{"id":3609,"date":"2014-08-06T23:48:14","date_gmt":"2014-08-07T04:48:14","guid":{"rendered":"http:\/\/www.zdziarski.com\/blog\/?p=3609"},"modified":"2023-02-23T10:02:14","modified_gmt":"2023-02-23T15:02:14","slug":"a-post-mortem-on-zdnets-smear-campaign","status":"publish","type":"post","link":"https:\/\/www.zdziarski.com\/blog\/?p=3609","title":{"rendered":"A Post-Mortem on ZDNet&#8217;s Smear Campaign"},"content":{"rendered":"<p>A few days after I gave a talk at the HOPE\/X conference titled, &#8220;Identifying Backdoors, Attack Points, and Surveillance Mechanisms in iOS Devices&#8221;, ZDNet published what their senior editor has described privately to me as an opinion piece, however passed it off as a factual article in an attempt to make headlines at my expense. Now that things have had time to settle down, I&#8217;ve taken the time to calmly write up a post-mortem describing what actually happened as well as some behind-the-scenes details that may shed some light on the drama we&#8217;ve seen from ZDNet and one of its writers over the past couple of weeks. Let me say first that this is the last time I will address this matter, and have no desire to continue to discuss it, or engage with ZDNet or their writer. In fact, I haven&#8217;t engaged with either parties since this all transpired a week or so after my talk, in spite of repeated attempts to bait me with more personal attacks and false claims of harassment.<\/p>\n<p>At HOPE\/X, I gave a very carefully-worded talk describing a number of &#8220;high value forensic services&#8221; that had not been disclosed by Apple to the consumer (some not even to developers),\u00a0such as the com.apple.mobile.file_relay service, which I admitted to the audience as having &#8220;no better word for&#8221; to describe than as a &#8220;backdoor&#8221; to bypass the consumer&#8217;s backup encryption on iOS devices; this doesn&#8217;t necessarily mean a nefarious backdoor, but can simply be an engineering backdoor, like how supervisor passwords or other mechanisms work &#8211; a simple bypass to make things convenient. A number of news agencies reached out to me, and I took time to explain to each journalist that this was nothing to panic about, as\u00a0the threat models were very limited (specifically geared towards law enforcement forensics and potentially foreign espionage). Also, that I did not believe there was any conspiracy here by Apple. Reporters from ARS Technica, Reuters, The Register, Tom&#8217;s Guide, InfoSec Institute, and a number of others spoke to me and got all the time they wanted.\u00a0You can see that these journalists each\u00a0published relatively balanced and non-alarmist stories; even The Register, who prides themselves on outlandish headlines, if you read their story, was actually quite level headed about the matter. A number of other news agencies, who <em>had not<\/em> reached out to me, published sensationalist stories with crazy\u00a0claims of an NSA conspiracy, secret backdoors, and other ridiculous nonsense. I\u00a0tried very hard to throw cold water on those ideas both in my talk and in big letters on my first blog entry,\u00a0with&#8221;DON&#8217;T PANIC&#8221; and\u00a0instructions for journalists.<\/p>\n<p>ZDNet was among the news agencies that had initially published a sensationalist story without approaching me first for questions.<\/p>\n<p><!--more--><\/p>\n<h1>About the Research<\/h1>\n<p>My\u00a0talk was based on research that I had recently submitted to, and had\u00a0<a href=\"http:\/\/www.sciencedirect.com\/science\/article\/pii\/S1742287614000036\">gotten accepted and published<\/a>, in <a href=\"http:\/\/www.journals.elsevier.com\/digital-investigation\">The International Journal of Digital Forensics and Incident Response<\/a>. The research paper was fully peer-reviewed by Editor-in-Chief <a href=\"https:\/\/en.wikipedia.org\/wiki\/Eoghan_Casey\">Eoghan Casey<\/a>, now\u00a0with the Department of Defense. The editorial board for this journal consists of leading researchers from Google, Microsoft, a number of universities, and defense contractors. The journal publishes solid, academic quality research covering a wide range of disciplines within the digital forensics field. My\u00a0research paper goes into thorough detail about the threat models and risks that apply to this research, explains a number of the caveats, and outlines the technical details in a very thorough presentation. During the blind review process, I received feedback from the reviewers, and the research paper was refined and brought to consensus as worthy of publication.<\/p>\n<p>The findings of my research were later validated by a number of researchers, the most prominent of which was a paper published by\u00a0<a href=\"https:\/\/web.archive.org\/web\/20171201171525\/https:\/\/www.strozfriedberg.com\/wp-content\/uploads\/2014\/08\/SFWP_MitigatingPairingRecordRisks_08112014.pdf\">Stroz Friedberg<\/a>.