Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
TazeTSchnitzel · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
chrismarlow9 · · focus · HN ↗
<a href="https://naehrdine.blogspot.com/2024/11/reverse-engineering-ios-18-inactivity.html" rel="nofollow">https://naehrdine.blogspot.com/2024/11/reverse-engineering-i...
axus · · focus · HN ↗
klinquist · · focus · HN ↗
polskibus · · focus · HN ↗
klinquist · · focus · HN ↗
klinquist · · focus · HN ↗
petergs · · focus · HN ↗
[1] <a href="https://en.wikipedia.org/wiki/Grayshift" rel="nofollow">https://en.wikipedia.org/wiki/Grayshift
toast0 · · focus · HN ↗
kube-system · · focus · HN ↗
Here's a renewal of one, presumably basic, license:
<a href="https://bidbanana.thebidlab.com/contract/4jKIvKMvZdoWo3d6K6qg" rel="nofollow">https://bidbanana.thebidlab.com/contract/4jKIvKMvZdoWo3d6K6q...
The product is not publicly available, and is sold only B2G: <a href="https://www.magnetforensics.com/products/magnet-graykey/#pardot-form" rel="nofollow">https://www.magnetforensics.com/products/magnet-graykey/#par...
loloquwowndueo · · focus · HN ↗
saagarjha · · focus · HN ↗
daveoc64 · · focus · HN ↗
quux · · focus · HN ↗
franczesko · · focus · HN ↗
amluto · · focus · HN ↗
delichon · · focus · HN ↗
As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
pieter_mj · · focus · HN ↗
skinfaxi · · focus · HN ↗
mmooss · · focus · HN ↗
alistairSH · · focus · HN ↗
jstanley · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
dana-s · · focus · HN ↗
jimt1234 · · focus · HN ↗
jstanley · · focus · HN ↗
Yes it's bad that the government overreaches, but it is also bad for your mental health to worry about it.
UpsideDownRide · · focus · HN ↗
simiones · · focus · HN ↗
The majority of people walking in the worse neighborhoods of LA or Chicago never have a single crime happen to them. But that doesn't mean that it's safe to go in a bad neighborhood - and it really doesn't mean it's safe to go there wearing designer clothing, gold watches, diamond rings and wearing your Apple VR device.
The same is true for travel. It's perfectly safe for the vast majority - but it's very important to be aware what may make you a target and what can happen to you if you are. Tens of millions of people visit the UK or China every year with no incident. But if you're a public active supporter of Palestine Action, or an active demonstrator against the CCCP respectively, be aware that you personally face a real risk from this travel, and your devices are actually very likely to be searched at those borders. Vice versa though (anti-CCCP activist traveling to UK, PA activist traveling to China) is perfectly safe, though.
Liftyee · · focus · HN ↗
(CCCP = Union of Soviet Socialist Republics...)
simiones · · focus · HN ↗
Though I should note that this would be the "SSSR" since I was clearly using the latin alphabet, even if I had chosen to use the Russian name of the USSR.
bryceacc · · focus · HN ↗
godwinson__4-8 · · focus · HN ↗
bryceacc · · focus · HN ↗
>CBP only searched the electronic devices of 55,318 international travelers,” the agency wrote, or 0.0013%.
would suck to be one of those 55 thousand people. I've never been bitten by a shark but I sure care about people that have?
serf · · focus · HN ↗
It seems more like they're trying to determine that it is in fact a laptop and not something resembling one.
dylan604 · · focus · HN ↗
0cf8612b2e1e · · focus · HN ↗
matheusmoreira · · focus · HN ↗
0cf8612b2e1e · · focus · HN ↗
wildzzz · · focus · HN ↗
folmar · · focus · HN ↗
LorenPechtel · · focus · HN ↗
sellmesoap · · focus · HN ↗
Havoc · · focus · HN ↗
jstanley · · focus · HN ↗
Havoc · · focus · HN ↗
jstanley · · focus · HN ↗
FireBeyond · · focus · HN ↗
encrypted_bird · · focus · HN ↗
FireBeyond · · focus · HN ↗
eli · · focus · HN ↗
<a href="https://www.aclu.org/news/privacy-technology/can-border-agents-search-your-electronic" rel="nofollow">https://www.aclu.org/news/privacy-technology/can-border-agen...
jstanley · · focus · HN ↗
devin · · focus · HN ↗
ryandrake · · focus · HN ↗
Razengan · · focus · HN ↗
brokenmachine · · focus · HN ↗
WithinReason · · focus · HN ↗
ChrisMarshallNY · · focus · HN ↗
Having thugs on speed dial opens a lot of doors.
rdevsrex · · focus · HN ↗
Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.
