OpenHat - ios-max-security GitHub

← Back to profiles

Why These Settings Matter

Adam Siwiec Founder · OpenHat Security

Commercial surveillance, Apple’s own terms, and a Fourth Amendment loophole that does not need your front door.

Abstract

These iPhone configuration profiles exist because a modern iPhone is not a sealed vault. Even apps that advertise end-to-end encryption can still leave data on Apple’s servers. Apple’s public privacy policy and iCloud terms describe collection for “personalization” and “convenience,” and they reserve the right to disclose information for national security and law enforcement. U.S. agencies can also buy commercially collected location and behavioral data from brokers — often without a warrant. That is a quieter path around the Fourth Amendment’s warrant requirement than kicking in a door. This paper quotes Apple’s own documents, cites U.S. opt-out law, and explains why the OpenHat levels exist. They do not fully secure an iPhone. Nothing can, on a closed, proprietary OS that updates on Apple’s schedule. They do cut the amount of tracking a personal device will volunteer.

1. They do not need the Fourth Amendment anymore

The Fourth Amendment protects against unreasonable searches and seizures. The classic picture is a warrant, probable cause, a judge. That picture is incomplete if the same facts can be purchased.

The ACLU has documented that DHS components have bought data they would normally need a warrant to compel.1 The Brennan Center describes “a glaring loophole in current law” that lets law enforcement and intelligence agencies pay data brokers for private information.2 NPR put it in one line: “Your data is everywhere. The government is buying it up.”3

They do not need the Fourth Amendment anymore — not if a vendor will sell location, associations, and timing. The government found a better, easier way to reach the same facts: the commercial stack that already profiles you for ads.

2. “Secure” apps still touch Apple

Telegram, Signal, Proton, and similar apps encrypt traffic between clients. That is not the same as “Apple never sees anything.”

Apple’s iCloud Terms state:

“If you sign in to certain third party apps with your iCloud credentials, you agree to allow that app to store data in your personal iCloud account and for Apple to collect, store and process such data on behalf of the relevant third-party app developer.”4

If iCloud Backup is on, backups can include app data, messages, and photos, depending on settings.5 Under Standard Data Protection, some iCloud material — including certain message-backup keys — can be produced under legal process. Advanced Data Protection encrypts more categories so Apple says it cannot produce that content.5

End-to-end encryption in the app does not mean nothing lands in iCloud, CloudKit, push infrastructure, or diagnostics. If it lands there, Apple is in the chain.

3. Personalization, convenience, and what the policy actually lists

Apple’s Privacy Policy (updated July 30, 2025) lists Usage Data as “app launches within our services, including browsing history; search history; product interaction; crash data, performance and other diagnostic data; and other usage data.” It also describes coarse location and device identifiers, including serial numbers that can make a device identifiable — to “power our services,” “improve our offerings,” and “personalize your experience.”6

That is the official story: personalization and convenience. In a market already dominated by Apple and Google, those features are sold as being solely for you. Apple also says it does not sell personal data as “sale” is defined in California and Nevada, and does not “share” it as California defines that term.6

The same policy continues:

“We may also disclose information about you if we determine that for purposes of national security, law enforcement, or other issues of public importance, disclosure is necessary or appropriate.”6

Apple publishes a U.S. Transparency Report on government requests — account data, content (photos, email, backups, contacts, calendars), and national-security counts.7 iMessage in transit is end-to-end encrypted. iCloud backups under Standard Data Protection may still make Messages in iCloud producible. With Advanced Data Protection, Apple says it cannot produce that content.5

So: not an ad-network sale, by Apple’s definition. Still a pipeline that can answer a government request. Still a behavioral picture built for “personalization.” Whether that picture is also useful to partners, or to a state that already buys broker data, is not a mystery the policy bothers to deny in full. It does not have to. You tapped Agree.

4. The 500-page door

Almost nobody reads the Apple Media Services Terms, iCloud Terms, and Privacy Policy before the first unlock. They are not written to be read. They are written to grant broad permission to collect and process data for services, security, fraud prevention, personalization, and compliance with law; to reserve national-security and law-enforcement disclosure; and to let third-party apps store data in iCloud while Apple processes it for the developer.46

That click is legal consent. It is also a wall of text designed to hide the sentence that matters. That is how this stays “legal.” You were not too lazy. The document was built so that reading it is the unreasonable act.

5. You do have opt-out rights — in some states

U.S. law already treats commercial profiling as real. In California, the CCPA as amended by the CPRA gives consumers the right to opt out of the “sale” or “sharing” of personal information, including for cross-context behavioral advertising, and requires a clear “Do Not Sell or Share My Personal Information” (or “Your Privacy Choices”) link, plus honor for Global Privacy Control.8 After an opt-out, a business generally cannot ask you to opt back in for 12 months.

The FTC has treated automated profiling and behavioral targeting as commercial surveillance that can be unfair or deceptive if hidden.9 There is still no single federal “opt out of all profiling” statute. State law is why a “no” button exists at all.

6. What these profiles actually do

OpenHat does not fix Apple, the brokers, or the warrant loophole. It does three concrete things on a phone you hold:

  1. Cut third-party tracking at the network layer: private DNS, Apple analytics and personalized ads off, tighter lock screen.
  2. Make the worst graph-building apps harder to use: Safari deny lists; delete or Screen Time block Instagram, Snapchat, TikTok, and the rest.
  3. Offer a harder posture: Lockdown Mode (Level 3, a Settings switch), optional self-hosted MDM you run (Level 4.1, no erase), or erase-and-supervise (Level 4.2). Lockdown Mode and MDM are independent. You manage those steps. OpenHat cannot see your data.

It is not possible to fully secure an iPhone or a Mac. The OS is proprietary and closed. Updates can change the ground. These levels configure as much as a user-installed profile is allowed to configure, depending on how far you want to go.

Sources

  1. ACLU, “DHS Is Circumventing the Constitution by Buying Data It Would Normally Need a Warrant to Access.”
  2. Brennan Center, “Congress Must Close the Data Broker Loophole.”
  3. NPR, reporting on government purchase of commercially collected data.
  4. Apple, iCloud Terms of Service.
  5. Apple, iCloud data security / Advanced Data Protection overview.
  6. Apple Privacy Policy (PDF). See also apple.com/legal/privacy/en-ww.
  7. Apple Privacy Policy (web).
  8. Apple Transparency Report (United States). See also overview and PDF reports.
  9. California Privacy Protection Agency, CCPA/CPRA materials.
  10. Discussion of FTC Section 5 enforcement on commercial surveillance and AI profiling.

Also: Apple privacy governance · POGO, data-broker loophole · CDT on the data-broker loophole