<\/p>\n<h1>The Second ZDNet Story<strong><br \/>\n<\/strong><\/h1>\n<p>A few days after their first story, ZDNet ran a second, this time by a freelance\u00a0reporter going by the name Violet Blue. As was with the first reporter, this one\u00a0also failed to contact me to ask any questions. She ran a smear story with the sole intent of\u00a0trying to\u00a0discredit my claims and fabricate a narrative\u00a0that my research had been debunked. ZDNet already had egg on their face from their first sensationalist story, so perhaps this was an attempt to save face from\u00a0that article, which was also irresponsibly written without my input. In ZDNet&#8217;s story, a number of personal attacks were made against me, and over 30 falsehoods were published in a mere 20 or so sentences. I&#8217;ll document these at the end of this blog post. I initially ignored the smear piece and moved on, however within a few hours, the reporter\u00a0(Violet Blue) resorted to demeaning taunts and baiting tactics on her Twitter account to get my attention. It was at this time I decided to contact ZDNet&#8217;s senior editor. In waiting for a reply, tension flared a bit and I made a few comments (via tweets) to Ms. Blue about the substandard quality of her journalism and lack of principles (which I do not apologize for), as well as two comments about ZDNet&#8217;s desire to publish what I deemed rubbish (again, which I do not apologize for, because it was). Additionally, a number of other well respected members of the InfoSec and iOS hacking communities made comments to Ms. Blue about inaccuracies in her story and the poor taste in which it was written. Here is <a href=\"https:\/\/twitter.com\/chronic\/status\/493531617743220737\">one example<\/a>. Here is <a href=\"https:\/\/twitter.com\/aral\/status\/493386138024161280\">another<\/a>. Here is <a href=\"https:\/\/twitter.com\/iainthomson\/status\/492790727621898240\">yet another<\/a>.<\/p>\n<p>Outside of a few comments and an email to ZDNet&#8217;s editors, I have made absolutely no attempts to engage with, contact, or address Ms. Blue.<\/p>\n<p>Somewhere in the midst of this, I even offered Ms. Blue $100 (via Twitter) to find me one journalist who would say that I led them to panic. She never claimed this bounty.<\/p>\n<h1>Motivations<\/h1>\n<p>During this time, a few things were made known to me privately, by many individuals who had dealt with Ms. Blue and her tactics before. It was explained to me that Blue\u00a0is a manipulator, and that this type of baiting and manipulation was commonplace. I was told\u00a0that she had subjected a number of other innocent individuals to the same harassment; baiting them, taunting them, using her position to make personal attacks&#8230; and then falsely claiming harassment when they responded. This manipulation tactic is referred to as <a href=\"http:\/\/dynamic.uoregon.edu\/jjf\/defineDARVO.html\">DARVO<\/a> (Deny, Attack, Reverse Victim and Offender), and is a technique often employed by abusers. A\u00a0number of credible journalists also contacted me privately to corroborate her\u00a0tactics. I was specifically told by one journalist\u00a0that Ms. Blue &#8220;attacks people in an underhanded way and when they respond screams harassment&#8221; and that she &#8220;makes my profession harder&#8221;. A different journalist expressed frustration that Ms. Blue had also misrepresented his piece as sensationalist in her own smear piece. Yet another journalist had some very not nice things to say about her at all, which do not bear repeating.<\/p>\n<p>Another thing that had been told to me by a few different people privately, were that they had first-hand knowledge that Ms. Blue&#8217;s piece on me had more to do with the fact that I was a Christian (alleging she is very discriminating against those with my beliefs &#8211; plausible, given: <a href=\"https:\/\/twitter.com\/violetblue\/status\/238020005936115712\">link<\/a>, <a href=\"https:\/\/twitter.com\/violetblue\/status\/4619155386\">link<\/a>), and because I had previously written an essay <a href=\"http:\/\/www.zdziarski.com\/blog\/?p=3140\">criticizing Mozilla<\/a> for ousting Brendan Eich as CEO merely due to public opinion about his personal contributions to Proposition 8. Given the reliability of the people who provided this information, it seems like a plausible\u00a0explanation. On the other hand, I haven&#8217;t ruled out misandry all together, or perhaps just sheer ignorance of\u00a0tech.<\/p>\n<p>After learning about Ms. Blue&#8217;s tactics, and seeing her begin to already falsely claim harassment, I immediately decided to stop engaging with her altogether. While Ms. Blue had claimed publicly that she blocked my Twitter account, this was just one of many lies\u00a0she&#8217;d made up, and so even while seeing her attacks continue, I have since continued to ignore her attempts to bait me &#8211; up to and including her posting derogatory comments about me on a tumblr account in the form of an &#8220;interview&#8221; that never took place (a reporter sent me the same questions for a followup). During this period where Ms. Blue had alleged I had &#8220;harassed&#8221; her, she was making numerous personal attacks against me, accused me of attacking her using a troll\u00a0account (which I hadn&#8217;t, and never would do), hurled insults at me such as\u00a0&#8220;creepy&#8221; and suggested I had psychological issues, and continued to attempt to discredit me and my character. My only attempts to engage her, as I said, were to contact her editor and fire back with a few comments of my own about her journalism. I&#8217;ve never been one to mince words. While I admit my comments, in the heat of her slander, were mildly sarcastic, they were certainly not abusive or personal in any way &#8211; as her own comments had been toward me. Nothing I ever said or did would have ever constituted harassment. If you write a smear piece about someone, you should expect to get at least a little bit of feedback from those you harmed. Journalism comes with a degree\u00a0of accountability, which is why I had approached her editor to file a complaint.