‹ BackHN Continuity

Thread

Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones

287 points · 226 comments · speckx

  1. delichon · · focus · HN ↗
    I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.

    As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

    1. pieter_mj · · focus · HN ↗
      If you travel abroad you must unlock. No 4th amendment for you.
      1. skinfaxi · · focus · HN ↗
        You can decline but then they can seize is that right?
        1. mmooss · · focus · HN ↗
          It would depend on the country.
        2. alistairSH · · focus · HN ↗
          In the US, that is generally true. They cannot prevent entry (by citizens), but can keep the phone for a period.
      2. jstanley · · focus · HN ↗
        This is mostly FUD. I've never been asked to unlock my phone when travelling abroad.
        1. [deleted] · · focus · HN ↗

          [deleted]

        2. dana-s · · focus · HN ↗
          I believe the parent comment is talking about leaving US, coming back to the US and then having US's border patrol do so. If that is also what you understood, are you an activist or anyone whom would be of interest to the feds to be asked so? Otherwise saying "I've never been asked" sounds like a common thing for most people.
          1. jimt1234 · · focus · HN ↗
            What's the BFD? I have nothing to hide! (I hear that shit all the time. So annoying.)
          2. jstanley · · focus · HN ↗
            Reading this kind of stuff online made me afraid of international travel for many years. When I finally did it literally nothing happened to me.

            Yes it's bad that the government overreaches, but it is also bad for your mental health to worry about it.

            1. UpsideDownRide · · focus · HN ↗
              It's even worse for your mental to never think about It.
            2. simiones · · focus · HN ↗
              It's important to separate what can happen from what will happen.

              The majority of people walking in the worse neighborhoods of LA or Chicago never have a single crime happen to them. But that doesn't mean that it's safe to go in a bad neighborhood - and it really doesn't mean it's safe to go there wearing designer clothing, gold watches, diamond rings and wearing your Apple VR device.

              The same is true for travel. It's perfectly safe for the vast majority - but it's very important to be aware what may make you a target and what can happen to you if you are. Tens of millions of people visit the UK or China every year with no incident. But if you're a public active supporter of Palestine Action, or an active demonstrator against the CCCP respectively, be aware that you personally face a real risk from this travel, and your devices are actually very likely to be searched at those borders. Vice versa though (anti-CCCP activist traveling to UK, PA activist traveling to China) is perfectly safe, though.

              1. Liftyee · · focus · HN ↗
                Last time I checked, the Soviet Union was dissolved.

                (CCCP = Union of Soviet Socialist Republics...)

                1. simiones · · focus · HN ↗
                  Oops, should have said CCP, not CCCP.

                  Though I should note that this would be the "SSSR" since I was clearly using the latin alphabet, even if I had chosen to use the Russian name of the USSR.

            3. bryceacc · · focus · HN ↗
              this sounds exactly like the chilling effect and fear the US government wants to instill on people these days. They want us to know big brother is watching, they have the power to stop and search you, and you can't do anything about it
        3. [deleted] · · focus · HN ↗

          [deleted]

        4. bryceacc · · focus · HN ↗
          <a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;tech-policy&#x2F;2026&#x2F;09&#x2F;immigration-advocate-sues-border-agents-for-demanding-his-cell-phone&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;tech-policy&#x2F;2026&#x2F;09&#x2F;immigration-advo...

          &gt;CBP only searched the electronic devices of 55,318 international travelers,” the agency wrote, or 0.0013%.

          would suck to be one of those 55 thousand people. I&#x27;ve never been bitten by a shark but I sure care about people that have?

        5. serf · · focus · HN ↗
          I get asked to unlock my dev laptop every single time I go from the US to Montreal. The TSA person sits there and waits for my WM to boot before waving me past.

          It seems more like they&#x27;re trying to determine that it is in fact a laptop and not something resembling one.

