Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones
Unofficial Hacker News client; not affiliated with Y Combinator.
Cider9986 · · focus · HN ↗
GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.
On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.
If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.
[1] <a href="https://strongphrase.net" rel="nofollow">https://strongphrase.net give memorable ones which is cool.
23ahGa17 · · focus · HN ↗
Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.
Cider9986 · · focus · HN ↗
Yes this is of course safer. What evidence do you have that it doesn't work on GrapheneOS, though?
<a href="https://www.computerweekly.com/feature/Journalist-Richard-Medhurst-had-his-mobile-phone-seized-Did-using-a-secure-phone-protect-his-data" rel="nofollow">https://www.computerweekly.com/feature/Journalist-Richard-Me...
1298436 · · focus · HN ↗
stefan_ · · focus · HN ↗
Someone · · focus · HN ↗
“The Great Firewall operates by checking transmission control protocol (TCP) packets for keywords or sensitive words. If the keywords or sensitive words appear in the TCP packets, access will be closed. If one link is closed, more links from the same machine will be blocked by the Great Firewall. The effect includes: limiting access to foreign information sources, blocking popular foreign websites and mobile apps, and requiring foreign companies to adapt to domestic regulations. Due to the Great Firewall, China has one of the lowest cross-border internet traffic rates in the world. Usage of foreign apps in China is minuscule; Asia Society estimated in 2026 that foreign apps blocked by the Great Firewall have extremely low traffic, particularly compared to domestic apps; the top five domestic apps saw traffic that was 1,000 times more than the top five foreign apps.”
oasisaimlessly · · focus · HN ↗
wat10000 · · focus · HN ↗
When I was there last year, it took some doing to get a VPN working. Mullvad was pretty good but it would take a few tries to find an endpoint I could connect to. The simplest escape hatch is to have a cellular connection from another country, but that's either expensive or slow.
alkh-qrt · · focus · HN ↗
gambiting · · focus · HN ↗
Edit: Just to be perfectly clear - Border Force in the UK can do the exact same thing to you once you return, British citizen or not. Leaving your device at home is still the safest choice.
Cider9986 · · focus · HN ↗
> Despite all the nonsense that's posted about UK on the internet
How is it nonsense? I'm not debating the warrant thing, but it's very reasonable to assume the UK has terrible protections for these sorts of things.
<a href="https://en.wikipedia.org/wiki/Key_disclosure_law#:~:text=United%20Kingdom,edit" rel="nofollow">https://en.wikipedia.org/wiki/Key_disclosure_law#:~:text=Uni...
<a href="https://eylenburg.github.io/countries.htm" rel="nofollow">https://eylenburg.github.io/countries.htm
gambiting · · focus · HN ↗
And yes, UK has some awful laws around this. Yes it has put people in jail just for planning a protest before. Yes you can go to jail for not disclosing your passwords. But what you read on the internet is almost laughably out of proportion - no, you won't get arrested for posting a meme about the king.
dmitrygr · · focus · HN ↗
Might it "seem" that way because it is that way?
<a href="https://www.forbes.com/sites/steveforbes/2025/09/09/people-are-being-thrown-in-uk-prisons-over-what-theyve-said-online-can-free-speech-be-saved/" rel="nofollow">https://www.forbes.com/sites/steveforbes/2025/09/09/people-a...
<a href="https://www.telegraph.co.uk/news/2026/08/22/britain-has-become-a-surveillance-state-and-its-not-making/" rel="nofollow">https://www.telegraph.co.uk/news/2026/08/22/britain-has-beco...
<a href="https://freespeechunion.org/news/more-than-62-000-people-have-been-arrested-for-speech-offences-over" rel="nofollow">https://freespeechunion.org/news/more-than-62-000-people-hav...
Oh, and your government itself openly states it on record, too: <a href="https://hansard.parliament.uk/lords/2025-07-17/debates/F807CB70-D90D-4A19-9433-99539B7CF21F/OnlineCommunicationOffenceArrests" rel="nofollow">https://hansard.parliament.uk/lords/2025-07-17/debates/F807C...
gambiting · · focus · HN ↗
Not that this is some kind of great bar to clear, but if you're going to argue with what I said, argue with what I actually wrote.
dmitrygr · · focus · HN ↗
Clearly the point is clear. Why nitpick pointlessly?
gambiting · · focus · HN ↗
Someone above asked me how it was nonsense. I responded that people parotting the point about getting arrested for criticising the king is nonsense - like for instance, my American coworkers asking if that's true, because they read it somewhere on the internet. That is nonsense.
