Automatic (machine) translation. This text was translated automatically from the Polish original and may contain inaccuracies. In case of any doubt, the Polish version is the authoritative one.
← Back to Knowledge
Knowledge

Analysing communication and data synchronisation in the Apple ecosystem

Analysing communication and data synchronisation in the Apple ecosystem

One of the key issues in digital forensics is analysing how Apple devices – the iPhone, MacBook or iPad – store and synchronise data among one another. The Apple ecosystem was designed so that all devices signed in to the same Apple ID can work coherently, using iMessage, FaceTime or Continuity. This user convenience, however, carries specific evidentiary consequences as well as potential security risks.

In practice, this means that iMessage messages and SMS sent from an iPhone are automatically visible on a Mac too, if it is signed in to the same Apple ID account. The Continuity mechanism (SMS Relay) allows a MacBook to send and receive SMS messages even though it has no SIM card of its own – it acts as a terminal, while the actual sending is carried out by the iPhone. The recipient, however, still sees the phone number assigned to the iPhone.

Similarly, applications such as WhatsApp – although the desktop version functions as a "mirror" of the phone – save their own copies of databases containing the chat history and metadata. As a result, durable traces of communication remain on the computer, which can be analysed even when the phone has been wiped.

A MacBook stores a rich set of configuration data in files and SQLite databases. One example is Accounts4.sqlite, which holds information about Apple ID account aliases, the assigned phone numbers and e-mail addresses. The chat.db database, in turn, contains the history of iMessage and SMS, together with the sender, recipient, date and content. This data is synchronised, which makes it possible to reconstruct the activity of an entire Apple ID account from a single device.

This synchronisation feature also has a flip side. If an unauthorised person gains physical access to a Mac signed in to the iPhone owner's Apple ID, they in practice gain the ability to send iMessage or SMS messages as if the phone's owner were sending them. For the recipient, the sender remains the phone number assigned to the iPhone, even though the message was sent from a MacBook.

From a digital-forensics perspective, this means that establishing the mere fact that a message was sent from an Apple ID account does not always unambiguously point to the person physically operating the device. It requires additional analysis of the context, such as system logs, geolocation data, or determining who actually had access to the given device at the given time.

The diagram below illustrates the mechanism for synchronising communication services in the Apple ecosystem.
Pic.1

Image description: The diagram shows the mechanism for synchronising communication services in the Apple ecosystem. The phone number assigned to the iPhone (SIM card) is linked to the Apple ID account. The iPhone activates the iMessage and SMS Relay service and then makes it possible to send and receive messages on other devices signed in to the same Apple ID as well – e.g. a MacBook or iPad. As a result, the user can communicate from a computer, while for the recipient the sender of the message still remains the iPhone's phone number.

This mechanism increases the convenience of using the services, but in court practice it is significant: if an unauthorised person gains access to a MacBook signed in to the owner's Apple ID, they can send messages that will appear to the recipient as if sent from the phone number assigned to the iPhone.

Evidentiary significance

In forensic examinations, then, it is extremely important not only to reconstruct the content of the communication, but also to fully understand the mechanisms of synchronisation between devices. Only correlating data from several sources – e.g. the MacBook's databases, the Apple ID configuration and activity logs – makes it possible to answer the question of whether the messages were actually sent by the owner or by a third party who had access to their equipment.

Synchronising data between Apple devices significantly eases everyday use of the services, but at the same time complicates forensic analysis. A Mac can act as an "extension" of the iPhone – sending and receiving messages on its behalf, and storing historical data. That is why, in the evidentiary process, it is necessary to consider both technical aspects (account configuration, aliases, logs) and organisational ones (third-party access to devices). Only such an approach allows for a reliable and complete assessment of the evidentiary material.

Prepared by: Waldemar Chodasiewicz Date prepared: 7 October 2024