          1. dylan604 · · focus · HN ↗
            That&#x27;s been my experience as well. I&#x27;ve visited Sydney twice, and both times I&#x27;ve been asked to light up my devices. Granted, I was on work trips requiring three separate laptops which does probably look suspect, but once they were booted they did not request to browse anything and were satisfied to see them working.
            1. 0cf8612b2e1e · · focus · HN ↗
              All the more reason to dual boot into a decoy OS. Does not stop a targeted investigation, but lets you pass a cursory examination where some thug might want to rifle through your data.

              Edit: now I am gleefully thinking about how I would craft my decoy desktop persona. What gives me the most effective non interesting profile.

          2. matheusmoreira · · focus · HN ↗
            Now I&#x27;m wondering what exactly they&#x27;re looking for... What else could those devices have been?
            1. 0cf8612b2e1e · · focus · HN ↗
              Maybe the agent gets lucky and you have a folder full of nudes on the desktop.
            2. wildzzz · · focus · HN ↗
              They are looking to see if you&#x27;ve gutted a laptop and filled it with explosives or drugs. Although tbh, a computer that can launch a desktop doesn&#x27;t need much physical space and the battery just has to last long enough for a cursory glance.
          3. folmar · · focus · HN ↗
            In EU normally BIOS startup screen is the point at which they wave it as ok.
            1. LorenPechtel · · focus · HN ↗
              I&#x27;ve only had it a couple of times, BIOS was enough. Very good as the battery in that machine was shot and it couldn&#x27;t actually boot. (I always used it plugged in, it wasn&#x27;t worth the cost to fix.)
          4. sellmesoap · · focus · HN ↗
            Might also be documenting serial number and identifying radios associated with your device. As a dragnet etc. Palantir and co love them some massive data hoards!
        6. Havoc · · focus · HN ↗
          Dismissing something as false just because you haven’t personally experienced it is quite something
          1. jstanley · · focus · HN ↗
            &quot;If you travel abroad you must unlock&quot; is hardly the central experience. It is FUD.
            1. Havoc · · focus · HN ↗
              No, it&#x27;s just incredibly bad reasoning. I&#x27;ve not been in a car crash yet, but I don&#x27;t conclude that therefore talk of road safety is FUD.
              1. jstanley · · focus · HN ↗
                The fact that car crashes are possible does not mean you&#x27;re going to have a car crash every time you get in a car though? Suggesting that you are is FUD.
        7. FireBeyond · · focus · HN ↗
          TSA thought it odd that I had two MBPs (work and personal) and an iPad in my carry on, and asked me to power up all three.
          1. encrypted_bird · · focus · HN ↗
            What is an MBP?
            1. FireBeyond · · focus · HN ↗
              MacBook Pro.
      3. eli · · focus · HN ↗
        That’s not the full story and not really correct.

        <a href="https:&#x2F;&#x2F;www.aclu.org&#x2F;news&#x2F;privacy-technology&#x2F;can-border-agents-search-your-electronic" rel="nofollow">https:&#x2F;&#x2F;www.aclu.org&#x2F;news&#x2F;privacy-technology&#x2F;can-border-agen...

    2. jstanley · · focus · HN ↗
      It seems foolhardy to carry your life savings around everywhere, encrypted or not.

      If you really want to keep this stuff on a phone at least stretch to a second phone and keep it somewhere safe.

      1. devin · · focus · HN ↗
        or a separate hard drive in a fireproof safe or something.
      2. ryandrake · · focus · HN ↗
        Exactly. Don&#x27;t keep your life on your phone. We shouldn&#x27;t have to take these precautions but unfortunately we do.
        1. Razengan · · focus · HN ↗
          What if everyone at the airport or border stood together and refused to comply?
          1. brokenmachine · · focus · HN ↗
            Nobody makes their flight.
    3. WithinReason · · focus · HN ↗
      If you don&#x27;t give access to law enforcement when they ask: straight to jail. Encryption is irrelevant in that situation. If they see the encrypted volume you need to provide them access.
      1. ChrisMarshallNY · · focus · HN ↗
        Classic $5 wrench.

        Having thugs on speed dial opens a lot of doors.

      2. rdevsrex · · focus · HN ↗
        Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.

        Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.

        1. DaveSchmindel · · focus · HN ↗
          That&#x27;s been my understanding until now as well... the latest on the case against Samuel Tunick has me worried and second guessing that blanket statement though...

