-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathCITATION.cff
More file actions
36 lines (36 loc) · 1.34 KB
/
Copy pathCITATION.cff
File metadata and controls
36 lines (36 loc) · 1.34 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
cff-version: 1.2.0
title: "How iOS stores messages, and how to read a backup"
message: >-
If you use these notes in a paper, a report or an expert opinion, please cite
them. The CC BY 4.0 licence asks for attribution, and a citation is how that
is done in writing.
type: dataset
authors:
- family-names: Kowalski
given-names: Krzysztof
affiliation: Bokart
city: Warsaw
country: PL
abstract: >-
Notes on Apple's on-device message database and on the layout of an iPhone
backup, verified against real backups from iOS 11 to iOS 26. Covers the sms.db
schema and how to tell the iOS generation apart without a version field, Apple
absolute time, the attributedBody blob that holds the text when the text column
is NULL, the message_summary_info blob that keeps what an edited message used to
say, the SHA1 backup file naming rule, the write-ahead log beside sms.db,
attachment paths and the MediaDomain they resolve under, the SMS, MMS, RCS and
iMessage transports, encrypted backups, the RSMF container, and an honest
account of what a backup does not contain.
keywords:
- iOS
- iPhone
- sms.db
- iMessage
- SQLite
- digital forensics
- eDiscovery
- file format
- backup
license: CC-BY-4.0
repository-code: "https://github.com/ChatExport/ChatExportKnowledge"
url: "https://github.com/ChatExport/ChatExportKnowledge"