Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones (404media.co)

228 points by speckx 7 hours ago

int0x29 2 hours ago

These three quotes make me wonder if the police are effectively searching the phone before getting a warrant

> given that oftentimes they can’t immediately try to break into iPhones that have been seized. That could be because police are still waiting for a court authorization to do so

> GrayKey Preserve and Evidence Preservation Mode are also designed to combat another iPhone feature that automatically deletes certain data — such as cached locations, and recently deleted photos and iMessages — after a certain number of days. “We're gonna be able to preserve that data for an infinite amount of time.”

> “That AFU state is captured,” by GrayKey Preserve and Evidence Preservation Mode, the employee says. “Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost. This is the true magic behind the GrayKey Preserve and the Evidence Preservation Mode function.”

The power loss tolerance in particular looks iffy. The photo and iMessage bits are a bit more problematic in that light. I get that they claim the police aren't seeing the data but if they are extracting before a warrant that is effectivly the same as pre searching everyone and promising not to read it.

Dylan16807 an hour ago

> pre searching everyone and promising not to read it

Oh, like how bulk internet monitoring works. Ugh.

ktm5j an hour ago

I'm not seeing what you're seeing. The inactivity reboot wouldn't be a problem if they aren't waiting for a warrant. The fact that this article even exists supports the fact that they are waiting for warrants.

Also, as someone who was the victim of a pretty awful violent crime I'm here to tell you that police are not the enemy. There are some really bad people out there, trust me.. if you ever met one you would probably be okay with cops violating their privacy.

writtenone an hour ago

There's no world in which cops can or will only violate the privacy of obvious criminals.

It becomes "well we need to scan websites to make sure there's no X, Y, or Z, and prosecute the site operators who don't cooperate" real fast.

AngryData 16 minutes ago

The most likely person to assault me are the cops so I still think cops are the enemy.

LorenPechtel 23 minutes ago

Police are not supposed to be the enemy. All too often these days they become the enemy, though.

sixothree an hour ago

Dahmer's victim would like to have a word with you.

whatsdowndog an hour ago

>> police are not the enemy

You are on the wrong website buddy. The group think here doesn't like statements like these.

jmward01 an hour ago

toomuchtodo 38 minutes ago

Cider9986 6 hours ago

For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.

GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.

On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.

If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.

[1] https://strongphrase.net give memorable ones which is cool.

NetMageSCW 25 minutes ago

Note that the iPhone also can be set to use a complicated password instead of a PIN and it will require it on first unlock.

iamnothere 5 hours ago

Never use a website to generate a password for something important like this. You can print out diceware passwords and roll dice.

throw0101c an hour ago

> You can print out diceware passwords and roll dice.

Or on the CLI:

* https://packages.debian.org/search?keywords=diceware

* https://packages.debian.org/search?keywords=pwgen

fluidcruft 4 hours ago

You can just take a picture of a pile of dice, a pile of rice, or a tree, patch of grass, etc, and compute a secure hash/whatever and base six it to get the rolls.

Brybry 3 hours ago

cj 3 hours ago

theendisney 2 hours ago

fluidcruft 4 hours ago

Why not automatically power down if any unknown USB device is attached?

ssl-3 25 minutes ago

Or shut down when any USB device is attached while the phone is locked/inactive?

It'd work like this: Unlock phone, plug in USB widget; it works.

Or: Plug in USB widget without first unlocking phone; phone shuts down.

eli 3 hours ago

So like you connect it to your computer for the first time and it shuts off?

sellmesoap 2 hours ago

83 3 hours ago

isoprophlex 3 hours ago

usern20260720 2 hours ago

olyjohn 3 hours ago

nkrisc 3 hours ago

dylan604 5 hours ago

> On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase

Why do you call out just one OS? It's a good idea for any OS.

rtkwe 5 hours ago

This seems specific to GrapheneOS (unique as far as I know though I'd be happy to learn otherwise) where you could set a very long first unlock passphrase and have a shorter less cumbersome fingerprint plus pin option for subsequent unlocks. I wouldn't want to have to enter a long passphrase every time I unlock but once a day isn't so bad.

dylan604 5 hours ago

dataflow 5 hours ago

Cider9986 5 hours ago

Yes, in fact on GrapheneOS it's less necessary and it's only necessary if you don't want to rely on the secure element rate limiting.