          <a href="https:&#x2F;&#x2F;nccriminallaw.sog.unc.edu&#x2F;2026&#x2F;08&#x2F;03&#x2F;giving-police-a-duress-code-instead-of-a-passcode-to-a-phone&#x2F;" rel="nofollow">https:&#x2F;&#x2F;nccriminallaw.sog.unc.edu&#x2F;2026&#x2F;08&#x2F;03&#x2F;giving-police-a...

          1. delichon · · focus · HN ↗
            Yeah, if you use it as a way to destroy data that gives them a whole new and powerful attack vector. 18 U.S.C. § 2232 is very broad.
            1. Razengan · · focus · HN ↗
              What&#x27;s more infuriating than laws like that is that there&#x27;s a class of people completely immune to those laws.
          2. simiones · · focus · HN ↗
            That&#x27;s completely different. Pleading the 5th and not testifying is completely different from giving false testimony - which is never protected. Even in a trial, if you are asked under oath if you handled the body, you are allowed to say that you invoke your 5th amendment rights not to respond; but you are not allowed to say &quot;no, I didn&#x27;t&quot; if in fact you did (you can later be accused of perjury in addition to your conviction).
          3. rtkwe · · focus · HN ↗
            That case has the specific, very important, wrinkle that he provided a _destructive_ duress code, he could have continued to refuse to provide the unlock code just fine legally. It&#x27;s the use of the duress code that is likely going to be getting him in trouble and that falls outside of the existing defined protections about being compelled to unlock safes&#x2F;computers etc containing possible evidence against yourself.

            We&#x27;ll have to see how that case goes but ultimately the reason he&#x27;s getting in trouble is only tangentially related to his phone being encrypted. It&#x27;s more correct to think of it like he smashed the phone to pieces (and imagine this definitively destroys the data for the sake of the metaphor) instead of it being about the encryption itself.

            1. LoganDark · · focus · HN ↗
              He didn&#x27;t smash the phone to pieces, he gave LE a hammer and they smashed the phone to pieces. It&#x27;s entirely LE&#x27;s own fault this happened -- they shouldn&#x27;t have been trying to get into that phone, and it&#x27;s their own fault it went wrong.

              Though I would expect courts to consider that he knew LE planned to enter the provided PIN, and that the duress PIN would then result in the phone being wiped, and therefore accuse him of doing the wiping anyway.

              But I don&#x27;t think it&#x27;s this guy&#x27;s fault at all. LE is the one who asked him under duress, he easily could&#x27;ve feared for his life, and he did no direct harm. It was self-defense at worst.

              1. someothherguyy · · focus · HN ↗
                &gt; He didn&#x27;t smash the phone to pieces, he gave LE a hammer and they smashed the phone to pieces. It&#x27;s entirely LE&#x27;s own fault this happened -- they shouldn&#x27;t have been trying to get into that phone, and it&#x27;s their own fault it went wrong.

                Setting a booby trap to destroy evidence that then gets destroyed when that trap is triggered is the same as destroying evidence. This is common sense, but also see <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Principal_(criminal_law)" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Principal_(criminal_law)

              2. rtkwe · · focus · HN ↗
                That&#x27;s too cute by half for the law, this kind of &quot;I&#x27;m not touching you&quot; argument comes up each time and it just doesn&#x27;t work. The guy intentionally provided the code knowing it would destroy the &quot;evidence&quot;&#x2F;contents of his phone if they entered it, it&#x27;s clear what his intent was and the data would not have been destroyed if he did not take that action. The minor separation that he did not enter the code himself is highly unlikely to protect him in this case.

                It&#x27;s been a weakness in destructive duress codes since their inception.

          4. [deleted] · · focus · HN ↗

            [deleted]

        2. glitchc · · focus · HN ↗
          &gt; The Fifth Amendment protects against self-incrimination.

          You can still be held in custody for obstruction of justice:

          <a href="https:&#x2F;&#x2F;www.findlaw.com&#x2F;legalblogs&#x2F;third-circuit&#x2F;man-held-in-contempt-for-refusing-to-unlock-devices-in-child-porn-case&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.findlaw.com&#x2F;legalblogs&#x2F;third-circuit&#x2F;man-held-in...

