Lab report · 10 October 2026
We searched a real iPhone backup for our own messages.
We typed the same words in WhatsApp and in OUT on the same iPhone. Then we made a backup of the phone, first a plain one and then an encrypted one, and searched every byte of it. This page shows what we found, how we did it, and what this test does not prove.
- The text of every message
- Who sent it: 3 sent, 3 received
- The time, to a fraction of a second
- A second copy in WhatsApp’s search index
- One OUT file in the whole backup: a 196-byte settings file
- It says dark mode is on. Nothing about who you talk to
- No message text, no photo, no message times
The whole test in 48 seconds
What we did
- On one iPhone, we sent and received the same test phrase in a WhatsApp chat and in an OUT chat. In OUT we also sent a photo.
- We closed OUT and connected the iPhone to a Mac. In Finder we made a full local backup: plain (no password) the first time, encrypted the second time, with a new test phrase.
- For the plain backup, we listed every file each app put into it and searched all 19.4 GB for the test phrase, as UTF-8 and as UTF-16, ignoring upper and lower case.
- For the encrypted backup, the phone’s owner entered the backup password on his own Mac. A script decrypted each of the 22,351 files in memory, one at a time, and searched it the same way. Only the locations of matches were written down, never their content.
Test phrases: “OUT FORENSIC” in the plain backup, “OUT KEY TEST” in the encrypted one. Using a new phrase for the second test means no result can come from the first.
$ python out_scan.py Backup password (not shown): Password OK. Scanning every file in the backup... 2000/22351 files, 0.2 GB ... 20000/22351 files, 19.2 GB 22000/22351 files, 19.3 GB Done in 85 s. Files scanned: 22351, errors: 0. Matches: 9. OUT files: 1.
Results
| OUT | ||
|---|---|---|
| Files in the backup | about 15,960 | 1 file (plus 4 empty folders) |
| “OUT FORENSIC”, plain backup | Found: 4 messages | Not found |
| “OUT KEY TEST”, encrypted backup | Found: 6 messages | Not found |
| Photo sent in OUT | – | Not found |
| Where | ChatStorage.sqlite and the search index fts/ChatSearchV5f.sqlite | – |
| What can be rebuilt | Text, direction, exact time, the conversation it belongs to | Nothing about any conversation |
What WhatsApp left
WhatsApp, like most messengers, writes every message into a database on the phone, and that database is part of the backup. In the plain backup it could be opened directly, without any password. These are the test messages from the encrypted backup, exactly as stored once it is decrypted (times in UTC):
| Text | Direction | Time stored |
|---|---|---|
| OUT KEY TEST | sent | 05:27:24.364 |
| OUT KEY TEST | sent | 05:27:36.222 |
| OUT KEY TEST | sent | 05:27:39.071 |
| OUT KEY TEST | received | 05:29:55 |
| OUT KEY TEST | received | 05:29:58 |
| OUT KEY TEST | received | 05:30:00 |
The same words were also in WhatsApp’s search index, a second copy that exists so you can search your chats. Encrypting the backup did not change any of this: anyone with the backup password reads it all.
What OUT left
In both backups, OUT contributed exactly one file: Library/Preferences/com.outmessenger.app.plist, 196 bytes. This is its entire content:
out.chatsView galaxy out.appearance dark out.interfaceSounds true out.signedOut false out.acceptedTermsVersion 2 out.installMarker 1
No messages, no photo, no contacts, no usernames, no message times. That is by design: OUT keeps message content in memory and never writes it to a chat database, so there is nothing for a backup to copy.
What iOS records anyway
We also looked for every file in the backup that mentions OUT by name. These traces are written by iOS itself, not by OUT, and they are the same for any app:
- That OUT is installed: home screen layout, the Spotlight app list, notification settings.
- Permissions: camera and microphone allowed.
- Network use: iOS keeps a first-seen and last-seen time for each app that uses the network.
None of them contained message text, contacts or names.