DaveSchmindel · · focus · HN ↗
<a href="https://nccriminallaw.sog.unc.edu/2026/08/03/giving-police-a-duress-code-instead-of-a-passcode-to-a-phone/" rel="nofollow">https://nccriminallaw.sog.unc.edu/2026/08/03/giving-police-a...
delichon · · focus · HN ↗
Razengan · · focus · HN ↗
simiones · · focus · HN ↗
rtkwe · · focus · HN ↗
We'll have to see how that case goes but ultimately the reason he's getting in trouble is only tangentially related to his phone being encrypted. It's more correct to think of it like he smashed the phone to pieces (and imagine this definitively destroys the data for the sake of the metaphor) instead of it being about the encryption itself.
LoganDark · · focus · HN ↗
Though I would expect courts to consider that he knew LE planned to enter the provided PIN, and that the duress PIN would then result in the phone being wiped, and therefore accuse him of doing the wiping anyway.
But I don't think it's this guy's fault at all. LE is the one who asked him under duress, he easily could've feared for his life, and he did no direct harm. It was self-defense at worst.
someothherguyy · · focus · HN ↗
Setting a booby trap to destroy evidence that then gets destroyed when that trap is triggered is the same as destroying evidence. This is common sense, but also see <a href="https://en.wikipedia.org/wiki/Principal_(criminal_law)" rel="nofollow">https://en.wikipedia.org/wiki/Principal_(criminal_law)
rtkwe · · focus · HN ↗
It's been a weakness in destructive duress codes since their inception.
[deleted] · · focus · HN ↗
[deleted]
glitchc · · focus · HN ↗
You can still be held in custody for obstruction of justice:
<a href="https://www.findlaw.com/legalblogs/third-circuit/man-held-in-contempt-for-refusing-to-unlock-devices-in-child-porn-case/" rel="nofollow">https://www.findlaw.com/legalblogs/third-circuit/man-held-in...
It took four years before he could secure his release:
<a href="https://www.sophos.com/en-us/blog/suspect-who-refused-to-decrypt-hard-drives-released-after-four-years" rel="nofollow">https://www.sophos.com/en-us/blog/suspect-who-refused-to-dec...
izacus · · focus · HN ↗
roncesvalles · · focus · HN ↗
rdtsc · · focus · HN ↗
nater5000 · · focus · HN ↗
But that's all beyond the point, anyways. If they did hand you your phone and said, "enter your passphrase," you can just say, "I don't remember it." They can throw a fit and put more heat on you in various ways, but until they resort to torturing you or they develop mind-reading technology, there's not much they can do at that point until the case reaches a judge.
That's not to say "I don't remember" is a sound, blanket defense. But it's sufficient for demonstrating that these dynamics all depend on willing participants which is partially why these laws are designed the way they are.
rdtsc · · focus · HN ↗
> But it's sufficient for demonstrating that these dynamics all depend on willing participants which is partially why these laws are designed the way they are.
What happens if during serving a search warrant the door is impossible to open or they find super reinforced safe. Owner can even say "I don't remember the combination"?
sterlind · · focus · HN ↗
kadoban · · focus · HN ↗
midas89 · · focus · HN ↗
keep in mind that the "obstruction" charge can be and is abused as a catchall charge.
MC995 · · focus · HN ↗
He didn't provide an incorrect code, or no code at all, he provided a duress code intended to destroy the device. There's a huge legal difference.
nikanj · · focus · HN ↗
wslh · · focus · HN ↗
BeetleB · · focus · HN ↗
There's a difference.
throw0101c · · focus · HN ↗
SCOTUS: Hold my beer…
:)
gonzalohm · · focus · HN ↗
wahern · · focus · HN ↗
Note that the recent high-profile case of a man being jailed involved him refusing, not claiming he didn't know. He was deliberately trying to test the law in this area, to force the issue onto the courts, and being arrested and charged was part of his plan.
spl757 · · focus · HN ↗
Cider9986 · · focus · HN ↗
>As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
Yes, it seems that way in the US: <a href="https://news.ycombinator.com/item?id=49922513">https://news.ycombinator.com/item?id=49922513
If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.