<\/p>\n<h1>The Editor\u00a0Responds<\/h1>\n<p>ZDNet&#8217;s senior editor (David Grober) eventually responded back amidst the mess that Ms. Blue had created and insisted that her piece was a &#8220;commentary on the relationship between your presentation and media reports\/interpretations of your work&#8221;\u00a0and that her article should have been labeled as &#8220;opinion&#8221;. Mr. Grober also acknowledged that Ms. Blue should have reached out to me for comment, as a courtesy. In spite of this, Mr. Grober made no attempt to retract or correct the article, or any of the 30 falsehoods I had pointed out &#8211; in spite of my request for him to do so. I had even provided Mr. Grober my personal cellphone number in hopes that we could walk through the article. He never called, and instead decided to ignore my\u00a0ethics complaint. Mr. Grober instead asked me to provide a rebuttal, however it appeared to me that he was only interested in the headlines and website traffic it would generate. I declined, refusing to even acknowledge their article as an act of journalism. Of course, by this time the damage had already been done anyway, and in many cases, the article was written in a way to make any attempts at a rebuttal ineffective.<\/p>\n<h1>The Fallout<\/h1>\n<p>The damage Ms. Blue had attempted to cause &#8211; whatever her motivation &#8211; was in fabricating a story and the illusion that somehow my research had been debunked, or was even being questioned; she introduced doubt where there was none, and this could have put Apple&#8217;s response to correcting the issue at risk. Additionally, as someone who has testified as an expert in high profile criminal cases, and has consulted on cases for the federal government, military, and even internationally on matters as important as national security &#8211; my credibility is important. In fabricating the idea that my research had somehow been debunked (without any evidence to back up her claim), Ms. Blue had made a direct attack at my credibility, and could have recklessly put many cases at risk.\u00a0With such a strong and outrageous accusation, Ms. Blue provided absolutely no evidence from anyone in the community of anyone questioning the validity of these security issues.<\/p>\n<p>Following Ms. Blue&#8217;s article, there had been limited debate about the semantics of the term &#8220;backdoor&#8221;, and some understandably disagree that the file_relay fits the technical definition of such&#8230; however, even among those who disagree with the wording have also publicly stated that the underlying security issues should be addressed. Some of the community&#8217;s well-respected researchers posted public summaries, such as Dino Dai Zovi&#8217;s <a href=\"https:\/\/web.archive.org\/web\/20160403091522\/http:\/\/ddz.roughdraft.io\/b6879ba86fc7ddc2e26f-ios-lockdown-diagnostic-services\">TL;DR writeup<\/a> (which had originally even used the term &#8220;backdoor&#8221;, but then decided that using Apple&#8217;s term would be less controversial); Ms. Blue&#8217;s tweet history shows that she even attempted to attack Mr. Dai Zovi for &#8220;validating&#8221; my work (<em>validating<\/em> was her choice of words). Among others who found value in the research were <a href=\"https:\/\/twitter.com\/attrc\/status\/490617294444167168\">Andrew Case<\/a>, <a href=\"https:\/\/twitter.com\/p0sixninja\/status\/491986960660324352\">Josh Hill (p0sixninja)<\/a>, <a href=\"https:\/\/twitter.com\/matthew_d_green\/status\/490467850378031104\">Matthew Green<\/a>, and many others. MobileIron and Good Technologies both noted my research and published articles citing ways to protect your mobile data in light of this research. Many also jumped to my defense including <a href=\"https:\/\/twitter.com\/anthonyvance\/status\/492819874582769664\">Anthony Vance<\/a>, <a href=\"https:\/\/twitter.com\/FredericJacobs\/status\/492821495173758976\">Frederic Jacobs<\/a>, and more. In addition to this, Apple themselves have validated my research by <a href=\"http:\/\/www.zdziarski.com\/blog\/?p=3600\">already beginning to address the security issues<\/a> in their latest beta, which was released shortly after my talk had received national attention. So while there has since been a semantics debate about use of the term &#8220;backdoor&#8221; (a term the media has inaccurately attributed\u00a0to conspiracy theories), the research and the threats these vulnerabilities pose have not been undermined or discredited in any way, and quite the contrary have been deemed valid enough that Apple is addressing\u00a0them quickly and two major countries (Russia and China) are raising all of the right questions.<\/p>\n<p>I cannot speak as to Ms. Blue&#8217;s true motivation for running such a fabricated smear piece. Perhaps it is related to my religion, or to save face at ZDNet, or perhaps it is just because those types of sensationalist headlines sell. What I do know is that her piece was entirely fabricated, written in a vacuum, and is strongly disputed by the reputable journalists who took the time to discuss the technical details with me (and read the full white paper as well). Ms. Blue&#8217;s unfounded personal attacks have caused me great personal stress and upset.<\/p>\n<p>Ms. Blue has continued to take every opportunity to harass and abuse me without provocation. On several occasions since these events, I&#8217;ve seen my name appear cited in news articles by reputable sources\u00a0on Twitter, with tweets from Ms. Blue trailing in the replies, attempting to smear me all over again. In anything that I do, Ms. Blue continues to slander and harass\u00a0me. I have long since moved on from this awful experience, however my professional life is now subject to cyber stalking by\u00a0this individual, who takes every opportunity to cause damage to my reputation.<\/p>\n<p>ZDNet&#8217;s management staff eventually went through a turnover, and the new staff found Ms. Blue&#8217;s article so embarrassing that they have since disavowed themselves of it entirely with a boilerplate at the top, even to the degree of citing that Violet Blue no longer writes for them.