          It took four years before he could secure his release:

          <a href="https:&#x2F;&#x2F;www.sophos.com&#x2F;en-us&#x2F;blog&#x2F;suspect-who-refused-to-decrypt-hard-drives-released-after-four-years" rel="nofollow">https:&#x2F;&#x2F;www.sophos.com&#x2F;en-us&#x2F;blog&#x2F;suspect-who-refused-to-dec...

        3. izacus · · focus · HN ↗
          Self-incrimination yes, but not for cases when the person compelled has evidence to incriminate another process in a case.
          1. roncesvalles · · focus · HN ↗
            That being said, overlap protects you still. So if answering a question about another person might incriminate you, you don&#x27;t have to answer.
        4. rdtsc · · focus · HN ↗
          Can&#x27;t they just hand it to you say &quot;you enter your passphrase, but don&#x27;t divulge it to us and then hand us the phone&quot;. In other words hinging the passphrase divulging to the 5th can backfire in that respect. It like saying we have a search warrant, you open the safe for us, it&#x27;s fine if you keep the combination to yourself, we just need to get inside.
          1. nater5000 · · focus · HN ↗
            No, that&#x27;s pretty absurd. It&#x27;s not specifically about the act of speaking. It&#x27;s the act of incriminating yourself.

            But that&#x27;s all beyond the point, anyways. If they did hand you your phone and said, &quot;enter your passphrase,&quot; you can just say, &quot;I don&#x27;t remember it.&quot; They can throw a fit and put more heat on you in various ways, but until they resort to torturing you or they develop mind-reading technology, there&#x27;s not much they can do at that point until the case reaches a judge.

            That&#x27;s not to say &quot;I don&#x27;t remember&quot; is a sound, blanket defense. But it&#x27;s sufficient for demonstrating that these dynamics all depend on willing participants which is partially why these laws are designed the way they are.

            1. rdtsc · · focus · HN ↗
              If the search warrant and seizure wasn&#x27;t a thing I&#x27;d agree with you. But I can easily see opening a phone interpreted not that differently than opening a safe or your reinforced front door.

              &gt; But it&#x27;s sufficient for demonstrating that these dynamics all depend on willing participants which is partially why these laws are designed the way they are.

              What happens if during serving a search warrant the door is impossible to open or they find a super reinforced safe. Owner can even say &quot;I don&#x27;t remember the combination&quot;?

              1. sterlind · · focus · HN ↗
                I&#x27;m not sure the police can compel you to open a safe. they can get a warrant to have someone weld it open with a blowtorch, but I don&#x27;t think they can get a warrant to compel you to open your own safe for them.
          2. kadoban · · focus · HN ↗
            The act of unlocking it can incriminate you. It&#x27;s ~proof that you have control of the device beyond what they already knew.
        5. midas89 · · focus · HN ↗
          you have the guy sitting in jail waiting for the courts to decide if his grapheneOS wiping his computer after wrong unlock codes is him obstructing.

          keep in mind that the &quot;obstruction&quot; charge can be and is abused as a catchall charge.

          1. MC995 · · focus · HN ↗
            &gt; courts to decide if his grapheneOS wiping his computer after wrong unlock codes is him obstructing

            He didn&#x27;t provide an incorrect code, or no code at all, he provided a duress code intended to destroy the device. There&#x27;s a huge legal difference.

        6. nikanj · · focus · HN ↗
          The fifth amendment doesn&#x27;t do jack shit if they haul you away. After a few years of trials and appeals you might regain your freedom.
        7. wslh · · focus · HN ↗
          I think that the issue is that the law enforcement personnel could make you pass a bad time even if it&#x27;s covered by the Fifth Amendment. The enforcement could be later than the arbitrary decision.
        8. BeetleB · · focus · HN ↗
          He said &quot;jail&quot;, not &quot;prison&quot;.

          There&#x27;s a difference.

        9. throw0101c · · focus · HN ↗
          &gt; Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.