GrapheneOS allows using a passphrase with more convenience because of the fingerprint plus second factor pin (I don't think you can just have a pin as a secondary unlock). You don't need to enter the passphrase every time you unlock with this setup, only when first starting up.

The official opinion: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

subscribed an hour ago

Because apart of the IOS, according to GrayKey and Cellebrite, GrapheneOS on Pixels is the only phone where it even makes sense (realistically).

burningChrome 2 hours ago

>> then a fingerprint with a second factor pin as the secondary unlock

Unless you have a 4 or 4XL which are pretty popular with graphene os users. The weird thing is the 4 and 4XL are the only models without fingerprint because Google was pushing its #D Face Unlock System at the time.

The funny part is Graphene by default now disables face unlock on newer Pixel models.

23ahGa17 6 hours ago

People believed the reboot feature last time GrapheneOS was mentioned. It is of course nonsense.

Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.

Cider9986 6 hours ago

> Shut down the phone in areas with a high snatch risk.

Yes this is of course safer. What evidence do you have that it doesn't work on GrapheneOS, though?

https://www.computerweekly.com/feature/Journalist-Richard-Me...

1298436 5 hours ago

markus_zhang 5 hours ago

To add an extra layer of safety. Bring a secondary phone when travelling by airplanes, especially to other countries. You should also use it frequently, maybe with some side apps to make it look like it's your daily phone.

ryandrake 5 hours ago

3128128 2 hours ago

GrapheneOS is critical infrastructure. Questioning it is not like criticizing Neovim. People can get detained, killed and more.

Perhaps the reflexive genius downvoters can explain what happened to Richard Medhurst? After his phone was snatched and the authorities pretended not to be able to decrypt it, he went on a GrapheneOS promotion spree on X and wanted to write a book about computer security.

Now he has disappeared for nearly 6 weeks. How many more people do you want to get in trouble with your false promises?

stefan_ 5 hours ago

The internet exists and can transfer your data with no customs and borders, so if you are at risk of being snatched, the correct choice is to not carry a phone (or laptop, or..) at all.

Someone 5 hours ago

alkh-qrt 4 hours ago

iancarroll 3 hours ago

> “Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost. This is the true magic behind the GrayKey Preserve and the Evidence Preservation Mode function.”

Based on this, it seems more likely that this involves exploiting the device to retrieve the underlying keybags present in AFU mode and store them, rather than manipulating the actual feature of automatic reboots. Then the device can be exploited again in BFU mode but with the prior keybag to decrypt everything.

It sounds like this feature is being used to exploit and extract keys from devices without a warrant (or in advance of getting one), which seems dubious to me.

delichon 6 hours ago

I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.

As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

WithinReason 6 hours ago

If you don't give access to law enforcement when they ask: straight to jail. Encryption is irrelevant in that situation. If they see the encrypted volume you need to provide them access.

rdevsrex 6 hours ago

Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.

Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.

DaveSchmindel 6 hours ago

glitchc 6 hours ago

midas89 4 hours ago

rdtsc 4 hours ago

BeetleB 2 hours ago

nikanj 3 hours ago

throw0101c an hour ago

izacus 5 hours ago

wslh 3 hours ago

spl757 2 hours ago

Precisely, unless there is plausible deniability that a blob of data is indeed an encrypted file they can just hold you in jail until you comply. There are encryption schemes that provide plausible deniability, but implementing would probably not be trivial.

ChrisMarshallNY 6 hours ago

Classic $5 wrench.

Having thugs on speed dial opens a lot of doors.

gonzalohm 6 hours ago

So if an app installs an encrypted volume for which you don't have the password to, you go to jail? That doesn't make sense. How can they know if I have the password or not

wahern 6 hours ago

Cider9986 6 hours ago

It would seem wise to at least keep a backup in an E2EE cloud [1]. This could possibly allow you to not give access even if legally compelled.

>As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

Yes, it seems that way in the US: https://news.ycombinator.com/item?id=49922513

If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.