<\/p>\n<h1>Conclusion<\/h1>\n<p>This is the end of the matter as far as I am concerned. I have not engaged with Ms. Blue since, and will not engage with her in the future, regardless of her ongoing harassment. Any attempts to taunt or bait me recently have gone and will continue to go unanswered, and I have made it clear that I think it is best for both of us to ignore each other and move on. I have at no time harassed Ms. Blue in any way, nor do I intend to; people who know me know that I&#8217;m not capable of that. If Ms. Blue wants to continue baiting me in an attempt to garner attention, that is her personal character issue to deal with. I do find her work to lack any semblance of <a href=\"https:\/\/www.pewresearch.org\/politics\/1999\/03\/30\/section-i-the-core-principles-of-journalism\/\">principles in journalism<\/a>, but in this day and age, this is hard to come by.<\/p>\n<p>Several individuals (including some from ZDNet) have recommended I pursue a libel suit against Ms. Blue, however I am not the litigious type. Needless to say, I may one day revisit that thought\u00a0should her harassment continue.<\/p>\n<p>After it was published, Ms. Blue had initially asked me to point out inconsistencies in her article. I have included 31 fabrications or falsehoods below, which I had previously placed on pastebin for her review, and sent to her editor as well. Many of her statements are outrightly libelous and actionable.<\/p>\n<h1>List of ZDNet Fabrications<\/h1>\n<p>The following is an overview of the\u00a0fabrications in the ZDNet article &#8220;The Apple Backdoor That Wasn&#8217;t&#8221;; I&#8217;m including for review the referenced write-up I&#8217;d done previously, as my blog is a more permanent home than pastebin. Please note I&#8217;ve made some minor edits.<\/p>\n<p>Source: http:\/\/www.zdnet.com\/the-apple-backdoor-that-wasnt-7000031781\/<\/p>\n<p><em>Before the iPhone came out, and long before anyone heard the name &#8220;Ed Snowden,&#8221; the most common use of the word &#8220;backdoor&#8221; was relegated to an industry that applied the term as a colorful anatomical descriptive, helping potential customers select the preferred access point for their adult entertainment.<\/em><\/p>\n<p>FALSEHOOD 1. In fact, Ms. Blue\u00a0proves herself wrong later on in the article when she links to OWASP&#8217;s paper (https:\/\/www.owasp.org\/images\/a\/ae\/OWASP_10_Most_Common_Backdoors.pdf) which outlines definitions longly held in technology for decades\u00a0that a backdoor is defined as 1. &#8220;a hidden entrance to a computer system that can be used to bypass security policies&#8221;, 2. &#8220;an undocumented way to get access to a computer system or the data it contains&#8221;, or 3. &#8220;a way of getting into a guarded system without using the required password&#8221;. The use of the term\u00a0&#8220;backdoor&#8221; in the public eye can be traced as early as 1983 in the motion picture &#8220;Wargames&#8221;. For Ms. Blue\u00a0to equate a\u201d backdoor&#8221; as having a pre-Snowden meaning solely relevant the porn industry is not only categorically false, but intentionally misleading as an overt attempt to discredit anyone who uses the term \u201cbackdoor\u201d in a technological way as a conspiracy theorist. She does just this further into her article.<\/p>\n<p><em>Last weekend, a hacker who&#8217;s been campaigning to make a point about Apple security by playing fast and loose with the now widely-accepted definition of &#8220;backdoor&#8221; struck gold when journalists didn&#8217;t do their homework and erroneously reported a diagnostic mechanism as a nefarious, malfeasant, secret opening to their private data.<\/em><\/p>\n<p>FALSEHOOD 2 There has been no campaign to make any point about Apple security, and Ms. Blue offers no evidence to back up that claim. There has, however, been an accepted, peer-reviewed journal paper, in a reputable forensics journal reviewed by members of the forensics community. Ms. Blue\u00a0has falsely attempted to re-label an accepted academic journal paper as &#8220;campaign&#8221; to smear Apple, and has provided no proof whatsoever that I\u00a0have attempted to do so. A look at my former\u00a0blog posts and Twitter stream, quite the contrary, show many attempts to prevent embarrassment of Apple or accusations of conspiracy. All of these facts are ignored as the false opinion is expressed that I wanted to embarrass Apple.<\/p>\n<p>FALSEHOOD 3 Accusing me\u00a0of &#8220;playing fast and loose&#8221;; Ms. Blue\u00a0here is using loaded language to attempt to discredit me\u00a0(the author of this peer-reviewed academic paper and all relevant research). She refers to as a &#8220;campaign&#8221;, without any facts or statements of proof as to my\u00a0motivation or prolonged \u201ccampaigning\u201d, and is already, by the second sentence, attempting to discredit me\u00a0with accusatory and derogatory terminology.<\/p>\n<p>FALSEHOOD 4 \u201cstruck gold\u201d. Here, Ms. Blue\u00a0is falsely suggesting, without any proof provided, that I\u00a0consider it some type of reward or positive outcome that journalists have misrepresented my\u00a0research, which helps her set the stage\u00a0to judge my personal character\u00a0by suggesting within the second sentence that my\u00a0intent was apparently to have journalists misled \/ misreport the research. Again, without presenting any proof; proof to the contrary is all over my website and Twitter feed.<\/p>\n<p>FALSEHOOD 5. \u201csecret opening\u201d. Ms. Blue\u00a0makes the false statement that I\u00a0attempted to mislead journalists to believe that these services were intentionally conspired as secret, however she cannot and does not attempt to back this accusation up with any facts or proof to show that I\u00a0had conspired to do this. In fact, my conference talk, blog entries, Twitter feed, and conversations with reporters all demonstrate attempts to rule out the idea of conspiracy.