Keys and the Keychain
An encrypted backup also contains the iPhone’s Keychain, where apps keep passwords and keys. This backup held 1,986 Keychain items. 561 of them are marked ThisDeviceOnly: they are locked to the hardware of that one iPhone and cannot be opened anywhere else, even with the backup password.
OUT stores its keys only in ThisDeviceOnly items. Which app owns each Keychain item cannot be seen from the backup, because that information is encrypted too.
Beyond a backup: where this test sits
Forensic examiners choose between several kinds of extraction. Each one reaches deeper into the phone than the one before. A backup is the shallowest kind, and it is the one we tested.
| Extraction | What it reaches | This test |
|---|---|---|
| Backup / logical | Live files that iOS hands over through its backup service: messages, photos and app databases. Usually not device usage, location history or system logs. | Yes, plain and encrypted |
| BFU Before First Unlock | A phone that has not been unlocked since it was switched on. Most files are still encrypted with keys derived from the passcode, so little is readable. | Not tested |
| AFU After First Unlock | A phone unlocked at least once since it was switched on. Most of the file system and the Keychain become readable, close to a full extraction. | Not tested |
| Full file system | Every live file, including system logs, usage timelines and database records marked as deleted. | Not tested |
| Physical | A bit-for-bit copy of the storage chip. Largely obsolete on modern iPhones, where every file has its own encryption key. | Not applicable |
Some of the places examiners rely on most are only reached by the deeper extractions. We checked our plain backup: none of the first three below were in it. This is what OUT puts in each of them, by design and checked in our source code before every release:
| Location on the iPhone | What it can hold | OUT |
|---|---|---|
| Usage timeline /private/var/mobile/Library/CoreDuet/Knowledge/knowledgeC.db | Which app was in use and when, screen and lock state | Recorded by iOS for every app, OUT included. Times of use, never content. |
| App intent streams (Biome) /private/var/mobile/Library/Biome/streams/restricted/App.Intent | Actions apps share with iOS, which can include parts of messages | Nothing. OUT shares no intents, activities or Spotlight items with iOS. |
| Notification history /private/var/mobile/Library/DuetExpertCenter/streams/userNotificationEvents | Notifications the phone received, which can include parts of messages | No message text and no sender name. OUT notifications carry neither. |
| Deleted database records SQLite free pages and write-ahead logs | Messages that were deleted but not yet overwritten | Nothing to recover. OUT has no message database. |
| People and sharing history /private/var/mobile/Library/CoreDuet/People/interactionC.db | Who you share with and what, from which app to which | Not in our plain backup. In the encrypted one it held a file name shared from Mail to WhatsApp, and nothing from OUT. |
| Keychain | Passwords and keys, more of them in deeper extractions | OUT’s keys live here, ThisDeviceOnly. There are no stored messages for them to unlock. |
Some apps encrypt their own databases. A deeper extraction usually includes the Keychain where those database keys are kept, so the messages can still be read. OUT does not depend on that: there is no message database to decrypt in the first place.
Extraction types and file locations follow published 2026 guidance for iOS forensic examiners. Whether each location was present is from the backups in this test.
Technical details
Backup format. A Finder backup stores every file under a SHA-1 name in 256 folders. Manifest.db, an SQLite database, maps each one back to its app domain and original path. That is how each finding below is tied to an app.
Encryption. In an encrypted backup every file has its own AES-256 key. Those keys are wrapped by data-protection class keys, kept in a keybag that only the backup password unlocks (PBKDF2). Keychain items of the ThisDeviceOnly classes are wrapped with a key bound to the iPhone’s hardware instead, so the password alone does not open them.
Search. Every file was read in full and searched, ignoring case, for the test phrase as UTF-8 and as UTF-16LE. Files were decrypted in 8 MB blocks with an overlap, so a phrase split across two blocks is still found. Only the location of a match was recorded, never the surrounding data.
