Hidden services in iOS may be used to exfiltrate data

July 23, 2014

Security researcher Jonathan Zdziarski has presented his view on iOS security at the HOPE X Conference. Zdziarski believes that Apple has secured iOS enough against common attacker but left backdoors for Apple itself and for cooperating law enforcement agencies to get access to user data. This is illustrated on example of hidden service called which allows access to almost all user’s content. Apple has denied that it installs backdoors to its devices and claimed that the data are collected only for purposes of detection of technical problems. Apple’s statement however does not fully explain the wide range of collected data.

