Skip to main content
  1. Home
  2. Phones
  3. Apple
  4. Mobile
  5. Legacy Archives

Why that iOS ‘backdoor’ isn’t really a threat unless Big Brother is after you

Add as a preferred source on Google

Last week, forensic scientist and iOS hacker Jonathan Zdziarski revealed what appears to be a backdoor in iOS at the Hackers On Planet Earth conference in New York. Shortly thereafter, his report flooded the Internet, alerting iOS users to the danger.

Zdziarski stated that the backdoor could be used by hackers, the NSA, or other government agencies to spy on unsuspecting iOS users. Apple stated that no backdoor was intentionally built into iOS and that it works with no government surveillance programs whatsoever. The company also said that the feature is used to diagnose problems with iPhones and iPads only. In response, Zdziarski cautioned iOS users against overreacting to his report, but encouraged Apple to solve the issue.

Recommended Videos

However, Zdziarski did not address the main question that iPhone and iPad users want answered: Is the backdoor in iOS and immediate and likely threat to my iOS devices?

Based on Zdziarski’s report, the answer is no. But before we get to that, let’s take a closer look at his report.

What info does the backdoor reveal?

When exploited, the backdoor Zdziarski found in iOS would allow hackers access to all the metadata stored on your iPhone, your GPS location data, calendar and contacts, photos, and recent messages. The backdoor could easily be used to surveil a person once the device is compromised. Zziarski stated that the features could be used by high-level hackers, the NSA, or other government agencies.

Zdziarski added that although he doesn’t think it’s a “grand conspiracy” by Apple, “there are some services running in iOS that shouldn’t be there, that were intentionally added by Apple as part of the firmware and that bypass backup encryption while copying more of your personal data than ever should come off the phone for the average consumer.”

In a statement to Financial Times writer Tim Bradshaw, Apple countered that iOS is designed “so that its diagnostic functions do not compromise user privacy and security, but still provides needed information to enterprise IT departments, developers and Apple for troubleshooting technical issues,” adding that “a user must have unlocked their device and agreed to trust another computer before that computer is able to access this limited diagnostic data. The user must agree to share this information, and data is never transferred without their consent.”

Apple (once again) did deny creating the backdoor to give governments easy access to user data.

How would a hacker access the information?

Zdziarski’s report revealed that hackers can access the backdoor  only when the iPhone or iPad is paired via USB with a Mac or PC. During the pairing process, a pairing file is created and stored on both the PC/Mac and the iOS device. If a hacker retrieves this file, he can access all the user information listed above. The hacker could then surveil the user from the device itself, after using a few tools built into iOS itself.

  • Using the lockdownd feature, the com.apple.mobile.installation_proxy service lets any person with an Apple enterprise license to download malware to the iOS device.
  • Hackers could exploit the com.apple.mobile.house_arrest feature to view databases and personal data from third-party apps. The tool also includes a packet sniffer, which can record every action the user takes on the iOS device from then on.
  • Another tool called file relay could let hackers copy all your metadata, GPS location, calendar, contacts, photos, and recent messages typed on the screen.

However, in order to access all these malicious backdoor features in iOS, hackers must go through several key steps with specific information on hand. First, the hacker has to know where your iOS device is located, what Wi-Fi network its on, and the pairing codes used by your PC or Mac and iOS device during USB pairing. The iOS device must also be unlocked, connected to Wi-Fi, and paired to an infected computer.

Is it easy to exploit the features and will it happen to me?

Apple quickly pointed out that it is highly unlikely that the average hacker will have all that highly detailed information about you and your iOS device. Essentially, the hacker would have to know where you live, have access to your personal computer, and be very stealthy to exploit these features.

Based on Zdziarski’s report, it appears that unless your brother is a hacker or Big Brother is watching you, the backdoor is no threat to you or your personal data.

Nonetheless, the fact that the NSA or other government agencies could take advantage of these features is concerning and Apple should fix the issue immediately.

Malarie Gokey
As DT's Mobile Editor, Malarie runs the Mobile and Wearables sections, which cover smartphones, tablets, smartwatches, and…
Google will now let you sign in with a selfie video
The selfie videos will have a live aspect to avoid spoofing.
Google selfie video verify

For nearly half a decade, Google has been trying to transition users away from the mess of unsafe (and easy-to-guess) passwords. First came hardware keys (like those made by YuBiCo) and then came the password-less login system called Passkeys that enabled biometric sign-ins, too. Now, Google wants you to verify your identity with a selfie video, somewhat like we use Face ID to sign in for services on an iPhone or iPad. 

“Selfie video is a new way to get into your account, giving you more options if you’re ever locked out or don’t have access to your usual phone or computer,” says the company. Google is pushing selfie videos as a secure backup login option, especially in scenarios when you don’t have access to your trusted device and recovering a lost password is not feasible. 

Read more
Dbrand’s Grip cases tout superior protection for the Galaxy Z Flip 8 & Fold 8 without looking dull
Your foldables don't need to be chunky to be well protected
Samsung Galaxy Z Fold 8 Dbrand Grip Case Deal

Samsung’s latest foldables may be thinner and sturdier than their predecessors, though none of these refinements matters a lot if you're planning on slapping a thick protective cover on them. But considering how the lineup starts from $1,200 and even crosses the $2,000 mark, it makes sense to get a case. This is where Dbrand comes in.

It has just launched its Grip cases for the Galaxy Z Flip 8, Galaxy Z Fold 8, and Galaxy Z Fold 8 Ultra, giving buyers a way to protect Samsung’s newest foldables without wrapping them in a dull slab of black plastic. Better yet, Digital Trends readers can currently save 15% on all three cases using the discount code "DIGITALTRENDS15".

Read more
I went hands-on with Samsung Galaxy Z Fold 8 Ultra. It’s peak foldable in an old garb. 
It may not look like a fresh start, but underneath the familiar chassis, there's plenty of thoughtful engineering tweaks.
Samsung Galaxy Z Fold 8 Ultra

Samsung just wrapped up its glitzy Unpacked event, revealing three new foldable phones and a pair of smartwatches. While my heart flutters for the pocketable Galaxy Z Fold 8, it’s the Ultra variant that truly feels like a refinement. Interestingly, when you look at the Galaxy Z Fold 8 Ultra for the first time, you might mistake it for the Galaxy Z Fold 7.

Both of them look identical, and Samsung has not made any visible changes on the Galaxy Z Fold 8 Ultra for it to stand out from its predecessor. Color options, obviously, are fresh this time around, but there are a few changes that have been made under the hood, and they make this phone feel like a practically rewarding iteration.

Read more