[1] https://www.privacyguides.org/en/cloud/

0x262d 4 hours ago

Yeah, getting all your sensitive stuff off your phone onto a secure cloud service seems like the obvious approach here right? They can still escalate what they try to coerce you to do, but they don't have physical access to your data just by taking your phone, and you can also leave the phone with them and only lose the device if needed. In my likely scenario - innocent traveler, they aren't looking for anything specific, but I still don't want them to look through my files and photos just because I happen to travel internationally - that seems like it puts it out of reach (and out of obvious view) for now.

BeetleB 2 hours ago

> I keep all of my most sensitive personal documents on my phone

Why...?

If I had anything I didn't want the authorities to get, I'd remove it from my phone before travel (e.g. put in cloud, etc).

jstanley 6 hours ago

It seems foolhardy to carry your life savings around everywhere, encrypted or not.

If you really want to keep this stuff on a phone at least stretch to a second phone and keep it somewhere safe.

ryandrake 5 hours ago

Exactly. Don't keep your life on your phone. We shouldn't have to take these precautions but unfortunately we do.

Razengan 4 hours ago

devin 5 hours ago

or a separate hard drive in a fireproof safe or something.

fragmede 2 hours ago

Oh my god, get out of crypto. Put your money into a bank instead of trying to one-man-army yourself into being Fort Knox.

tenacious_tuna 2 hours ago

Cryptomator appears to be a file encryption tool, not a cryptocoin anything. What're you reacting to?

fragmede 2 hours ago

pieter_mj 6 hours ago

If you travel abroad you must unlock. No 4th amendment for you.

eli 3 hours ago

That’s not the full story and not really correct.

https://www.aclu.org/news/privacy-technology/can-border-agen...

skinfaxi 6 hours ago

You can decline but then they can seize is that right?

alistairSH 5 hours ago

mmooss 6 hours ago

jstanley 6 hours ago

This is mostly FUD. I've never been asked to unlock my phone when travelling abroad.

bryceacc 6 hours ago

Havoc 5 hours ago

serf 6 hours ago

dana-s 6 hours ago

FireBeyond 3 hours ago

mmooss 5 hours ago

It seems to me you are taking a big risk. Some considerations:

> Cryptomator

Much security is poorly implemented; you can't count on it being effective. Even Apple, which takes security very seriously and has world-class talent and enormous resources, fails to implement security effectively sometimes (as in the OP). Can Cryptomator do better? Find the most respected - by professionals - security solution you can.

And on a device with many other functions - all the things you use your phone for - you risk all sorts of security holes in every function of app you use. And what happens to the data when your phone is backed up? Store the data on a single-purpose device.

Also, on an Internet-connected device, you make the data potentially accessible to the entire Internet. Use offline storage.

Bringing the storage device with you everywhere is asking for a mistake on your part - losing it, etc. Hide it someplace.

> or legal access

Ask a lawyer.

ethagnawl 6 hours ago

> The idea behind this so-called “inactivity reboot” is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology.

This is weird framing. The feature makes it harder for anyone to break into the device.

tamimio 5 hours ago

Not weird, not anyone can buy those equipment to break into a fully updated phone, in fact, it’s pretty much only law enforcement can or will have access to them, so that statement is true, it will make it harder for police to do so.

ethagnawl 4 hours ago

That's not how exploits work, though. This is also the reason why backdoors in encryption and the like are never a good idea. Sure, "police" are the ones _most likely_ to use this tool (developed by a private company...) to use this exploit to break into iPhones. However, anyone who is motivated enough and/or has the resources _could_ also do it.

nikanj 3 hours ago

You can buy the mandatory TSA key for your suitcase lock from eBay for a few bucks. Tools have a way of falling off the truck at the loading dock

15155 2 hours ago

It's amazing that this hasn't been tried as tortious interference. If MMOGlider can be found liable, why can't Cellebrite or GrayKey? Every TOS has anti-reverse-engineering clauses.

wat10000 an hour ago

In the implicit hierarchy of our society, large corporations and law enforcement are both near the top, whereas ordinary people are waaaaaay at the bottom. Something that helps ordinary people at the expense of large corporations gets squashed, but if it helps law enforcement that's a different matter altogether.