          SCOTUS: Hold my beer…

          :)

      3. gonzalohm · · focus · HN ↗
        So if an app installs an encrypted volume for which you don&#x27;t have the password to, you go to jail? That doesn&#x27;t make sense. How can they know if I have the password or not
        1. wahern · · focus · HN ↗
          They can&#x27;t know, they infer. AFAIU, normally they just detain you at the airport and harass you to try to break you. To jail you they&#x27;re technically supposed to be confident enough about you knowing the password to be able to charge you with a crime (presumably something like obstruction, possibly specific to immigration law, otherwise right against self-incrimination might prevent a conviction on failure to disclose alone), or have other evidence of some other crime. Then you end up in the legal system, where courts handle due process and a judge, preliminarily, and then a judge or jury decides if you knew the password.

          Note that the recent high-profile case of a man being jailed involved him refusing to decrypt, rather than claiming he didn&#x27;t know. He was deliberately trying to test the law regarding the permissible scope of inspection of digital data, to force the matter into the courts so the issues could be litigated in a controlled context untainted by other potential crimes; being arrested and charged was part of his plan.

      4. spl757 · · focus · HN ↗
        Precisely, unless there is plausible deniability that a blob of data is indeed an encrypted file they can just hold you in jail until you comply. There are encryption schemes that provide plausible deniability, but implementing would probably not be trivial.
    4. Cider9986 · · focus · HN ↗
      It would seem wise to at least keep a backup in an E2EE cloud [1]. This could possibly allow you to not give access even if legally compelled.

      &gt;As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

      Yes, it seems that way in the US: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49922513">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49922513

      If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.

      [1] <a href="https:&#x2F;&#x2F;www.privacyguides.org&#x2F;en&#x2F;cloud&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.privacyguides.org&#x2F;en&#x2F;cloud&#x2F;

      1. 0x262d · · focus · HN ↗
        Yeah, getting all your sensitive stuff off your phone onto a secure cloud service seems like the obvious approach here right? They can still escalate what they try to coerce you to do, but they don&#x27;t have physical access to your data just by taking your phone, and you can also leave the phone with them and only lose the device if needed. In my likely scenario - innocent traveler, they aren&#x27;t looking for anything specific, but I still don&#x27;t want them to look through my files and photos just because I happen to travel internationally - that seems like it puts it out of reach (and out of obvious view) for now.
    5. mmooss · · focus · HN ↗
      It seems to me you are taking a big risk. Some considerations:

      &gt; Cryptomator

      Much security is poorly implemented; you can&#x27;t count on it being effective. Even Apple, which takes security very seriously and has world-class talent and enormous resources, fails to implement security effectively sometimes (as in the OP). Can Cryptomator do better? Find the most respected - by professionals - security solution you can.

      And on a device with many other functions - all the things you use your phone for - you risk all sorts of security holes in every function of app you use. And what happens to the data when your phone is backed up? Store the data on a single-purpose device.

      Also, on an Internet-connected device, you make the data potentially accessible to the entire Internet. Use offline storage.

      Bringing the storage device with you everywhere is asking for a mistake on your part - losing it, etc. Hide it someplace.

      &gt; or legal access

      Ask a lawyer.

    6. fragmede · · focus · HN ↗
      Oh my god, get out of crypto. Put your money into a bank instead of trying to one-man-army yourself into being Fort Knox.
      1. tenacious_tuna · · focus · HN ↗
        Cryptomator appears to be a file encryption tool, not a cryptocoin anything. What&#x27;re you reacting to?
        1. fragmede · · focus · HN ↗
          I made the leap based on

          &gt; could cost me my home and life savings

          but it&#x27;s entirely fair to point out that Cryptomator itself is not a crypto wallet. I just know too many people irl that have lost thousands of dollars because they lost crypto private keys.

    7. BeetleB · · focus · HN ↗
      &gt; I keep all of my most sensitive personal documents on my phone

      Why...?

      If I had anything I didn&#x27;t want the authorities to get, I&#x27;d remove it from my phone before travel (e.g. put in cloud, etc).

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.