[1] <a href="https://www.privacyguides.org/en/cloud/" rel="nofollow">https://www.privacyguides.org/en/cloud/
0x262d · · focus · HN ↗
mmooss · · focus · HN ↗
> Cryptomator
Much security is poorly implemented; you can't count on it being effective. Even Apple, which takes security very seriously and has world-class talent and enormous resources, fails to implement security effectively sometimes (as in the OP). Can Cryptomator do better? Find the most respected - by professionals - security solution you can.
And on a device with many other functions - all the things you use your phone for - you risk all sorts of security holes in every function of app you use. And what happens to the data when your phone is backed up? Store the data on a single-purpose device.
Also, on an Internet-connected device, you make the data potentially accessible to the entire Internet. Use offline storage.
Bringing the storage device with you everywhere is asking for a mistake on your part - losing it, etc. Hide it someplace.
> or legal access
Ask a lawyer.
fragmede · · focus · HN ↗
tenacious_tuna · · focus · HN ↗
fragmede · · focus · HN ↗
> could cost me my home and life savings
but it's entirely fair to point out that Cryptomator itself is not a crypto wallet. I just know too many people irl that have lost thousands of dollars because they lost crypto private keys.
BeetleB · · focus · HN ↗
Why...?
If I had anything I didn't want the authorities to get, I'd remove it from my phone before travel (e.g. put in cloud, etc).
ChrisMarshallNY · · focus · HN ↗
Good name.
thraway3837 · · focus · HN ↗
artisinal · · focus · HN ↗
Unless you are Norwegian royalty and have your assistant wipe your phone.
robotresearcher · · focus · HN ↗
klinquist · · focus · HN ↗
Cider9986 · · focus · HN ↗
GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.
On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.
If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.
[1] <a href="https://strongphrase.net" rel="nofollow">https://strongphrase.net give memorable ones which is cool.
23ahGa17 · · focus · HN ↗
Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.
Cider9986 · · focus · HN ↗
Yes this is of course safer. What evidence do you have that it doesn't work on GrapheneOS, though?
<a href="https://www.computerweekly.com/feature/Journalist-Richard-Medhurst-had-his-mobile-phone-seized-Did-using-a-secure-phone-protect-his-data" rel="nofollow">https://www.computerweekly.com/feature/Journalist-Richard-Me...
1298436 · · focus · HN ↗
stefan_ · · focus · HN ↗
Someone · · focus · HN ↗
“The Great Firewall operates by checking transmission control protocol (TCP) packets for keywords or sensitive words. If the keywords or sensitive words appear in the TCP packets, access will be closed. If one link is closed, more links from the same machine will be blocked by the Great Firewall. The effect includes: limiting access to foreign information sources, blocking popular foreign websites and mobile apps, and requiring foreign companies to adapt to domestic regulations. Due to the Great Firewall, China has one of the lowest cross-border internet traffic rates in the world. Usage of foreign apps in China is minuscule; Asia Society estimated in 2026 that foreign apps blocked by the Great Firewall have extremely low traffic, particularly compared to domestic apps; the top five domestic apps saw traffic that was 1,000 times more than the top five foreign apps.”
oasisaimlessly · · focus · HN ↗
wat10000 · · focus · HN ↗
When I was there last year, it took some doing to get a VPN working. Mullvad was pretty good but it would take a few tries to find an endpoint I could connect to. The simplest escape hatch is to have a cellular connection from another country, but that's either expensive or slow.
alkh-qrt · · focus · HN ↗
gambiting · · focus · HN ↗
Edit: Just to be perfectly clear - Border Force in the UK can do the exact same thing to you once you return, British citizen or not. Leaving your device at home is still the safest choice.
Cider9986 · · focus · HN ↗
gambiting · · focus · HN ↗
And yes, UK has some awful laws around this. Yes it has put people in jail just for planning a protest before. Yes you can go to jail for not disclosing your passwords. But what you read on the internet is almost laughably out of proportion - no, you won't get arrested for posting a meme about the king.
dmitrygr · · focus · HN ↗
Might it "seem" that way because it is that way?
<a href="https://www.forbes.com/sites/steveforbes/2025/09/09/people-are-being-thrown-in-uk-prisons-over-what-theyve-said-online-can-free-speech-be-saved/" rel="nofollow">https://www.forbes.com/sites/steveforbes/2025/09/09/people-a...