Validation. We checked the results at their source rather than trusting one program’s summary: the WhatsApp rows were read directly from the database and their times decoded by hand from Apple’s clock (seconds since 1 January 2001, UTC). The test was run twice, independently: a raw byte search of a plain backup and a decrypt-and-search of an encrypted one, each with its own test phrase. A cross-check with a second, independent forensic tool is still to come.
| Item | Detail |
|---|---|
| Backups | Finder, local, full. Plain: 04:55 UTC. Encrypted: 05:42 UTC, 22,351 files, 19,387,083,952 bytes decrypted in 85 s, 0 errors. |
| Decryption library | iphone_backup_decrypt 0.11.2 (open source, MIT licence, commit c4a3e1a) with pycryptodome 3.24.0 |
| Our scripts | out_scan.py SHA-256 d961ae0fd56faf34d91ed6d18c8485e69cd1d4a90a303d1deb7d79782debbabe out_probe.py SHA-256 7fb5a225fa0fe4a1859320a5a9523be2b00fb7fc880fa67053c43a3c57868928 |
| WhatsApp messages | AppDomainGroup-group.net.whatsapp.WhatsApp.shared/ChatStorage.sqlite, table ZWAMESSAGE: ZTEXT (text), ZISFROMME (direction), ZMESSAGEDATE (seconds since 1 January 2001, UTC) |
| WhatsApp search index | AppDomainGroup-group.net.whatsapp.WhatsApp.shared/fts/ChatSearchV5f.sqlite |
| OUT | AppDomain-com.outmessenger.app/Library/Preferences/com.outmessenger.app.plist (196 bytes, the only OUT file) |
| Keychain | KeychainDomain/keychain-backup.plist: 1,986 items. AfterFirstUnlock 1,274 · WhenUnlocked 132 · Always 19 · AfterFirstUnlock ThisDeviceOnly 232 · WhenUnlocked ThisDeviceOnly 17 · Always ThisDeviceOnly 312 |
| iOS traces of OUT | WirelessDomain/Library/Databases/DataUsage.sqlite (network use), HomeDomain/Library/TCC/TCC.db (permissions), HomeDomain/Library/FrontBoard/applicationState.db, HomeDomain/Library/SpringBoard/IconState.plist |
| iOS share history | HomeDomain/Library/CoreDuet/People/interactionC.db, table ZATTACHMENT joined to ZINTERACTIONS |
What this test does not prove
- It is a backup test, not a full extraction. Commercial forensic tools, such as Cellebrite or Magnet AXIOM, can sometimes copy more of a phone than a backup contains. We have not yet tested OUT with one.
- One iPhone, one iOS version (iOS 18.7.10), on one day.
- A message on screen can be photographed. If a phone is taken unlocked with a chat open, what is visible can be seen.
- No app can control the other person’s phone or what iOS itself records about app use.
We will publish further tests here as we run them.
Repeat it yourself
- Send a unique phrase in the app you want to test, and receive one.
- Back up the iPhone in Finder (Mac) or the Apple Devices app (Windows). Try it with and without “Encrypt local backup”.
- Search the backup for your phrase. For an encrypted backup, the open-source iphone_backup_decrypt library can decrypt it on your own computer.
We are happy to share the exact scripts we used. Write to info@outmessenger.com.
Questions about iPhone backups and messengers
Can WhatsApp messages be recovered from an iPhone backup?
In our test, yes. Every test message was in the backup with its text, whether it was sent or received, and its exact time. It was there in the plain backup and in the encrypted one, once the backup password was entered.
Does an encrypted iPhone backup protect WhatsApp chats?
Only from people who do not know the backup password. With the password, the whole WhatsApp chat database and its search index open like in a plain backup.
What does OUT leave in an iPhone backup?
One 196-byte settings file: chat view, dark mode, sounds, accepted terms version. No messages, photos, contacts, usernames or message times were found in either backup.
Can forensic tools like Cellebrite recover OUT messages?
We have tested iPhone backups, not a commercial full extraction yet. OUT keeps message content in memory and never writes it to a chat database on the phone, so there is no chat archive to recover. We will publish a full-extraction test when we run one.