Skip to main content
  1. Home
  2. Phones
  3. Apple
  4. Mobile
  5. News

Apple demands DMCA takedown of secret iBoot code leaked on Github

Leak of iBoot and other sensitive code began with low-level Apple employee

Add as a preferred source on Google

A portion of Apple’s proprietary source code for iOS devices has been leaked online. The code, labeled ‘”iBoot,” is responsible for ensuring only trusted versions of iOS can boot on Apple devices.

Shortly after Apple learned of the leaked source code, the company issued a Digital Millennium Copyright Act (DMCA) takdeown request to Github, requesting its immediate removal. Apple’s DMCA request was published by Github and states that the reason for the request is because “the ‘iBoot’ source code is proprietary and it includes Apple’s copyright notice. It is not open-source.” Github complied with the request and removed it from the repository of a user named ZioShiba.

Recommended Videos

Although the leaked code appears to be for an older version of the operating system, iOS 9, it may contain relevant code still used in iOS 11. While Apple does make some portions of its code open source, iBoot has never been included and is closely guarded by the company.

The leak apparently began with a low-level Apple employee, according to a story on Motherboard.  The story claims that friends encouraged the employee to share code to help them conduct security research. Motherboard also claims that iBoot was not the only sensitive code shared by the Apple employee; the story says it was provided with screenshots of additional code that was dated around the same time.

According to Motherboard, the Apple employee originally shared the iBoot source code with a group of five friends in 2016. The friends claim to have closely guarded the code, however, the group eventually began sharing the code with a wider group of people and eventually lost track of who had access to the code.

members of the original group that had access to iBoot believe the person who shared it on Github only obtained the code after they lost track of it. They claim that the code posted by ZioShiba was a copy of the code they received.

While ZioShiba was the first to post the iBoot source code on Github, this is not the first time the code has appeared online. Last year, a Reddit user named apple_internals published the same code on Reddit, however it failed to gain the same amount of attention. The code has also been circulating around jailbreaking groups in Discord.

Apple issued a statement assuring users that the leaked code was outdated and there is no need for alarm. “Old source code from three years ago appears to have been leaked but, by design the security of our products doesn’t depend on the secrecy of our source code. There are many layers of hardware and software protections built in to our products, and we always encourage customers to update to the newest software releases to benefit from the latest protections.”

Since 2013, Apple has included a Secure Enclave chip on iPhones. It effectively creates a separate computer within the iPhone to store both encryption and decryption keys, as well as other sensitive data.  Since Secure Enclave uses a physically embedded key to authenticate, it creates a scenario where it’s nearly impossible for hackers to access sensitive information by brute force.

Updated February 9: Clarified reason Apple employee leaked code. 

Steven Winkelman
Former Staff Writer, Mobile
Steven writes about technology, social practice, and books. At Digital Trends, he focuses primarily on mobile and wearables…
Google Drive can now batch-scan your documents and spare you a few other frustrations, too
The automated scanning experience runs entirely on your device, without sending anything to Google’s servers.
Electronics, Phone, Mobile Phone

Scanning documents from a phone has always been a frustrating experience, especially on Android smartphones. You’ve to scan one page at a time, blurry captures you don't notice until after, or accidentally hovering over the same page twice; all these issues bother users on a day-to-day basis. 

Well, Google Drive's new document scanner redesign fixes all three problems at once. Announced by Sameer Samat, the President of Android Ecosystem at Google, the feature is now rolling out for Android users.

Read more
I spent a day with the Xiaomi 17T Pro, and Leica cameras made every shot tempting
Leica and Xiaomi had me pulling out this phone for "just one more" shot
Electronics, Phone, Mobile Phone

Phone camera partnership had a very rocky start. These collaborations, while bringing big names, felt vague sometimes. Simply slapping a logo on the camera module and making a few color tuning changes will have you wondering how much of it actually changes the photos you take, especially when the price of a phone takes a hike.

Such partnerships have been bringing great results in the last couple of years, and a device that really made it apparent was the Xiaomi 17T Pro.

Read more
Vertu’s new foldable phone serves alligator skin, solid gold, and a fittingly outrageous price tag
This foldable phone costs more than my car and probably my rent too
Alphafold

Luxury phone maker Vertu has unveiled its newest foldable smartphone, the Vertu Alphafold, and it may be one of the most extravagant phones released in years. Combining foldable smartphone hardware with exotic leather, gold accents, AI-powered business tools, and ultra-premium pricing, the device is clearly aimed at wealthy buyers who want exclusivity as much as specifications.

The pricing alone is enough to turn heads. The standard calfskin leather version starts at $6,880, while the alligator leather model jumps to $8,800. For buyers wanting something even more extravagant, Vertu is offering customised variants with gold detailing and diamonds that can push the price all the way to $46,800.

Read more