<a href="https://www.telegraph.co.uk/news/2026/08/22/britain-has-become-a-surveillance-state-and-its-not-making/" rel="nofollow">https://www.telegraph.co.uk/news/2026/08/22/britain-has-beco...
<a href="https://freespeechunion.org/news/more-than-62-000-people-have-been-arrested-for-speech-offences-over" rel="nofollow">https://freespeechunion.org/news/more-than-62-000-people-hav...
Oh, and your government itself openly states it on record, too: <a href="https://hansard.parliament.uk/lords/2025-07-17/debates/F807CB70-D90D-4A19-9433-99539B7CF21F/OnlineCommunicationOffenceArrests" rel="nofollow">https://hansard.parliament.uk/lords/2025-07-17/debates/F807C...
gambiting · · focus · HN ↗
Not that this is some kind of great bar to clear, but if you're going to argue with what I said, argue with what I actually wrote.
dmitrygr · · focus · HN ↗
Clearly the point is clear. Why nitpick pointlessly?
gambiting · · focus · HN ↗
Someone above asked me how it was nonsense. I responded that people parotting the point about getting arrested for criticising the king is nonsense - like for instance, my American coworkers asking if that's true, because they read it somewhere on the internet. That is nonsense.
If you want to argue with this point please do, but also please observe the rest of my comment and especially the parts that I haven't actually said.
subscribed · · focus · HN ↗
6 people got arrested for trying to say "Not my king!" BEFORE his coronation: <a href="https://londondaily.com/not-my-king-anti-monarchy-protesters-arrested-during-uk-coronation" rel="nofollow">https://londondaily.com/not-my-king-anti-monarchy-protesters...
Before they had a chance of protest. After months of discussing the planned protest in details and getting a green light from the Met Police: <a href="https://www.bbc.co.uk/news/uk-65542558" rel="nofollow">https://www.bbc.co.uk/news/uk-65542558
52 people were arrested DURING the coronation, for example for holding a placard "not my king": <a href="https://londondaily.com/over-52-anti-monarchy-protestors-arrested-during-king-charles-coronation" rel="nofollow">https://londondaily.com/over-52-anti-monarchy-protestors-arr...
Police arrested despite KNOWING it's the member of public doesn't commit any offence: <a href="https://novaramedia.com/2025/03/11/police-officer-who-arrested-anti-monarchy-protester-was-aware-no-offence-had-been-committed/" rel="nofollow">https://novaramedia.com/2025/03/11/police-officer-who-arrest...
I'm afraid you unwittingly misled your coworkers.
gambiting · · focus · HN ↗
Dylan16807 · · focus · HN ↗
subscribed · · focus · HN ↗
>> Someone above asked me how it was nonsense. I responded that people parotting the point about getting arrested for criticising the king is nonsense
Protesting against the king is criticising the king IMO. I didn't see his quantifier, since I would agree that online critique of the king in particular is not yet penalised.
Not surprising you're implying bad faith though, if we're splitting the hair this thin.
Dylan16807 · · focus · HN ↗
No, but it's a critical part of the conversation chain.
"And yes, UK has some awful laws around this. Yes it has put people in jail just for planning a protest before. Yes you can go to jail for not disclosing your passwords. But what you read on the internet is almost laughably out of proportion - no, you won't get arrested for posting a meme about the king."
I'm not saying bad faith, I'm saying you misread their argument pretty badly.
2ahg7 · · focus · HN ↗
You can use other European countries like The Netherlands, which is a lawless police state with a liberal cover, as well.
gambiting · · focus · HN ↗
nostrademons · · focus · HN ↗
subscribed · · focus · HN ↗
6 people got arrested for trying to say "Not my king!" BEFORE his coronation: <a href="https://londondaily.com/not-my-king-anti-monarchy-protesters-arrested-during-uk-coronation" rel="nofollow">https://londondaily.com/not-my-king-anti-monarchy-protesters...
Before they had a chance of protest. After months of discussing the planned protest in details and getting a green light from the Met Police: <a href="https://www.bbc.co.uk/news/uk-65542558" rel="nofollow">https://www.bbc.co.uk/news/uk-65542558
It's not like Republicans in the UK are a violent group, unlike far right coddled by the same Met police.
52 people were arrested DURING the coronation, for example for holding a placard "not my king": <a href="https://londondaily.com/over-52-anti-monarchy-protestors-arrested-during-king-charles-coronation" rel="nofollow">https://londondaily.com/over-52-anti-monarchy-protestors-arr...
