Forensic Expert Questions Covert 'Backdoor' Services Included in iOS by Apple
As part of a recent Hackers On Planet Earth (HOPE/X) conference presentation, forensic scientist and iPhone jailbreak expert Jonathan Zdziarski detailed several backdoor security mechanisms that are secretly included in iOS by Apple. These mechanisms make covert data collection easier for Apple and governmental authorities, reports 
Zdziarski via 
ZDNet.  
 Zdziarski confirms that iOS is reasonably secure from attack by a malicious hacker, but notes that the mobile OS includes several forensic services and noticeable design omissions that make the OS vulnerable to snooping by forensic tools.  
 These services, such as "lockdownd," "pcapd" and "mobile.file_relay," can bypass encrypted backups to obtain data and can be utilized via USB, Wi-Fi and possibly cellular. They also are not documented by Apple and are not developer or carrier tools as they access personal data that would be not used for network testing or app debugging purposes.  
 While detailing these backdoors, Zdziarski makes it clear he is not a conspiracy theorist, but does want to know why Apple appears to be deliberately compromising the security of the iPhone and opening the door to professional, covert data access. 
 I am not suggesting some grand conspiracy; there are, however, some services running in iOS that shouldn’t be there, that were intentionally added by Apple as part of the firmware, and that bypass backup encryption while copying more of your personal data than ever should come off the phone for the average consumer. I think at the very least, this warrants an explanation and disclosure to the some 600 million customers out there running iOS devices. At the same time, this is NOT a zero day and NOT some widespread security emergency. My paranoia level is tweaked, but not going crazy. My hope is that Apple will correct the problem. Nothing less, nothing more. I want these services off my phone. They don’t belong there.
 Zdziarski also notes that he isn't the only one aware of these backdoors. Several existing forensic software companies, such as Cellebrite and Elcomsoft, are already exploiting them as part of the forensic services they provide to law enforcement.  
 Consumers who want to limit access to these backdoor services are advised by Zdziarski to enable a complex passcode in iOS and use the enterprise Apple Configurator application to set Mobile Device Management (MDM) restrictions and enable Pair locking which will delete all pairing records. This solution will block third-party forensic software, but won't protect the device contents if it is sent to Apple for analysis.  
 <small>Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our 
Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.</small>   
Recent Mac and iOS Blog Stories • 
Apple to Open New Retail Store in Chongqing, China on July 26  • 
Buyer's Guide Accessory Discounts: Mini Jambox, Sony QX10, Apple Smart Covers, and More • 
Buyer's Guide: Discounts on MacBook Air, Retina MacBook Pro, AppleCare, and More • 
Best Buy Offers Free iHome Speaker With $0 Down iPhone Purchase, Other Deals • 
Photos of Construction Material Hint at Scale of Apple's Spaceship Campus  • 
Upcoming Apple Store in Hanover, Germany Likely Opening in September • 
Blizzard's 'Hearthstone' Expansion 'Curse of Naxxramas' Launching July 22 for Mac/iOS • 
Apple ID Two-Step Verification Now Available in 59 Countries<img width='1' height='1' src='
http://rss.feedsportal.com/c/35070/f/648327/s/3cb5ed9a/sc/5/mf.gif' border='0'/><br clear='all'/>
<a href="
http://da.feedsportal.com/r/199120928763/u/49/f/648327/c/35070/s/3cb5ed9a/sc/5/rc/1/rc.htm" rel="nofollow"><img src="
http://da.feedsportal.com/r/199120928763/u/49/f/648327/c/35070/s/3cb5ed9a/sc/5/rc/1/rc.img" border="0"/>[/url]
<a href="
http://da.feedsportal.com/r/199120928763/u/49/f/648327/c/35070/s/3cb5ed9a/sc/5/rc/2/rc.htm" rel="nofollow"><img src="
http://da.feedsportal.com/r/199120928763/u/49/f/648327/c/35070/s/3cb5ed9a/sc/5/rc/2/rc.img" border="0"/>[/url]
<a href="
http://da.feedsportal.com/r/199120928763/u/49/f/648327/c/35070/s/3cb5ed9a/sc/5/rc/3/rc.htm" rel="nofollow"><img src="
http://da.feedsportal.com/r/199120928763/u/49/f/648327/c/35070/s/3cb5ed9a/sc/5/rc/3/rc.img" border="0"/>[/url]
<img src="[url]http://da.feedsportal.com/r/199120928763/u/49/f/648327/c/35070/s/3cb5ed9a/sc/5/a2.img" border="0"/>[/url]<img width="1" height="1" src="
http://pi.feedsportal.com/r/199120928763/u/49/f/648327/c/35070/s/3cb5ed9a/sc/5/a2t.img" border="0"/><div class="feedflare">
<img src="[url]http://feeds.feedburner.com/~ff/MacRumors-Front?d=yIl2AUoC8zA" border="0"></img>[/url] 
<img src="[url]http://feeds.feedburner.com/~ff/MacRumors-Front?d=6W8y8wAjSf4" border="0"></img>[/url] 
<img src="[url]http://feeds.feedburner.com/~ff/MacRumors-Front?d=qj6IDK7rITs" border="0"></img>[/url]
</div><img src="
http://feeds.feedburner.com/~r/MacRumors-Front/~4/2-BwLmEw1m4" height="1" width="1"/>
Source: 
Forensic Expert Questions Covert 'Backdoor' Services Included in iOS by Apple