<\/p>\n<p><em>Speaking at the Hackers On Planet Earth conference in New York, Jonathan Zdziarski said that Apple\u2019s iOS contains intentionally created access that could be used by governments to spy on iPhone and iPad users to access a user&#8217;s address book, photos, voicemail and any accounts configured on the device.<\/em><\/p>\n<p>FALSEHOOD 6. I\u00a0did specifically say that the services were intentionally placed by Apple (and even maintained), however the article\u00a0is accusing me\u00a0of suggesting that Apple&#8217;s intent in creating them was so that they could be used by governments to spy, and that is very different from what I said. I said the code was clearly maintained by Apple, and created by Apple.\u00a0I\u00a0never made accusations of conspiracy. Ms. Blue\u00a0offered no proof to substantiate her accusation, and in fact I&#8217;ve gone\u00a0on record numerous times denying\u00a0that sensationalist point of view.<\/p>\n<p><em>As he has been doing since the Snowden documents started making headlines last year, Mr. Zdziarski re-cast Apple&#8217;s developer diagnostics kit in a new narrative, turning a tool that could probably gain from better user security implementation into a sinister &#8220;backdoor.&#8221;<\/em><\/p>\n<p>FALSEHOOD 7. Ms. Blue\u00a0has accused me\u00a0of &#8220;re-casting&#8221; Apple&#8217;s developer diagnostics, however the file_relay service &#8211; the focal point of the talk &#8211; had\u00a0never previously been disclosed\u00a0by Apple until after my\u00a0talk; therefore, how could I\u00a0possibly attempt to re-cast anything? This is another attempt at discrediting my character by introducing the suggestion that my motives were somehow corrupt.<\/p>\n<p>FALSEHOOD 8. Ms. Blue\u00a0accused me\u00a0of &#8220;doing [this] since the Snowden documents started making headlines&#8221;, however offers no proof of this; in fact, my\u00a0first contribution occurred only months prior to the talk, with the acceptance of an academic paper outlining this research.<\/p>\n<p>FALSEHOOD 9. Ms. Blue\u00a0refers to a &#8220;developer diagnostics kit&#8221;. There is no such thing. In fact, of all three services outlined in the talk, only pcapd is even disclosed to developers or its use documented (which I\u00a0do not dispute). Ms. Blue\u00a0has offered no proof that this &#8220;developer diagnostics kit&#8221; even exists; the other two services: file_relay and house_arrest, are used exclusively and internally by Apple, and are not intended for developers. Apple has since clamped down on access to house_arrest (and pcapd) following my talk.<\/p>\n<p>FALSEHOD 10. Ms. Blue\u00a0accuses me of implying a &#8220;sinister backdoor&#8221;; quite the contrary, I\u00a0have always\u00a0maintained that the technical definition of a backdoor has absolutely nothing to do with conspiracy or intent; but rather an undisclosed technological bypass. I\u00a0also used very careful wording in both the paper and the talk to be sure to diffuse any attempts to draw a conspiracy theory of any kind out of the research. Ms. Blue\u00a0offered no quotes or other proof whatsoever that I\u00a0attempted to turn this research into a conspiracy accusation toward Apple.<\/p>\n<p><em>The &#8220;Apple installed backdoors on millions of devices&#8221; story is still making headlines, despite the fact that respected security researchers started debunking researcher Jonathan Zdziarski&#8217;s claims the minute people started tweeting about his HopeX talk on Sunday.<\/em><\/p>\n<p>FALSEHOOD 11. &#8220;debunking&#8221; No security researcher has debunked the technological points of this\u00a0research; in fact, many have confirmed the vulnerabilities and weaknesses, including author and well respected reseracher Dino Dai Zovi, who wrote a TL;DR on the subject. MobileIron, a well respected security company, even published a &#8220;how to protect yourself from backdoors&#8221; article as a followup. Good Technology, well respected for enterprise security solutions in the industry, also wrote an article, citing it in a Tweet titled, &#8220;Apple has a backdoor problem. Here&#8217;s how to protect your mobile data&#8221;. TripWire recently published an article, &#8220;Why You Should Care About The Apple Backdoor&#8221;. Apple, themselves, have validated the research by beginning to restrict access to these interfaces wirelessly. A number of other researchers, CEOs, and other technology-savvy members of the community have stepped up publicly to support my\u00a0research with articles, blog postings, and tweets. The only point that has been argued, actually, has been an argument about semantics and whether the technical definition of &#8220;backdoor&#8221; should apply to the file_relay service outlined in the research. Ms. Blue\u00a0has taken a discussion about semantics (which did not begin until after her article was published) and somehow used it to attempt to convince her readers that the\u00a0research has been debunked, falsely, and without any proof. This is very clearly an attempt to establish some form of\u00a0a scientific judgment by means of journalism, rather than science. This kind of public dismissal, even without proof, can be damaging to the reputation of a researcher, no matter how unfounded, and Ms. Blue\u00a0should know this given her background.