Police arrested despite KNOWING it's baseless and frankly illegal: <a href="https://novaramedia.com/2025/03/11/police-officer-who-arrested-anti-monarchy-protester-was-aware-no-offence-had-been-committed/" rel="nofollow">https://novaramedia.com/2025/03/11/police-officer-who-arrest...
Tell me some more how it isn't arresting for criticising the king. Oh, well, technically he wasn't a king yet.... but that's even worse to be fair.
[deleted] · · focus · HN ↗
[deleted]
markus_zhang · · focus · HN ↗
ryandrake · · focus · HN ↗
altruios · · focus · HN ↗
midas89 · · focus · HN ↗
smuhakg · · focus · HN ↗
Adding the USA to the list of countries where this is done would increase costs but it wouldn't be some nightmarish unprecedented problem.
markus_zhang · · focus · HN ↗
3128128 · · focus · HN ↗
Perhaps the reflexive genius downvoters can explain what happened to Richard Medhurst? After his phone was snatched and the authorities pretended not to be able to decrypt it, he went on a GrapheneOS promotion spree on X and wanted to write a book about computer security.
Now he has disappeared for nearly 6 weeks. How many more people do you want to get in trouble with your false promises?
prmoustache · · focus · HN ↗
Shutting it down won't help if you are forced by law to give out the password, which is the case in more and more countries.
dylan604 · · focus · HN ↗
Why do you call out just one OS? It's a good idea for any OS.
Cider9986 · · focus · HN ↗
rtkwe · · focus · HN ↗
dylan604 · · focus · HN ↗
rtkwe · · focus · HN ↗
<a href="https://threecats.au/two-factor-pin-fingerprint-unlock-grapheneos" rel="nofollow">https://threecats.au/two-factor-pin-fingerprint-unlock-graph...
dataflow · · focus · HN ↗
rtkwe · · focus · HN ↗
subscribed · · focus · HN ↗
iamnothere · · focus · HN ↗
fluidcruft · · focus · HN ↗
cj · · focus · HN ↗
theendisney · · focus · HN ↗
Extra points if you hold you face really close and count in a dead language. You can also make ordered hand gestures in stead of counting on your fingers. Be a wizard about it!
cheschire · · focus · HN ↗
Brybry · · focus · HN ↗
Is that actually better (in practice, not in terms of entropy) than /dev/urandom? I have a lot less trust in my ability to successfully scrub a picture from my phone that deterministically created my passphrase.
lisper · · focus · HN ↗
It offers protection in the event that your /dev/urandom is compromised. Otherwise no.
(Of course, if your /dev/urandom is compromised then your path to computing a hash of a photo is likely compromised as well.)
Matumio · · focus · HN ↗
NetMageSCW · · focus · HN ↗
manwe150 · · focus · HN ↗
theendisney · · focus · HN ↗
heelix · · focus · HN ↗
throw0101c · · focus · HN ↗
Or on the CLI:
* <a href="https://packages.debian.org/search?keywords=diceware" rel="nofollow">https://packages.debian.org/search?keywords=diceware
* <a href="https://packages.debian.org/search?keywords=pwgen" rel="nofollow">https://packages.debian.org/search?keywords=pwgen
busssard · · focus · HN ↗
iamnothere · · focus · HN ↗
busssard · · focus · HN ↗
fluidcruft · · focus · HN ↗
eli · · focus · HN ↗
isoprophlex · · focus · HN ↗
dessimus · · focus · HN ↗
olyjohn · · focus · HN ↗
83 · · focus · HN ↗
katzenq · · focus · HN ↗
LorenPechtel · · focus · HN ↗
Telaneo · · focus · HN ↗
hulitu · · focus · HN ↗
nkrisc · · focus · HN ↗
sellmesoap · · focus · HN ↗
usern20260720 · · focus · HN ↗
NetMageSCW · · focus · HN ↗
Telaneo · · focus · HN ↗
dzhiurgis · · focus · HN ↗
ssl-3 · · focus · HN ↗
fluidcruft · · focus · HN ↗
ssl-3 · · focus · HN ↗
And by that I mean, using the database itself is simple. But when it exists, then a list of targets for an attacker to emulate also exists.
Those boys at Cellebrite aren't dummies, at all, and they've been doing this stuff for quite a long time. They're a formidable opponent.
