After using DMCA notice to remove iOS 9 “iBoot” code leak on GitHub, Apple says “the security of our products doesn't depend on the secrecy of our source code”
Context & Ripple Effects
The takedown follows Apple's DMCA notice against the iBoot repository filed a day earlier, after experts judged the leaked iOS 9 bootloader code authentic and likely still in use in iOS 11. The company is pairing enforcement with a message: security rests on design, not secrecy — consistent with its earlier argument that the deliberately unencrypted iOS 10 kernel cache was a performance choice that didn't compromise security.
The claim sits awkwardly next to Apple's own record: it refused China's request for source code, and jailbreak-community sources say the iBoot leak came from a low-level employee with more code already stolen. The statement reads as reputation management ahead of what may be further leaks.
First-order effects
- GitHub hosts must take down the iBoot repository, but the code is already mirrored across the jailbreaking community, so removal limits Apple's legal exposure more than its spread.
- Security researchers and jailbreak developers gain a rare authenticated look at the iOS secure-boot chain, the same component Apple hardened when iOS 9.1 shut down Pangu's jailbreak.
Second-order effects
- If more stolen code surfaces as community sources claim, Apple faces a running series of DMCA actions rather than a one-off, pushing it toward the kind of internal leak policing later seen in its New Product Security team's crackdown on CAD schematic leaks.
- The 'security doesn't depend on secrecy' framing will be quoted back at Apple by governments and litigants pressing for source-code access — including regimes whose requests it has previously refused.
Third-order effects
- The episode points toward a structural split in how major platform vendors handle source exposure: public insistence that architecture, not secrecy, carries the security burden, paired with aggressive private enforcement and insider-threat programs whenever code escapes.
- Secure-boot code becoming a recurring leak category would shift jailbreak research from reverse-engineering toward exploiting published internals, forcing vendors to treat old code as permanently compromised rather than recoverable.
The trend: Platform vendors are publicly reframing security as a property of design rather than source secrecy even as they expand internal anti-leak enforcement — a gap that grows each time internals escape.