<\/p>\n<p>FALSEHOOD 12. &#8220;the minute people started tweeting about it&#8221;. Ms. Blue\u00a0has attempted to falsely, and without any evidence, make this\u00a0research appear as already debunked, when in reality there has been absolutely no such thing whatsoever. The technological points made in the research still stand, are acknowledged by many security researchers, and their existence even caused Apple to disclose what they claim was their original intent in a knowledge base article. Incidentally, the validity of research is not determined via &#8220;Twitter&#8221; as Ms. Blue claims. It is determined during the peer review process, which took place prior to my paper being published in a reputable journal. And it is determined by followup papers to either reaffirm or dispute the research. Not on social networking websites.<\/p>\n<p><em>Since Mr. Zdziarski presented &#8220;Identifying back doors, attack points, and surveillance mechanisms in iOS devices&#8221;, his miscasting of Apple&#8217;s developer diagnostics as a &#8220;backdoor&#8221; was defeated on Twitter, debunked and saw SourceClear calling Zdziarski an attention seeker in Computerworld, and Apple issued a statement saying that no, this is false.<\/em><\/p>\n<p>FALSEHOOD 13. \u201cmiscasting\u201ds. Again, the article\u00a0attempts to make me\u00a0appear to intentionally be miscasting a &#8220;developer diagnostic kit&#8221; &#8211; that does not exist &#8211; as a sinister conspiracy theory, without any proof or statements to back up her claims whatsoever.<\/p>\n<p>FALSEHOOD 14. defeated on Twitter. Without a single quote cited from Twitter, Ms. Blue\u00a0attempts to make the argument that the collective of Twitter has rejected the notion of &#8220;backdoor&#8221;, when in fact the security community is quite torn in half about whether or not the file_relay technologically meets the criteria of being a backdoor. Twitter has, however, shown a significant amount of public support for fixing these issues, as well as criticizing Ms. Blue&#8217;s article for its inaccurate reporting.<\/p>\n<p><em>In fact, this allegedly &#8220;secret backdoor&#8221; was added to diagnostic information that has been as freely available as a page out of a phone book since 2002.<\/em><\/p>\n<p>FALSEHOOD 15 \u201csecret backdoor\u201d; again, Ms. Blue\u00a0attempts to paint a conspiracy theory without any proof that I\u00a0attempted to infer that Apple had conspired to allow government to spy on its devices. I\u00a0have been noted on record &#8211; repeatedly &#8211; as denying this conspiracy likely exists, and has warned journalists in writing, through my\u00a0blog, not to sensationalize on a conspiracy notion.<\/p>\n<p>FALSEHOOD 16 \u201cdiagnostic information&#8230; 2002\u201d. Here, Ms. Blue\u00a0outlined old documentation describing pcapd, and has completely missed the point that I\u00a0was referring to a completely different service\u00a0when describing the undisclosed file_relay service. Ms. Blue\u00a0appears to be working very hard here to attempt to discredit me\u00a0by ignoring the actual service that was central to the\u00a0talk and research. I am\u00a0well aware, and have acknowledged publicly, that pcapd has been around for a very long time, however pcapd is not the service I\u00a0was referring to as a backdoor around backup encryption. Ms. Blue\u00a0has completely missed the point of this portion of the research.<\/p>\n<p><em>The packet capture software used for diagnostics referenced by Mr. Zdziarski in support of his claims is similar in functionality as the one that&#8217;s installed on every Apple laptop and desktop computer for diagnostics. So his numbers of &#8220;backdoors&#8221; allegedly installed by Apple for wide-ranging nefarious purposes are off by like, a billion.<\/em><\/p>\n<p>FALSEHOOD 17. Regurgitation of the last sentence; here again attempts to pass off the &#8220;packet capture&#8221; as the service I\u00a0was alleging to be associated with the backdoor; she clearly here is either completely lying or has made a grave error in completely misunderstanding the nature of my\u00a0intent to disclose file_relay as the service appearing to be a backdoor around encryption.<\/p>\n<p><em>It appears that no one reporting Zdziarski&#8217;s claims as fact attended his talk, watched it online, and less than a handful fact-checked or consulted outside experts.<\/em><\/p>\n<p>FALSEHOOD 18. Ms. Blue\u00a0has provided no proof or examples of any claims of &#8220;fact&#8221; by anyone, nor made any attempt to determine whether anyone had attended the talk or watched it online. In fact, I\u00a0interviewed with Paul Wagensale (Tom&#8217;s Guide) who attended the talk, and ran a piece on the talk. A number of other reporters and researchers also attended the talk, many who later wrote about it. Ms. Blue\u00a0makes a completely unsubstantiated argument here, in an attempt to single me out and insult anyone who supports my research.<\/p>\n<p><em>Which is, incidentally, what I did. I saw the talk begin to gain momentum on Twitter, then quickly flushed the idea of a story when the researchers I consulted kindly told me there was no &#8220;there&#8221; there.<\/em><\/p>\n<p>FALSEHOOD 19. Violet provided no statements from researchers that she consulted to confirm her claims, and did not establish that anyone had said there was no &#8220;there&#8221;. Additionally, Ms. Blue\u00a0completely failed to attempt to contact me\u00a0to ask questions or obtain clarification on any of the points to her story.<\/p>\n<p><em>Regardless of the problems with Mr. Zdziarski&#8217;s sermon, the (incorrect) assertion that Apple installed backdoors for law enforcement access was breathlessly reported this week by The Guardian, Forbes, Times of India, The Register, Ars Technica, MacRumors, Cult of Mac, Apple Insider, InformationWeek, Read Write Web, Daily Mail and many more (including ZDNet).