Skip to main content

Don’t worry, the backdoor to your data already exists

iPhone Passcode
ymgerman/123rf
Risk assessment: we’re not even safe in the air anymore. Every time you log into a device and have it connected to the space we call the Internet, it most likely checks for automatic updates … unless you’ve turned them off. Depending on how urban you are, it might be a good idea to do so. Because the very developers you’ve purchased your software from most likely also provided hackers with a pre-installed backdoor. Sort of.

In a recent article on Ars Technica, Leif Ryge discusses the importance of the ongoing encryption battle between Apple and FBI. The FBI demands that Apple develops a new operating system (likely a modified version of iOS); one that would assist the FBI in catching criminals without having to turn to Apple for help –this would also set a nefarious precedent. The Feds also demand that Apple’s devices no longer delete certain data after a limited number of failed PIN unlocking attempts. It would effectively let anyone abuse your phone for hours on end, should they get their hands on it.

There’s also a push for Apple to provide the FBI with a “backdoor” to their operating system — even Apple is calling it such. But that backdoor has existed for a long time; it simply takes the right key to get access, and that’s something the FBI is very interested in. Giving in to those demands would put other IT companies in an awkward position, and unlikely to succeed in refusing the FBI themselves. The clincher is that other countries could follow in the those tracks. After all, if the iPhone is accessible by the United States, why shouldn’t it be the same in, say, China?

But before we start concerning ourselves with whether China will be hacking their way through smartphones on an international level, there’s already a major security flaw to address. Because in pretty much every software update you receive, be it on your computer, tablet, or phone, there’s a hacking buffet awaiting the one that gets a hold of that update’s master key. Assume that this is your operating system for one moment, take a few steps back and breathe.

How often is your device automatically updated (assuming you have that option turned on)? How about the entire OS? For an OS, it most likely checks whether or not you’re using an authentic version of the software before starting the update. At that very moment, it will often use the previously mentioned master key. There can be several keys to get access to your system, and due to their nature, they’re cryptographic single points of failure. They are access points rather than safeguards, should they fall into the wrong hands.

If you’re having a bad day, and a poorly mannered hacker passes by your digital life, they might infer it’s a good day to check for someone with a false sense of security. Provided the conditions are right, the hacker could be in a position to pose as an authentic update to your device. In a worst case scenario, this then equals a malicious automatic update delivered directly to you, one which the hacker tricks your device into believing is real. It wouldn’t look dangerous. For all you’d know it looks like an update with puppy eyes, meant to improve your system stability and ask you to play around with all the new toys/features.

“But,” you ask, “if this key is so powerful, what happens if it’s not just some lone hacker that gets access to that key?” Massive damage, perhaps. It all depends on the intentions of your hacker. The crucial point is that they essentially will have the ability to do as they please with your device. All due to a deliberately placed security system that’s getting outrun by both governments and criminal organizations.

Editors' Recommendations

Dan Isacsson
Being a gamer since the age of three, Dan took an interest in mobile gaming back in 2009. Since then he's been digging ever…
The Arc Pulse is a barely there case for your iPhone 13
The Arc Pulse case is a minimal case designed to protect your iPhone 13 Pro.

When you think about it, the best Apple iPhone 13 cases have a number of different jobs. A case needs to look good, keep your iPhone 13 looking good, and keep it protected against the usual drops and spills. For most, that means a rubber or plastic (or both) case that surrounds your phone in a protective layer and keeps it safe. But is that the only design? Arc doesn't think so.

I've been using the Arc Pulse Case on my iPhone 13 Pro for three weeks, and there's a lot to talk about. One of the biggest of those is the fact that there's not a lot to talk about. Confused? That's why we wanted to bring it to your attention.
Less is more
The guiding principle behind the Arc case is to provide you with 90% of the protection with roughly 10% of the case. The Arc comes in two metal pieces with a 100% recyclable, rubberized/grippy SEBS layer inside. The type of metal depends on which you buy: Titanium or aluminum.

Read more
What to do when your iPhone won’t charge
iPhone battery feature image.

If your iPhone is not charging as you would expect, there are a number of potential fixes available, from restarting your iPhone to changing your Lightning cable. They're all easy to try, and in the vast majority of cases, they'll get your iPhone juiced back up again.
Check, change, or replace the Lightning cable

Your iPhone charges by receiving electricity through its Lightning cable. If it's not charging, then there may be a problem with this cable. Here are a number of things you can try.

Read more
Totallee’s $39 lightweight MagSafe case keeps a tight grip on your iPhone
Totallee MagSafe iPhone case from the side.

Case maker Totallee has introduced a MagSafe version of its super-thin iPhone case, and I’ve been giving it a try over the last few days. I recently sung the praises of Incipio’s MagSafe-equipped Grip case for the iPhone 13 Pro and wanted to see how Totallee’s case compared, especially as I’ve liked the brand’s cases in the past. But how would the thin case affect the MagSafe magnet's grip?

The case is made from flexible TPU with a transparent rear panel matched to a black outer bumper for increased protection. It adds very little additional bulk or thickness to the iPhone and is more pocket-friendly than the Incipio Grip, but it definitely won’t provide as much protection in the event of a serious fall.

Read more