Skip to content

ios-backup-forensic

Native, read-only, panic-free reading of iOS device backups — encrypted ones included.

  • Purpose & Scope — what this is for, and what it deliberately is not.
  • Implementation census — how we compare with eleven independent implementations, and the three defects it found in ours.
  • Validation — what correctness rests on, tier by tier, and the gap that is still open.
  • Decisions — the ADRs.
  • Test data — fixture provenance.

The decisions

ADR
0001 Reader and analyzer are two crates
0002 sqlite-core reads Manifest.db
0003 Truncate to the recorded size; never strip padding
0004 A failed unwrap is a wrong password
0005 A credentials seam for mounting tools
0006 An absent domain is reported unrated
0007 The 1.88 MSRV is inherited, not ours
0008 A fileID is validated, never sanitised
0009 The effective encryption state, not the declaration