Researcher Claims iOS Backdoor; Apple Says for 'Diagnostics' Only

Advertisement
By NDTV Correspondent | Updated: 22 July 2014 10:27 IST
The question of 'who has access to data on our smartphones?' has reared its ugly head again, with security researcher highlighting 'backdoors' in iOS devices that can potentially be used by Apple - or any third-party agency like the NSA - to 'spy' on users.

Jonathan Zdziarski, an iOS forensic examiner, gave a presentation at the HOPE X hacker conference last Friday detailing hidden data-collection processes that run on iOS devices. This data can then be seen by a 'trusted' computer that has been 'paired' with the iOS device via USB. and How would someone connect to these mechanisms on an iPhone? Zdziarski explained the trick has to do with iOS "pairing." Once the pairing has been done, the keys and certificates that identify this element of 'trust' are stored on both the iOS device as well as the desktop.

Anyone with access to this pairing data, the researcher claims, can then locate the specific iOS device on a Wi-Fi network. However, perhaps the most interesting bit is what happens once the pairing relationship has been established. Tools like com.apple.mobile.file_relay - which Zdziarski describes as a "undocumented file-relay service that really only has relevance to purposes of spying and/or law enforcement" - are allegedly given automatic access to data, allowing copying and relay of all data stored on iOS device.

Another tool, according to the researcher, is a packet sniffer that views all network traffic and HTTP header data going to and from the iOS device.

Advertisement

"Why do we need a packet sniffer running on 600 million personal iOS devices?" Zdziarski asked during his presentation.

Advertisement

While his presentation, expectedly, sent everyone in a tizzy, Zdziarski himself tried to downplay the presentation, though he urged Apple to come clean.

"I have NOT accused Apple of working with NSA, however I suspect (based on released documents) that some of these services MAY have been used by NSA to collect data on potential targets," he said in a blog post. "I am not suggesting some grand conspiracy; there are, however, some services running in iOS that shouldn't be there, that were intentionally added by Apple as part of the firmware, and that bypass backup encryption while copying more of your personal data than ever should come off the phone for the average consumer."

Advertisement

Apple issued a statement on Monday terming the features 'diagnostic' in nature. Here is Apple's statement in full:

We have designed iOS so that its diagnostic functions do not compromise user privacy and security, but still provides needed information to enterprise IT departments, developers and Apple for troubleshooting technical issues," Apple told iMore. "A user must have unlocked their device and agreed to trust another computer before that computer is able to access this limited diagnostic data. The user must agree to share this information, and data is never transferred without their consent.As we have said before, Apple has never worked with any government agency from any country to create a backdoor in any of our products or services.

Zdziarski dismissed Apple's explanation, saying any diagnostic feature must have a way it can be disabled.

Advertisement

"The problem with this is that these services dish out data (and bypass backup encryption) regardless of whether or not "Send Diagnostic Data to Apple" is turned on or off, and whether or not the device is managed by an enterprise policy of any kind," Zdziarski said in another blog post. "So if these services were intended for such purposes, you'd think they'd only work if the device was managed/supervised or if the user had enabled diagnostic mode. Unfortunately this isn't the case and there is no way to disable these mechanisms."

Clearly, we haven't heard the last on this subject.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. MacBook Neo Launched in India With 13-Inch Display, A18 Pro Chip: See Price
  2. iPhone 17e vs iPhone 17: Price in India, Features, Specifications Compared
  3. Vivo X300 FE Launched as Global Version of This Chinese Smartphone
  4. Apple Studio Display, Studio Display XDR With 27-Inch 5K Displays Launched in India
  1. Hubble Constant Puzzle Deepens as Supernova and CMB Measurements Clash
  2. MacBook Neo Launched in India With 13-Inch Liquid Retina Display, Apple's A18 Pro Chip: Price, Specifications
  3. Samsung Galaxy A37, Galaxy A57 Spotted on Geekbench With Better Results Ahead of Anticipated Launch
  4. Vivo X300 FE Launched With Snapdragon 8 Gen 5, 50-Megapixel Telephoto Camera: Price, Features
  5. Vivo V70 FE Colour Options, Key Specifications Revealed Ahead of March 9 Launch
  6. Apple MacBook Neo Reportedly Listed on Regulatory Site Hours Before Anticipated Launch
  7. Tecno Pop X Launched in India With 5,000mAh Battery, IP64 Rating: Price, Specifications
  8. Tecno Megapad 2, Tecno Watch GT 1S and Tecno FreeHear 2 Unveiled at MWC 2026: Availability, Features
  9. Mike & Nick & Nick & Alice OTT Release Date: Know When and Where to Watch it Online
  10. MediaTek Showcases AI Glasses at MWC 2026; Demonstrates Emergency Satellite Alerts With Starlink
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.