If you want to argue with this point please do, but also please observe the rest of my comment and especially the parts that I haven't actually said.
subscribed · · focus · HN ↗
6 people got arrested for trying to say "Not my king!" BEFORE his coronation: <a href="https://londondaily.com/not-my-king-anti-monarchy-protesters-arrested-during-uk-coronation" rel="nofollow">https://londondaily.com/not-my-king-anti-monarchy-protesters...
Before they had a chance of protest. After months of discussing the planned protest in details and getting a green light from the Met Police: <a href="https://www.bbc.co.uk/news/uk-65542558" rel="nofollow">https://www.bbc.co.uk/news/uk-65542558
52 people were arrested DURING the coronation, for example for holding a placard "not my king": <a href="https://londondaily.com/over-52-anti-monarchy-protestors-arrested-during-king-charles-coronation" rel="nofollow">https://londondaily.com/over-52-anti-monarchy-protestors-arr...
Police arrested despite KNOWING it's the member of public doesn't commit any offence: <a href="https://novaramedia.com/2025/03/11/police-officer-who-arrested-anti-monarchy-protester-was-aware-no-offence-had-been-committed/" rel="nofollow">https://novaramedia.com/2025/03/11/police-officer-who-arrest...
I'm afraid you unwittingly misled your coworkers.
gambiting · · focus · HN ↗
Dylan16807 · · focus · HN ↗
subscribed · · focus · HN ↗
>> Someone above asked me how it was nonsense. I responded that people parotting the point about getting arrested for criticising the king is nonsense
Protesting against the king is criticising the king IMO. I didn't see his quantifier, since I would agree that online critique of the king in particular is not yet penalised.
Not surprising you're implying bad faith though, if we're splitting the hair this thin.
(and this specific planning of the protest was so heavy handed, because it belong to one of the two naughty protests, environmental. The second naughty one is protesting against the genocide. The rest is okay)
Dylan16807 · · focus · HN ↗
It's in the original comment you responded to, and it's a critical part of the conversation chain.
"And yes, UK has some awful laws around this. Yes it has put people in jail just for planning a protest before. Yes you can go to jail for not disclosing your passwords. But what you read on the internet is almost laughably out of proportion - no, you won't get arrested for posting a meme about the king."
I'm not saying bad faith, I'm saying you misread their argument pretty badly.
Your citations support the problems they already admitted. The hair was split before you got here because they're distinguishing in-person and online actions.
2ahg7 · · focus · HN ↗
You can use other European countries like The Netherlands, which is a lawless police state with a liberal cover, as well.
gambiting · · focus · HN ↗
nostrademons · · focus · HN ↗
subscribed · · focus · HN ↗
6 people got arrested for trying to say "Not my king!" BEFORE his coronation: <a href="https://londondaily.com/not-my-king-anti-monarchy-protesters-arrested-during-uk-coronation" rel="nofollow">https://londondaily.com/not-my-king-anti-monarchy-protesters...
Before they had a chance of protest. After months of discussing the planned protest in details and getting a green light from the Met Police: <a href="https://www.bbc.co.uk/news/uk-65542558" rel="nofollow">https://www.bbc.co.uk/news/uk-65542558
It's not like Republicans in the UK are a violent group, unlike far right coddled by the same Met police.
52 people were arrested DURING the coronation, for example for holding a placard "not my king": <a href="https://londondaily.com/over-52-anti-monarchy-protestors-arrested-during-king-charles-coronation" rel="nofollow">https://londondaily.com/over-52-anti-monarchy-protestors-arr...
Police arrested despite KNOWING it's baseless and frankly illegal: <a href="https://novaramedia.com/2025/03/11/police-officer-who-arrested-anti-monarchy-protester-was-aware-no-offence-had-been-committed/" rel="nofollow">https://novaramedia.com/2025/03/11/police-officer-who-arrest...
Tell me some more how it isn't arresting for criticising the king. Oh, well, technically he wasn't a king yet.... but that's even worse to be fair.
[deleted] · · focus · HN ↗
[deleted]
markus_zhang · · focus · HN ↗
ryandrake · · focus · HN ↗
altruios · · focus · HN ↗
midas89 · · focus · HN ↗
smuhakg · · focus · HN ↗
Adding the USA to the list of countries where this is done would increase costs but it wouldn't be some nightmarish unprecedented problem.
markus_zhang · · focus · HN ↗
3128128 · · focus · HN ↗
Perhaps the reflexive genius downvoters can explain what happened to Richard Medhurst? After his phone was snatched and the authorities pretended not to be able to decrypt it, he went on a GrapheneOS promotion spree on X and wanted to write a book about computer security.