We used to use their kit to clone personal data between very different devices back in the dumb phone days. They were the only ones to get it right out of a sea of others that were also evaluated.
ssl-3 · · focus · HN ↗
yencabulator · · focus · HN ↗
ssl-3 · · focus · HN ↗
burningChrome · · focus · HN ↗
Unless you have a 4 or 4XL which are pretty popular with graphene os users. The weird thing is the 4 and 4XL are the only models without fingerprint because Google was pushing its #D Face Unlock System at the time.
The funny part is Graphene by default now disables face unlock on newer Pixel models.
NetMageSCW · · focus · HN ↗
Melatonic · · focus · HN ↗
bigyabai · · focus · HN ↗
eli · · focus · HN ↗
bigyabai · · focus · HN ↗
Both of them needed a PR win, and San Bernardino gave both sides exactly what they wanted. If it wasn't collusion, it was certainly convenient for Apple and the FBI both.
monster_truck · · focus · HN ↗
That aside, it doesn't change their extensive history of ensnaring and enabling mentally deficient young men to incriminate themselves.
You could attempt to argue that anyone they can do that to is inherently a risk or threat because any other group could have done the same, but at the same time this approach broke containment and is being directed at a markedly more pale demographic, ie <a href="https://en.wikipedia.org/wiki/The_Base_(neo-Nazi_group)" rel="nofollow">https://en.wikipedia.org/wiki/The_Base_(neo-Nazi_group), with seemingly no counterplay
monster_truck · · focus · HN ↗
I wouldn't call it scheming though. The approach of choice to (scare quotes) ensuring continued access has traditionally been one where there is no overt coordination or communication. The ideal case is one where every engineer, pm, qa, leadership earnestly believe that they have done a good job/the correct thing... and then there is some deficiency that handily bypasses all of that, exposed publicly, without any authentication and a convenient lack of logging, or some oversight in the specification/standard everything operates against. Real world examples of this include backends to vehicle telemetry/connectivity apps that hand over complete driving histories with the right ip, json and a vin, or flock somehow deploying ~nationwide with a static password and no append only logging in each device. They're flagrant violations of best practices, without conseqeuences or liability.
That's one of the more incredible things about LLMs, the rate at which they are finding these needles in haystacks is only going to accelerate. It's the end of an era. These things were never used for what they should have been, I struggle to imagine a legitimate argument in favor for them that isn't carrying water for the wrong team.
saagarjha · · focus · HN ↗
Link?
clueless · · focus · HN ↗
saagarjha · · focus · HN ↗
canada_dry · · focus · HN ↗
<a href="https://news.ycombinator.com/item?id=38783112">https://news.ycombinator.com/item?id=38783112
Cider9986 · · focus · HN ↗
>Even if that device doesn't have the ability to turn on Airplane Mode or to turn off the transmitters through the Control Center of iOS.
IIRC, the default on iOS is that anyone with your locked device can enable airplane mode which is concerning simply for thieves. But I suppose they have to use faraday bags anyway because of the Find My network.
jonahhorowitz · · focus · HN ↗
Syper · · focus · HN ↗
ethagnawl · · focus · HN ↗
This is weird framing. The feature makes it harder for anyone to break into the device.
tamimio · · focus · HN ↗
ethagnawl · · focus · HN ↗
nikanj · · focus · HN ↗
Cider9986 · · focus · HN ↗
tamimio · · focus · HN ↗
monneyboi · · focus · HN ↗
bluefirebrand · · focus · HN ↗
Even then, who enforces the court order? :/
mmooss · · focus · HN ↗
bigyabai · · focus · HN ↗
This entire lawsuit was bizarre, and weirdly mishandled by Apple. It suggests to me that Apple was threatened, either by US spying agencies, NSO Group or NSO's local jurisdiction.
saagarjha · · focus · HN ↗
childintime · · focus · HN ↗
LorenPechtel · · focus · HN ↗
lrvick · · focus · HN ↗
It is not possible to actually own an Apple device.
It will do whatever Apple wants it to do, or whatever anyone that pays them enough wants it to do.
_justinfunk · · focus · HN ↗
monster_truck · · focus · HN ↗
iancarroll · · focus · HN ↗
Based on this, it seems more likely that this involves exploiting the device to retrieve the underlying keybags present in AFU mode and store them, rather than manipulating the actual feature of automatic reboots. Then the device can be exploited again in BFU mode but with the prior keybag to decrypt everything.