<\/em><\/p>\n<p>FALSEHOOD 20. \u201cSermon\u201d. Here, the article\u00a0attempts to further discredit\/embarrass\/chastise me\u00a0by referring to this research (which again began with a peer-reviewed academic paper) as a &#8220;sermon&#8221;, and has voted down my\u00a0assertions as incorrect without a shred of evidence or technical backing posted in the article.<\/p>\n<p>FALSEHOOD 21. Ms. Blue\u00a0made the false statement that every other news agency that reported on this research as anything having an opinion that did not match her own as wrong. Further, Ms. Blue\u00a0provided absolutely no specific citations of any of those articles and what was wrong with them, made non arguments, and provided no proof that any of the other articles were wrong.<\/p>\n<p><em>People were told to essentially freak out over iPhones allowing people who know the passcode and pairing information to use the device.<\/em><\/p>\n<p>FALSEHOOD 22 Without providing ANY proof here, she\u00a0has wrongly accused me\u00a0of leading all journalists to &#8220;freak out&#8221; over my\u00a0research. In fact, I\u00a0had provided via a number of quoted tweets from journalists I\u00a0spoke with, that every single one of them had been given a level-headed &#8220;don&#8217;t panic&#8221; talk from myself. What&#8217;s more, the\u00a0original blog post began\u00a0with the words &#8220;DONT PANIC&#8221; right underneath the link to the slides, followed by a stern warning to journalists not to &#8220;freak out&#8221; about it, and further attempted to clarify why they shouldn&#8217;t. I had\u00a0since offered Ms. Blue\u00a0$100 (via Twitter) to find one single journalist who would publicly say that I\u00a0attempted to mislead them\u00a0into panicking, and She\u00a0has not come forward to collect the bounty.<\/p>\n<p><em>If you&#8217;re the kind of person that walks into a public library, plugs in your iPhone and gives the public computer and every rando who accesses it permission to access everything on your phone forever, then okay, maybe you should freak out.<\/em><\/p>\n<p>FALSEHOOD 23. Here, Ms. Blue\u00a0attempts to patronize me\u00a0further while simultaneously showing that she has no technical grasp of the threat models outlined in my\u00a0research, which did not\u00a0involve any type of scenario where the general public would be threatened in any way.<\/p>\n<p><em>&#8216;I meant a different kind of backdoor&#8217; The researcher erroneously stated that Apple &#8220;confirmed&#8221; his allegations when in fact the company had done the opposite.<\/em><\/p>\n<p>FALSEHOOD 24. Here, she\u00a0attempts to accuse me\u00a0of backpedaling, or changing my\u00a0story with regards to my\u00a0allegations of a potential backdoor, again without showing any proof whatsoever. I\u00a0have been consistent in my definition of a backdoor since giving the talk, and in fact has attempted to clarify my definition of a backdoor as &#8220;technological&#8221; and not based on &#8220;conspiracy&#8221;. Those who attended the talk heard the phrase &#8220;undocumented services&#8221; rather than backdoor, and when backdoor was used one time, it was only used to explain that I\u00a0could find no other word that fit the technological definition he was referring to. I have since joked that we could call it a &#8220;chicken wing&#8221; or a &#8220;UFO&#8221; but that it doesn&#8217;t change the security threats outlined in the research.<\/p>\n<p><em>In light of much debunking in security communities and Apple&#8217;s statement, Zdziarski published a blog post backpedaling on the interpretation of &#8220;backdoor&#8221; &#8212; yet still affirmed his narrative.<\/em><\/p>\n<p>FALSEHOOD 25. Here, Ms. Blue\u00a0attempts to continue dismissing my\u00a0research as &#8220;debunked&#8221; when, in fact, the security community by and large has accepted the research&#8217;s technical findings of weaknesses in Apple&#8217;s security, and additionally so has Apple as evidenced by their latest work to address them. Ms. Blue\u00a0shows no proof whatsoever that any of the research has been debunked, except by her own personal opinion, which has essentially amounted to lying about it. This in an attempt to assume that the scientific community has reached any such conclusion &#8211; or at least to suggest that there is debate, when in fact there has been no debate about the\u00a0validity of the security issues.<\/p>\n<p>FALSEHOOD 26. Backpedaling. Here, Ms. Blue\u00a0continues to accuse me\u00a0of changing my\u00a0position with regards to backdoor, when in fact Ms. Blue\u00a0herself does not appear to have a firm grasp on\u00a0the definitions I have always used, as she did not attend my\u00a0talk nor did she ever attempt to contact me\u00a0with questions for the story.<\/p>\n<p><em>According to OWASP, a &#8220;backdoor&#8221; is defined as: A hidden entrance to a computer system that can be used to bypass security policies (MS definition). An undocumented way to get access to a computer system or the data it contains. A way of getting into a guarded system without using the required password.<\/em><\/p>\n<p>FALSEHOOD 27. Here, she\u00a0contradicts the very first sentence of her own story by establishing that the terminology of &#8220;backdoor&#8221; in fact did have significant technical merit in a pre-Snowden era.<\/p>\n<p><em>When Apple explained the diagnostics toolset and published a detailed support document, Zdziarski said that Apple&#8217;s acknowledgement of its not-secret developer tools only proved him right, and that this meant Apple was admitting to his claims of making iOS vulnerable to authorities&#8217; snooping by design.