Melatonic 6 hours ago

I wouldnt be surprised if they had a backdoor into the Qualcomm chip that Apple decided to oddly still include in most of their US iPhones vs the international versions that come with their own internal modem

canada_dry 3 hours ago

This extremely well hidden backdoor was an interesting find:

https://news.ycombinator.com/item?id=38783112

clueless 3 hours ago

that Qualcomm chip that apple uses is a modem, so not sure it's that relevant to the phone's security in this case...

bigyabai 4 hours ago

I wouldn't be surprised if they had a backdoor into the Secure Enclave. Apple is definitely a part of the US' NOBUS scheming, whether or not cops get to use it.

monster_truck 3 hours ago

The past few weeks of people ripping into it have demonstrated that SE is mostly reality distortion and does not offer any unique or meaningful protection. I have no doubt the old modems had deficiencies, the new ones assuredly do too. Just a changing of the guard for however long it lasts.

I wouldn't call it scheming though. The approach of choice to (scare quotes) ensuring continued access has traditionally been one where there is no overt coordination or communication. The ideal case is one where every engineer, pm, qa, leadership earnestly believe that they have done a good job/the correct thing... and then there is some deficiency that handily bypasses all of that, exposed publicly, without any authentication and a convenient lack of logging, or some oversight in the specification/standard everything operates against. Real world examples of this include backends to vehicle telemetry/connectivity apps that hand over complete driving histories with the right ip, json and a vin, or flock somehow deploying ~nationwide with a static password and no append only logging in each device. They're flagrant violations of best practices, without conseqeuences or liability.

That's one of the more incredible things about LLMs, the rate at which they are finding these needles in haystacks is only going to accelerate. It's the end of an era. These things were never used for what they should have been, I struggle to imagine a legitimate argument in favor for them that isn't carrying water for the wrong team.

eli 3 hours ago

So the FBI publicly fueding with Apple over encryption is all just misdirection? I dunno about that

monster_truck 3 hours ago

bigyabai 3 hours ago

Cider9986 6 hours ago

Huh, so this is essentially very similar be what this guy said to my suggestion of a factory reset timer in GrapheneOS being flawed. Apple's implementation of the reboot timer is flawed.

This goes to show for all the people that want GrapheneOS to implement a feature like hidden profiles–flawed features give people a false sense of security and should not be implemented (that's not to mention deniability may not even be a good feature if it was technically possible to implement it well).

Me:

>What about a duress timer working as the reboot timer but it wipes if you don't unlock within the time period. Would that have any advantages for destruction of evidence or deniability?

HybridStatAnim8:

>That would not be viable because the hardware does not support it. It cannot be implemented in the OS because the OS can be turned off or exploited endlessly. For GOS to consider it, it would likely need to be backed by the secure element.

>Duress PIN is deemed acceptable to implement in the OS because it is expected that the user is the one to enter it, so it has not fallen into the hands of attackers who may bypass it. Once attackers have it, you are effectively gambling. Account for that in your threat model and do not let it get to that point.

https://news.ycombinator.com/item?id=49040342

Cider9986 6 hours ago

Offtopic:

>Even if that device doesn't have the ability to turn on Airplane Mode or to turn off the transmitters through the Control Center of iOS.

IIRC, the default on iOS is that anyone with your locked device can enable airplane mode which is concerning simply for thieves. But I suppose they have to use faraday bags anyway because of the Find My network.

jonahhorowitz 3 hours ago

You can (and should) disable access to the Control Center when the phone is locked. You could, alternately, remove the “airplane mode” button from the control center.

Syper 2 hours ago

Thank you for those tips you both. I have never thought about the control center. Thankfully I have yet to have my devices stolen.

amluto 6 hours ago

Ooh, I wonder whether Apple made the classic mistake of using a wall clock timer when they should have used a monotonic (local) clock timer.

edit: having personally gone through this kind of mess, the correct solution is to use strict typing to make sure you keep track of the difference between times and durations and the difference between different clock types. Don’t use plain integers and also don’t try to fudge it the way that Go’s standard library solution does. The modern C++ library is actually pretty good, although you need to use very recent versions of the standard for full functionality.

TazeTSchnitzel 6 hours ago

Is it maybe providing a bogus NTP server or something? Maybe the automatic reboot feature can be moved to the Secure Enclave or something, and made to only rely on the hardware RTC in a way that can't be tampered with.

chrismarlow9 5 hours ago

Here's a deeper dive on that question:

https://naehrdine.blogspot.com/2024/11/reverse-engineering-i...

