iOS Forensic Toolkit 10.12 extracts the full file system image and the decrypted keychain from yet another IoT device: Apple HomePod mini. This is the first file system extraction of the device; the method uses the usbliter8 bootloader exploit and a custom adapter. This guide covers the hardware, the extraction and analysis steps.
Apple has shipped three HomePod models, each based on a different chip. Apple’s specifications do not list the processor; use the model identifier page at https://support.apple.com/en-us/101609 and match it to the chip below.
The S5 is roughly an A12 (iPhone Xs and Xr class). The A12 generation is within reach of the usbliter8 exploit, yet the exploit had to be adapted for this chip and this device.
A HomePod mini does not hold as much as a phone, but it holds the kind of data that places a device in a room and connects it to the people and hardware around it. The extraction returns:
With no screen or keypad, the HomePod mini has no passcode and cannot have one. No passcode means the data partition is not protected by a user secret, and this property limits the contents: a device without a passcode is never admitted to end-to-end encrypted iCloud data, so, aside of Wi-Fi passwords that do sync whether or not the speaker connected to a certain wireless network, the keychain you get is local to the speaker.
You will mostly just need the DYI adapter (Colobus with tcmini add-in), it’s open-source (both the hardware and firmware), and there are many manufacturers in any country you can order it from; the average cost is $30. Everything else is as usual: the HomePod mini itself, a USB-C cable, a macOS or Linux version of iOS Forensic Toolkit, and an active Internet connection to download the HomePod firmware.
The HomePod mini has one captive USB-C cable for power and data, and no button sequence to enter DFU. DFU is therefore triggered in hardware, by the adapter, in the same spirit as the Raspberry Pi Pico we use for automated DFU on the A11 devices (see Automating DFU Mode with Raspberry Pi Pico). The difference here is that the adapter chip does two jobs: it switches the speaker into DFU and applies the exploit.
For comparison, the first-generation HomePod was simpler in one respect and stranger in another. To put it into DFU, you unplug it, turn it upside down (the diagnostic port facing up), connect to the computer with an adapter, and plug it back in. For the HomePod mini that trick is gone, which is why the adapter does the work.
If you have the hardware, the rest is easy.
Flash the adapter once in the same way you flash a Waveshare RP2350 USB-A board; the firmware is different (get it from GitHub), though the exploit is the same usbliter8.
./EIFT_cmd info; the toolkit detects the speaker in Normal mode../EIFT_cmd boot
The toolkit detects the audioOS version and provides a firmware download link. Paste the link, or download the file and drag it onto the console window.
Once the ramdisk is up, ./EIFT_cmd info reports the device in ramdisk mode, with its product type (AudioAccessory5,1 for the mini) and the APFS volume layout.
./EIFT_cmd ramdisk unlockdata
The speaker has no passcode, so the volume unlocks without one. The toolkit reports the data volume as unlocked.
./EIFT_cmd ramdisk keychain -o homepod.xml
./EIFT_cmd ramdisk tar -o homepod.tar
The checksum is calculated during the extraction and shown at the end.
./EIFT_cmd ssh halt
The keychain comes out as a separate file. The convenient way to read it is the Keychain Explorer in Elcomsoft Phone Breaker (EPB). Open homepod.xml (in our example) there and the records are sorted by category.
The Wi-Fi entries are the useful part. Each is an AirPort network password, with the SSID and the password in clear text.
The file system image opens in general-purpose forensic tools as well. We loaded homepod.tar into Magnet AXIOM. The HomePod mini is not a rich device, so the artefact count is modest, but two things stand out.
First, the Bluetooth devices the speaker has seen. On our test extraction these included an iPhone 15 Pro Max, an Apple Watch, a MacBook Pro, an Apple TV (listed under the name “Home”), an Eve temperature sensor, and a couple of unidentified devices. Each carries a Bluetooth address and a UUID.
Second, the activity timeline: Siri execution events (without the spoken command itself), music playback events, application usage, network traffic, and updates.
One caveat on AXIOM: it asked for the path to the keychain file during processing, but did not attach its contents to the case. For the keychain, use EPB.
At the moment, the HomePod mini is supported in the macOS and Linux editions only. The exploit runs on the adapter chip, so a Windows edition is feasible; it just didn’t make this release.
The HomePod mini joins the list of Apple devices that iOS Forensic Toolkit extracts at the bootloader level. The hardware is a build-it-yourself adapter, and the extraction is simple: flash the adapter, connect the speaker, press a button, and run the usual boot, unlock, keychain, and tar commands. The speaker holds less than a phone, but a bunch of Wi-Fi passwords, the list of devices and account IDs are often a useful starting point, and sometimes the only one available.