<\/em><\/p>\n<p>FALSEHOOD 28. Here, she\u00a0refers to the tools as &#8220;not-secret&#8221;, however the file_relay service (the service in question) had never been previously disclosed until this document by Apple, after my\u00a0talk. Additionally, house_arrest had never been properly documented, and it had never been disclosed that pcapd was capable of running on all non-development iOS devices. Ms. Blue\u00a0attempts to, without any proof, falsely establish that all three of these services have been well documented by Apple in the past, which is not the case.<\/p>\n<p><em>Zdziarski says he &#8220;doesn&#8217;t believe for a minute that these services are intended solely for diagnostics.&#8221;<\/em><\/p>\n<p>FALSEHOOD 29. An out-of-context quote; placed in context, this was dismissing my\u00a0believed downplaying of these services as being &#8220;solely&#8221; for diagnostics; the pure personal nature of the data they relay makes them unsuitable for diagnostics only, based on the slides from my\u00a0talk which had already debunked that general notion prior to Apple&#8217;s response, for a number of reasons.<\/p>\n<p><em>And with one word &#8212; &#8220;believe&#8221; &#8212; we have the nut of what&#8217;s becoming a big problem in the state of security and journalism for everyone.<\/em><\/p>\n<p>FALSEHOOD 30. Here, Ms. Blue\u00a0is taking an out of context quote and trying to become abusive with it, and insult both the security industry and journalism, when in reality it is Ms. Blue\u00a0who has not provided a single shred of proof to back up any of her outrageous claims against me\u00a0or my\u00a0character.<\/p>\n<p>FALSEHOOD 31. This quote is actually a misquote; the word &#8220;believe&#8221; was never actually uttered by me. Ms. Blue invented it herself to attempt to make a more sensationalist end to her story. The original quote follows:<\/p>\n<p>&#8220;I don\u2019t buy for a minute that these services are intended solely for diagnostics. The data they leak is of an extreme personal nature. There is no notification to the user. A real diagnostic tool would have been engineered to respect the user, prompt them like applications do for access to data, and respect backup encryption.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A few days after I gave a talk at the HOPE\/X conference titled, &#8220;Identifying Backdoors, Attack Points, and Surveillance Mechanisms in iOS Devices&#8221;, ZDNet published what their senior editor has described privately to me as an opinion piece, however passed it off as a factual article in an attempt to make headlines at my expense. Now that things have had time to settle down, I&#8217;ve taken the time to calmly write up a post-mortem describing what actually happened as well as some behind-the-scenes details that may shed some light on the drama we&#8217;ve seen from ZDNet and one of its writers over the past couple of weeks. Let me say first that this is the last time I will address this matter, and have no desire to continue to discuss it, or engage with ZDNet or their writer. In fact, I haven&#8217;t engaged with either parties since this all transpired a week or so after my talk, in spite of repeated attempts to bait me with more personal attacks and false claims of harassment.<\/p>\n<p>At HOPE\/X, I gave a very carefully-worded talk describing a number of &#8220;high value forensic services&#8221; that had not been disclosed by Apple to the consumer (some not even to developers),\u00a0such as the com.apple.mobile.file_relay service, which I admitted to the audience as having &#8220;no better word for&#8221; to describe than as a &#8220;backdoor&#8221; to bypass the consumer&#8217;s backup encryption on iOS devices; this doesn&#8217;t necessarily mean a nefarious backdoor, but can simply be an engineering backdoor, like how supervisor passwords or other mechanisms work &#8211; a simple bypass to make things convenient. A number of news agencies reached out to me, and I took time to explain to each journalist that this was nothing to panic about, as\u00a0the threat models were very limited (specifically geared towards law enforcement forensics and potentially foreign espionage). Also, that I did not believe there was any conspiracy here by Apple. Reporters from ARS Technica, Reuters, The Register, Tom&#8217;s Guide, InfoSec Institute, and a number of others spoke to me and got all the time they wanted.\u00a0You can see that these journalists each\u00a0published relatively balanced and non-alarmist stories; even The Register, who prides themselves on outlandish headlines, if you read their story, was actually quite level headed about the matter. A number of other news agencies, who <em>had not<\/em> reached out to me, published sensationalist stories with crazy\u00a0claims of an NSA conspiracy, secret backdoors, and other ridiculous nonsense. I\u00a0tried very hard to throw cold water on those ideas both in my talk and in big letters on my first blog entry,\u00a0with&#8221;DON&#8217;T PANIC&#8221; and\u00a0instructions for journalists.<\/p>\n<p>ZDNet was among the news agencies that had initially published a sensationalist story without approaching me first for questions.<\/p>\n<p><a class=\"read-more\" href=\"https:\/\/www.zdziarski.com\/blog\/?p=3609\" title=\"Read More\"> <span class=\"button \">Read More<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,8,14],"tags":[],"class_list":["post-3609","post","type-post","status-publish","format-standard","hentry","category-apple","category-forensics","category-security"],"_links":{"self":[{"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3609","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3609"}],"version-history":[{"count":0,"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3609\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3609"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3609"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3609"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}