Tl,dr: it's likely baked into the sep, no ntp

I'm wondering if you put the phone into a mode where it thinks it's dialing emergency services or contacting them via crash detection etc that it won't reboot. I could picture a scenario where the code is written to never disrupt an emergency services call.

Full disclosure I don't own an iPhone so this may not even be a thing. Just guessing based on liability risk from Apple of "what's more important than protecting the phone"

childintime 4 hours ago

Why don't my credit card and my phone implement a second pincode or password that allows me to signal that I'm in a hostage situation, and want everything (discretely) wiped? So that would do a saldo = sqrt(saldo) for a bank card, for example, and cancel all my limits.

t1234s 3 hours ago

Graphine needs a triple tap power button for a hard power off.

monneyboi 5 hours ago

So we pay Apple for friction. And the state pays for Graykey to remove it. Whoever wins that arm race this quarter determines what our rights are worth in practice.

bluefirebrand 5 hours ago

Well, that's assuming you are ever able to claim your phone back. From what I understand police might just keep it indefinitely until they are able to access it, unless you get some kind of court order that it he returned to you

Even then, who enforces the court order? :/

_justinfunk 4 hours ago

I kept being thrown off by the headline and article saying "cops".

monster_truck 3 hours ago

Why? The only people that care about that are obnoxious judges and asshole state troopers

axus 6 hours ago

Does this mean iPhones are worth more to steal?

klinquist 6 hours ago

No. This requires an expensive license for a government agency to purchase in order to take advantage of this functionality.

loloquwowndueo 6 hours ago

Sounds like “this tsa approved lock needs a special key you can totally not just buy on Amazon”

polskibus 6 hours ago

Can you provide a reference to that?

kube-system 6 hours ago

petergs 6 hours ago

klinquist 6 hours ago

quux 6 hours ago

Perhaps for a short time. As soon as Apple understands the exploit I expect them to patch it. They may even back port the fix to older iOS versions as well.

daveoc64 6 hours ago

This article seems completely unrelated to theft of devices.

thraway3837 6 hours ago

iOS has a remote erase feature. Its also a leaked video and doesn't show which version or model. So it could be something that is already patched, or soon will be. Remember to always keep your OSes update.

klinquist 4 hours ago

The first thing the authorities know to do is put your phone in an RFID bag/enclosure so it can't talk to the outside world.

artisinal 6 hours ago

It's a bit difficult to remote erase your phone while you are in custody.

Unless you are Norwegian royalty and are notified of your upcoming arrest, then you can wipe all you need.

mmooss 5 hours ago

I wonder why Apple, with its resources, doesn't take the lawfare approach to someone attacking its phones, for profit, and damaging its reputation.

bigyabai 4 hours ago

Apple tried suing NSO Group, which is one of the most wanton and dangerous iPhone hacking firms anywhere in the world. Hilariously, halfway through the case Apple turned a 180 claiming some trade secret danger, and begged the court to drop the case: https://appleinsider.com/articles/24/09/13/apple-files-to-st...

This entire lawsuit was bizarre, and weirdly mishandled by Apple. It suggests to me that Apple was threatened, either by US spying agencies, NSO Group or NSO's local jurisdiction.

tamimio 6 hours ago

Well first on the things you can do right now till apple figures it out, you should have control center disabled while the phone is locked, you can find it under “Allow Access When Locked” in face id and passcode settings, while -per the article- this won’t stop them, it sure will make it harder as by the time they try to gain access the 72h might have passed and a reboot happens. Second, they definitely fake the internal clock through the port, and because connected phone will keep correcting it through the NTP, hence it’s crucial to them to isolate the phone, so your job is to make that harder on them or delay it enough till it reboots itself. I think some of the quick counter measures apple can do now is allowing custom reboot periods, remote reboots through icloud, and disabling the possibility of manipulating the time through the lightning/usbc port.

ChrisMarshallNY 6 hours ago

> AFU

Good name.

lrvick 4 hours ago

Remember that Apple has full remote code execution rights on every device and hands that power over to the CCP in China, and they could do it here too.

It is not possible to actually own an Apple device.

It will do whatever Apple wants it to do, or whatever anyone that pays them enough wants it to do.