The iOS bug that made deleted photos reappear
synacktiv.com
synacktiv.com
The connection details say summary over 4 days, last denied May 19. This would put the first connection on May 15 or 14, soon after 13.6.7 and iOS 17.5 were released on May 13.
In fact, I believe iOS uses hardlinks for this, as it is possible to save a 40GB video on a device with 64GB storage instantly - while logged out of iCloud and without an Internet connection.
Since hardlinks are used, there is likely no way to tell the original and copy apart except by their paths. The photo-rescuing algorithm that shipped in 17.5 probably wandered around the filesystem farther than intended, possibly via mds.
So Apple is probably not stealing your photos. If it is, this bug is not evidence of it.
How is this an indication of hardlinks being used?
Hardlinks are the most straightforward way of accomplishing this. It could be something more complex like APFS container trickery or masqueraded softlinks or some such, but they may lead to the same bug anyways.
It makes sense to do hardlink since that doesn't duplicate storage, but deletion in Photos or Files leaves the other alone. I'm not sure if sharing to other places also makes a hardlink copy, but that would make sense.
https://eclecticlight.co/2020/04/14/copy-move-and-clone-file...
Apple needs to explain that bug that resurfaced deleted photos - https://news.ycombinator.com/item?id=40433384 - May 2024 (60 comments)
Apple's photo bug exposes the myth of 'deleted' - https://news.ycombinator.com/item?id=40422136 - May 2024 (50 comments)
Apple Releases iOS 17.5.1 with Fix for Reappearing Photos Bug - https://news.ycombinator.com/item?id=40417703 - May 2024 (3 comments)
iOS 17.5 Bug May Also Resurface Deleted Photos on Wiped, Sold Devices - https://news.ycombinator.com/item?id=40393913 - May 2024 (31 comments)
iOS 17.5 is allegedly resurfacing pictures that were deleted years ago - https://news.ycombinator.com/item?id=40372867 - May 2024 (23 comments)
iPhone owners say the latest iOS update is resurfacing deleted nudes - https://news.ycombinator.com/item?id=40370078 - May 2024 (47 comments)
Fyi, if you want to tell apple to not store the decryption keys for your iCloud Photos, you can go into iCloud settings and enable Advanced Data Protection.
You have to click through a number of warnings and set up recovery keys. We of course can’t prove that Apple isn’t still storing the keys, but imo they probably don’t even want to as it’s not their business model.
That's all there is to it.
Apple, like all the other cloud companies does not delete anything.
Secondly, there’s the iOS changelog that mentions corrupted files re-appearing.
Finally, if you have iCloud Photos turned off (as many do), nothing is getting saved to the cloud, and there’s no benefit to Apple keeping it on device.
You’re suggesting that no picture in the photos app is ever truly deleted, and implying that Apple uses this for some nefarious purpose. But there’s no evidence for that.
It has been the case for decades that when you delete files those files aren't necessarily gone, but they are out of view from the average prying eye.
And looking at what is said in this article and in other articles regarding this issue on the net it seems not even these people understand it.
If Apple implements a function to delete a photo and the implementation of that delete button has a bug that doesn't infact delete the copy of the photo. Then that's different to the technical way in which files generally are removed from file systems.
- According to reports we have photos resurfacing that are 10 years old [1]
- The oldest phone supported by iOS 17 is an iPhone 11 [2], hat was released in 2019. 2024-2019 = 5.
Explain how we see 10 year old photos resurfacing when the oldest phone supported is an iPhone 11 from 2019 and it is safe to assume that the photo resurfaced on a phone it was not taken on because the user MUST have switched phones in between as 10 year old models are not supported by iOS17.
How does that add up?
The explanation given to us is that the phone stores the images in two different locations [3]. Of course, on phones were storage space is scarce we store the same image twice. Makes perfect sense. And then they introduced deduplication in the filesystem to make up for the lost space or what?
Even if we assume that the photo is just added to the Photo.App database so that it is displayed there, then that doesn't explain why a deleted image from the Photo.app that still existed on the filesystem has not been readded to the Photo.app after a system update like we see now. So there has to be some mechanism that filters those files out, which means that it's done on purpose.
Another question is how did those files move between phones as we can assume users switched phones in between because of the supported devices of iOS17. Have they been part of the backup/restore process? If so, why? And why has nobody noticed that the backups became bigger and bigger?
Are we probably talking about a hand full of photos here? How come some got deleted and others didn't? What kind of a bug is that? And why do people also see voice messages reappear that have been deleted ages ago? [4]
I wonder what else will reappear and how Apple explains how all these files were moved between phones without bloating the backup and/or being stored somewhere in the cloud and not using space on the local storage.
There are many more questions I have on this, but it's interesting to see that even security researchers just come up with a quick answer and don't question the overall situation.
[1] - https://www.macrumors.com/2024/05/15/ios-17-5-bug-deleted-ph...
[2] - https://support.apple.com/de-de/guide/iphone/iphe3fa5df43/io...
[3] - https://old.reddit.com/r/ios/comments/1cwgljj/regarding_the_...
[4] - https://www.imore.com/iphone/apple-might-be-dealing-with-ano...
Imagine it like a delete just always moves your files to the trash/recycle bin, but instead of the user having to manually empty the trash, it just gets reclaimed when necessary. That’s how you can do “shake to undo” that will undo deleting a file. Eventually your undo history/the “recently deleted” timer expires and for all practical intents the files are “deleted”, but they’re still there just like in most modern file systems they’re also still there (just unlinked) unless you explicitly overwrite them. Even then with modern tech like wear leveled SSDs they might still be around at some lower level.