It sounds like this feature is being used to exploit and extract keys from devices without a warrant (or in advance of getting one), which seems dubious to me.
t1234s · · focus · HN ↗
15155 · · focus · HN ↗
wat10000 · · focus · HN ↗
int0x29 · · focus · HN ↗
> given that oftentimes they can’t immediately try to break into iPhones that have been seized. That could be because police are still waiting for a court authorization to do so
> GrayKey Preserve and Evidence Preservation Mode are also designed to combat another iPhone feature that automatically deletes certain data — such as cached locations, and recently deleted photos and iMessages — after a certain number of days. “We're gonna be able to preserve that data for an infinite amount of time.”
> “That AFU state is captured,” by GrayKey Preserve and Evidence Preservation Mode, the employee says. “Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost. This is the true magic behind the GrayKey Preserve and the Evidence Preservation Mode function.”
The power loss tolerance in particular looks iffy. The photo and iMessage bits are a bit more problematic in that light. I get that they claim the police aren't seeing the data but if they are extracting before a warrant that is effectivly the same as pre searching everyone and promising not to read it.
Dylan16807 · · focus · HN ↗
Oh, like how bulk internet monitoring works. Ugh.
ktm5j · · focus · HN ↗
Also, as someone who was the victim of a pretty awful violent crime I'm here to tell you that police are not the enemy. There are some really bad people out there, trust me.. if you ever met one you would probably be okay with cops violating their privacy.
whatsdowndog · · focus · HN ↗
You are on the wrong website buddy. The group think here doesn't like statements like these.
jmward01 · · focus · HN ↗
NetMageSCW · · focus · HN ↗
AdamJacobMuller · · focus · HN ↗
The only difference is that a random asshole on the street can't really do anything to me, I can just walk away.
A random asshole cop has a crazy amount of discretionary power over me, even without him stepping outside departmental procedures or the law.
nielsbot · · focus · HN ↗
toomuchtodo · · focus · HN ↗
<a href="https://www.prisonpolicy.org/blog/2026/01/26/police_misconduct/" rel="nofollow">https://www.prisonpolicy.org/blog/2026/01/26/police_miscondu...
<a href="https://www.prisonpolicy.org/blog/2020/06/05/policekillings/" rel="nofollow">https://www.prisonpolicy.org/blog/2020/06/05/policekillings/
<a href="https://www.policedatainitiative.org/datasets/" rel="nofollow">https://www.policedatainitiative.org/datasets/
<a href="https://policecrime.bgsu.edu/Home/Crimes" rel="nofollow">https://policecrime.bgsu.edu/Home/Crimes
<a href="https://ij.org/the-ij-database-of-alpr-abuse/" rel="nofollow">https://ij.org/the-ij-database-of-alpr-abuse/
<a href="https://ndi.iadlest.org/home" rel="nofollow">https://ndi.iadlest.org/home
"And some, I assume, are good people."
sixothree · · focus · HN ↗
writtenone · · focus · HN ↗
It becomes "well we need to scan websites to make sure there's no X, Y, or Z, and prosecute the site operators who don't cooperate" real fast.
gatlin · · focus · HN ↗
LorenPechtel · · focus · HN ↗
AngryData · · focus · HN ↗
soulofmischief · · focus · HN ↗
thecrash · · focus · HN ↗
ktm5j · · focus · HN ↗
franga2000 · · focus · HN ↗
If the software hacks the phone first, but only releases the information later, while marketing itself as simply "preserving the device state", they can point at that marketing and say "we're just preserving evidence while waiting for a warrant", despite the fact they've actually already broken into your phone.
ktm5j · · focus · HN ↗
franga2000 · · focus · HN ↗
I don't know what you're not seeing here. Even the most honest and fair cop would love to "preserve evidence" while they wait for a warrant - they already turn on airplane mode and put devices in a Faraday cage, sometimes they even put them to charge so they stay AFU until they get a warrant. To them, such software is just a natural extension of that, after some manufacturers added auto reboots.
And from the software vendor's perspectice, it nakes perfect sense to take advantage of AFU, hack the phone, dump it or install a backdoor to "preserve AFU" and then pretend to hack it once the cops click "I have a warrant now". It's a great business model - it solves a real problem, it gives you a competitive advantage, you aren't even technically lying, just not telling the whole truth.
ktm5j · · focus · HN ↗
franga2000 · · focus · HN ↗
strathmeyer · · focus · HN ↗
[dead]
mmmlinux · · focus · HN ↗