Apple Says it Syncs Call Logs on iCloud As a 'Convenience to Customers' Amid Security Concerns

Earlier today, reports surfaced on The Intercept and Forbes claiming Apple "secretly" syncs Phone and FaceTime call history logs on iCloud, complete with phone numbers, dates and times, and duration. The info comes from Russian software firm Elcomsoft, which said the call history logs are stored for up to four months.

phone-icloud
Likewise, on iOS 10, Elcomsoft said incoming missed calls that are made through third-party VoIP apps using Apple's CallKit framework, such as Skype, WhatsApp, and Viber, also get synced to iCloud. The call logs have been collected since at least iOS 8.2, released in March 2015, so long as a user has iCloud enabled.

Elcomsoft said the call logs are automatically synced, even if backups are turned off, with no way to opt out beyond disabling iCloud entirely.

“You can only disable uploading/syncing notes, contacts, calendars and web history, but the calls are always there,” said Vladimir Katalov, CEO of Elcomsoft. "One way call logs will disappear from the cloud, is if a user deletes a particular call record from the log on their device; then it will also get deleted from their iCloud account during the next automatic synchronization.

Given that Apple possesses the encryption keys to unlock an iCloud account for now, U.S. law enforcement agencies can obtain direct access to the logs with a court order. Worse, The Intercept claims the information could be exposed to hackers and anyone else who might be able to obtain a user's iCloud credentials.

In some cases, hackers could access an iCloud account even without account credentials, such as by using Elcomsoft's Phone Breaker software. The tool is being updated today with the ability to extract call histories from iCloud with only an authentication token for an account from the accountholder's computer.

However, the entire narrative is largely overblown. In a 63-page white paper about iOS security, Apple clearly defines which information it collects for iCloud backups, emphasis our own. Likewise, in its Legal Process Guidelines, Apple notes FaceTime call invitation logs can be stored for up to 30 days.

Here’s what iCloud backs up:

• Information about purchased music, movies, TV shows, apps, and books, but not
the purchased content itself
• Photos and videos in Camera Roll
• Contacts, calendar events, reminders, and notes
• Device settings
• App data
• PDFs and books added to iBooks but not purchased
Call history
• Home screen and app organization
• iMessage, text (SMS), and MMS messages
• Ringtones
• HomeKit data
• HealthKit data
• Visual Voicemail

Further, in a statement today, Apple said the call history syncing is intentional.

“We offer call history syncing as a convenience to our customers so that they can return calls from any of their devices,” an Apple spokesperson said in an email. "Device data is encrypted with a user’s passcode, and access to iCloud data including backups requires the user’s Apple ID and password. Apple recommends all customers select strong passwords and use two-factor authentication.”

Security researcher Jonathan Zdziarski told The Intercept he "doesn't think Apple is doing anything nefarious in syncing the call logs," which are very clearly stored for the purposes of Continuity and being able to access your call history across Apple devices, even after restoring from a backup.

Nevertheless, Zdziarski emphasized the need for Apple to be clear to users about the data being collected and stored on iCloud. As noted by The Intercept, Apple does not indicate call logs are synced even with iCloud Backup disabled, while FaceTime call logs appear to be stored longer than Apple's claim of up to 30 days.

iCloud users concerned about their accounts being compromised should set a strong password and enable two-step verification.

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Rumored to Use Same Rear Chassis as iPhone 16

Friday July 19, 2024 7:16 am PDT by
Apple will adopt the same rear chassis manufacturing process for the iPhone SE 4 that it is using for the upcoming standard iPhone 16, claims a new rumor coming out of China. According to the Weibo-based leaker "Fixed Focus Digital," the backplate manufacturing process for the iPhone SE 4 is "exactly the same" as the standard model in Apple's upcoming iPhone 16 lineup, which is expected to...
iPhone 17 Plus Feature

iPhone 17 Lineup Specs Detail Display Upgrade and New High-End Model

Monday July 22, 2024 4:33 am PDT by
Key details about the overall specifications of the iPhone 17 lineup have been shared by the leaker known as "Ice Universe," clarifying several important aspects of next year's devices. Reports in recent months have converged in agreement that Apple will discontinue the "Plus" iPhone model in 2025 while introducing an all-new iPhone 17 "Slim" model as an even more high-end option sitting...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Just Two Months Away: Everything We Know

Monday July 15, 2024 4:44 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
Apple TV Plus Feature 2 Magenta and Blue

Apple TV+ Curbs Costs After Expensive Projects Fail to Capture Viewers

Monday July 22, 2024 5:11 am PDT by
Apple is scaling back its Hollywood spending after investing over $20 billion in original programming with limited success, Bloomberg reports. This shift comes after the streaming service, which launched in 2019, struggled to capture a significant share of the market, accounting for only 0.2% of TV viewership in the U.S., compared to Netflix's 8%. Despite heavy investment, critical acclaim,...
bsod

Microsoft Blames European Commission for Major Worldwide Outage

Monday July 22, 2024 11:55 am PDT by
Last Friday, a major CrowdStrike outage impacted PCs running Microsoft Windows, causing worldwide issues affecting airlines, retailers, banks, hospitals, rail networks, and more. Computers were stuck in continuous recovery loops, rendering them unusable. The failure was caused by an update to the CrowdStrike Falcon antivirus software that auto-installed on Windows 10 PCs, but Mac and Linux...

Top Rated Comments

farewelwilliams Avatar
100 months ago
if you're that paranoid about syncing call logs, you'd disable icloud drive anyways. elcomsoft just wants the attention.
Score: 21 Votes (Like | Disagree)
Ericus Macabeus Avatar
100 months ago
This has been public knowledge for years. My call logs show up on my iPad since I think iCloud Drive launched. This couldn't be more of a non-story.
Score: 12 Votes (Like | Disagree)
samcraig Avatar
100 months ago
I'll just say it... if this was a story about Google or Android, the flamethrowers would be out
Score: 12 Votes (Like | Disagree)
Mascots Avatar
100 months ago
Oh come on - so much Apple hate lately.

People seem to just be eager to try and start the next circle jerk.
Score: 11 Votes (Like | Disagree)
Rigby Avatar
100 months ago
if you're that paranoid about syncing call logs, you'd disable icloud drive anyways. elcomsoft just wants the attention.
I disagree. You can disable the syncing of other data (such as Safari browsing history and bookmarks) selectively in the iCloud Drive settings. Why not have the same option for the call history without having to disable everything?

Also, keep in mind that, while maybe your personal calls are not very interesting, there are people whose call histories may be genuinely sensitive, such as lawyers, journalists, policital activists etc. You can't just dismiss this all as paranoia.
Score: 9 Votes (Like | Disagree)
DCINKC Avatar
100 months ago
Yawn. Click bait.
Score: 9 Votes (Like | Disagree)