So if the whole user space is copied in backups, that would include these deleted files. The growing backup size wouldn’t be a concern because the growth is in “reclaimable” space and it also allows having multiple backups going back in time while being able to de-dupe / hardlink common files between backups (a la Time Machine).
Additionally if you’ve upgraded phones via the migration assistant, not only would the files have come with if the whole user space is copied (again so that backup / undelete history could be preserved) but unless you start filling up the new phone with even more data than you had before your now larger phone has more capacity to be written to before the deleted files need to be reclaimed. So a file you deleted 10 years ago might still be there because going from 4GB disk space to 128GB means you’ve never needed to overwrite that original 4GB disk space.
Now you introduce a bug that either scans the trash or doesn’t check that deleted flag properly and suddenly all these old files are re-appearing, photos are just the most visible ones but voice mails (which are just audio files on your phone) and notes would be affected just as much depending on what the scanner was scanning for.
If this article is one the right trail, it looks like scanning photos/media for subject tagging/recognition. Not sure why that would also resurface voicemails, but maybe a different similar change was made in that code path too.
Unfortunately even with it being all benign this is the sort of user facing bug that shatters confidence. Maybe only the system processes can scan the deleted / trash area of the disk, but the fact that it can as part of routine behavior as opposed to an explicit action (like a “Recover data” button/request) means users will question whether other apps can trigger a similar bug. If the sandboxing model holds, even if they could trigger such a bug it would only resurface their own data, but even that’s going to reasonably make people uncomfortable.
We’ve largely come to terms with “data recovery is possible because your filesystem doesn’t delete things just unlink them”, but likewise your file system doesn’t try to relink/ scan for unlinked files as part of any regular interaction. Having a user space version of the same behavior isn’t inherently bad, but having those soft deletes resurface-able as part of routine OS behavior is not great to say the least
So that's clearly not something that has happened here.
Also when I assume that's what's going on, then the phone would make a low level block by block backup of the raw storage device. You really trying to tell me that's what's going on here? And on top of that, that easy recovery of unlinked files, randomly scattered across hundreds or thousands of blocks in the filesystem can just easily be "relinked" and just reappear out of thin air?
You got to have zero idea about how all of this works or are one of those corporate shills but this is just the biggest nonsense there is.
I did not say that the files were unlinked at the filesystem level and somehow recovered as is. I said that they likely were doing a similar user space soft delete where the files themselves were note actually deleted. In fact, my second sentence is:
> Instead they are marked as deleted and just left un-displayed / un-indexed until they’re finally overwritten by some need to use that space.
I referenced both the unlinking that a program like `rm` would do, and the wear leveling tech in SSDs both as examples of how we already have similar concepts of soft deletes at other layers of the stack. My suggestion was that Apple has added an additional layer on top of this, which does soft deletes at the file presentation layer. That explains both how the files could move with backups (and without "block by block backup") and how they can just be "relinked and just appear out of thin air".
I'm sorry if I wasn't clear enough in distinguishing what I was suggesting Apple was doing, and the analogies I was using as a comparison point. Perhaps in the future, you could assume good intent and ask for clarification if I haven't been clear enough for you, rather than accusing me of being stupid or a shill.
* User saves an image to the Files app (aka filesystem)
* User imports image from Files to Photos
* User deletes image from Photos
* On the iOS update in question there was a migration to add images from the Files app to the Photos app
* People think photos were undeleted when they had been in the files app all along
I think we could spend a lot of time trying to determine if an imported picture that’s deleted should delete its source. Personally I think an import is a copy (not a move), and the source is left alone but I’m sure other people (people who don’t understand computers very well or those who do expect it to be a move operation) might disagree.
Are you sure manually importing from files to gallery is a behaviour that exists? I definetly may be misremembering iOS behaviour!
This is patently false. Ive literally, personally, implemented safeties and mechanisms to responsibly remove customer content multiple times.
Ive worked for both Apple and AWS and both companies take customer content and privacy very seriously. So much that it actually impedes support and business operations.
Yeah, Facebook does that to some extent, with content that is heavily compressed in the first place, but it’s also likely they clean out information like that once they have the metadata that is valuable for advertisers or once the information becomes stale. Data that has no commercial value is actively costing the company money.
Facebook is pretty upfront about this. They delete some of it…”some” presumably being the data that is worthless to them: https://www.facebook.com/help/356107851084108
With cloud storage providers that charge by the gigabyte and store originals that have not been compressed further, every gigabyte of data that is being allocated and not paid for is unwanted COGS.
Cloud companies would be bankrupt by now if your theory was the case.
This bug shows that when you delete a file on iOS, it does not immediately get removed from YOUR filesystem. The 'important questions' you raise are predicated on a misunderstanding.
In particular: 'why is Apple retaining these photos?' - Apple isn't (or at least, this bug does not show that they are). Apple reimported photos that were still present on your filesystem after you had deleted them.
The question of why they're still present on the filesystem is a good and fair question. Some folks are suggesting it could be to do with these actually being copies of the originals (which is perfectly possible—as far as I can tell, copies are created when you share and when you edit) which Photos lost track of, or some engineer forgot to consider when deleting. Or it may be a performance optimisation to simply dereference the file so that the user has a silky smooth experience, and allow a background job to eventually clear up the file system, and potentially that background job crashes from time to time, whatever.
Your questions on data privacy are not founded in fact here. There are some legitimate questions that users should be asking Apple here (why does Photos tell me it's deleted a file when it's still on my device is a pretty big one).