.

Another tool, according to the researcher, is a packet sniffer that views all network traffic and HTTP header data going to and from the iOS device.

Advertisement

"Why do we need a packet sniffer running on 600 million personal iOS devices?" Zdziarski asked during his presentation.

Advertisement

While his presentation, expectedly, sent everyone in a tizzy, Zdziarski himself tried to downplay the presentation, though he urged Apple to come clean.

"I have NOT accused Apple of working with NSA, however I suspect (based on released documents) that some of these services MAY have been used by NSA to collect data on potential targets," he said in a blog post. "I am not suggesting some grand conspiracy; there are, however, some services running in iOS that shouldn't be there, that were intentionally added by Apple as part of the firmware, and that bypass backup encryption while copying more of your personal data than ever should come off the phone for the average consumer."

Advertisement

Apple issued a statement on Monday terming the features 'diagnostic' in nature. Here is Apple's statement in full:

We have designed iOS so that its diagnostic functions do not compromise user privacy and security, but still provides needed information to enterprise IT departments, developers and Apple for troubleshooting technical issues," Apple told iMore. "A user must have unlocked their device and agreed to trust another computer before that computer is able to access this limited diagnostic data. The user must agree to share this information, and data is never transferred without their consent.As we have said before, Apple has never worked with any government agency from any country to create a backdoor in any of our products or services.

Zdziarski dismissed Apple's explanation, saying any diagnostic feature must have a way it can be disabled.

Advertisement

"The problem with this is that these services dish out data (and bypass backup encryption) regardless of whether or not "Send Diagnostic Data to Apple" is turned on or off, and whether or not the device is managed by an enterprise policy of any kind," Zdziarski said in another blog post. "So if these services were intended for such purposes, you'd think they'd only work if the device was managed/supervised or if the user had enabled diagnostic mode. Unfortunately this isn't the case and there is no way to disable these mechanisms."

Clearly, we haven't heard the last on this subject.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 15 Pro Max, Reno 15 Pro Launched Globally Alongside Reno 15
  2. Beauty (2025) OTT Release Date: When and Where to Watch it Online?
  3. Here's How Much the Realme 16 Pro Series Could Cost in India
  4. Lenovo to Reportedly Launch Four Copilot+ PCs at CES 2026
  5. These Three Xiaomi 17 Series Phones Could Launch in India in Q1 2026
  6. This WhatsApp Greeting Could Wipe Your Bank Account
  7. Hearing Static Noise on Your iPhone 17 Pro Max? You're Not Alone
  1. New Year 2026 Custom Greetings: 5 Best AI Prompts for ChatGPT, Gemini, and Other AI Tools
  2. NASA’s Chandra Spots Champagne Cluster Formed by a Massive Galaxy Collision
  3. NASA’s Curiosity Rover Sends Stunning Sunrise-and-Sunset Holiday Postcard from Mars
  4. Oppo Find X9s Key Specifications Leaked Again; Might Also Launch in India
  5. Redmi Turbo 5, Redmi Turbo 5 Pro to Be Equipped With Upcoming MediaTek Dimensity Chips, Tipster Claims
  6. Vivo V70 Presence on IMDA Certification Database Points to Imminent Release
  7. MediaTek Dimensity 7100 Chipset Launched For Mid-Ranged Phones, Brings Efficiency Gains
  8. JWST Reveals Powerful Winds and Dense Atmosphere on Scorching Exoplanet TOI-561b
  9. New Year 2026 Scam Alert: This WhatsApp Greeting Could Wipe Your Bank Account
  10. Apple Fitness+ Teaser Hints at New Features Coming in January 2026
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.