Now he has disappeared for nearly 6 weeks. How many more people do you want to get in trouble with your false promises?
prmoustache · · focus · HN ↗
Shutting it down won't help if you are forced by law to give out the password, which is the case in more and more countries.
dylan604 · · focus · HN ↗
Why do you call out just one OS? It's a good idea for any OS.
Cider9986 · · focus · HN ↗
GrapheneOS allows using a passphrase with more convenience because of the fingerprint plus second factor pin (I don't think you can just have a pin as a secondary unlock). You don't need to enter the passphrase every time you unlock with this setup, only when first starting up.
The official opinion: <a href="https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=by%3Agrapheneos%20passphrase%20rate%20limit&sort=byDate&type=comment" rel="nofollow">https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
rtkwe · · focus · HN ↗
dylan604 · · focus · HN ↗
rtkwe · · focus · HN ↗
<a href="https://threecats.au/two-factor-pin-fingerprint-unlock-grapheneos" rel="nofollow">https://threecats.au/two-factor-pin-fingerprint-unlock-graph...
dataflow · · focus · HN ↗
rtkwe · · focus · HN ↗
subscribed · · focus · HN ↗
iamnothere · · focus · HN ↗
fluidcruft · · focus · HN ↗
cj · · focus · HN ↗
theendisney · · focus · HN ↗
Extra points if you hold you face really close and count in a dead language. You can also make ordered hand gestures in stead of counting on your fingers. Be a wizard about it!
cheschire · · focus · HN ↗
Brybry · · focus · HN ↗
Is that actually better (in practice, not in terms of entropy) than /dev/urandom? I have a lot less trust in my ability to successfully scrub a picture from my phone that deterministically created my passphrase.
lisper · · focus · HN ↗
It offers protection in the event that your /dev/urandom is compromised. Otherwise no.
(Of course, if your /dev/urandom is compromised then whatever process you use to compute a hash of a photo is likely compromised as well.)
Matumio · · focus · HN ↗
NetMageSCW · · focus · HN ↗
manwe150 · · focus · HN ↗
theendisney · · focus · HN ↗
heelix · · focus · HN ↗
throw0101c · · focus · HN ↗
Or on the CLI:
* <a href="https://packages.debian.org/search?keywords=diceware" rel="nofollow">https://packages.debian.org/search?keywords=diceware
* <a href="https://packages.debian.org/search?keywords=pwgen" rel="nofollow">https://packages.debian.org/search?keywords=pwgen
busssard · · focus · HN ↗
iamnothere · · focus · HN ↗
busssard · · focus · HN ↗
fluidcruft · · focus · HN ↗
eli · · focus · HN ↗
isoprophlex · · focus · HN ↗
dessimus · · focus · HN ↗
olyjohn · · focus · HN ↗
83 · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
LorenPechtel · · focus · HN ↗
Telaneo · · focus · HN ↗
hulitu · · focus · HN ↗
nkrisc · · focus · HN ↗
sellmesoap · · focus · HN ↗
usern20260720 · · focus · HN ↗
NetMageSCW · · focus · HN ↗
Telaneo · · focus · HN ↗
dzhiurgis · · focus · HN ↗
ssl-3 · · focus · HN ↗
It'd work like this: Unlock phone, plug in USB widget; it works.
Or: Plug in USB widget without first unlocking phone; phone shuts down.
fluidcruft · · focus · HN ↗
I just wonder whether that could be too annoying for Android Auto / Car Play. But to be fair wireless is an option.
The other downside I guess is that a thief would just plug a USB drive in to disable device tracking. But they could just wrap the damn thing in foil so dunno if that should matter.
ssl-3 · · focus · HN ↗
And by that I mean, using the database itself is simple. But when it exists, then a list of targets for an attacker to emulate also exists.
Those boys at Cellebrite aren't dummies, at all, and they've been doing this stuff for quite a long time. They're a formidable opponent.
We used to use their kit to clone personal data between very different devices back in the dumb phone days. They were the only ones to get it right out of a sea of others that were also evaluated.
ssl-3 · · focus · HN ↗
When the usual manufacturer-prescribed method for reading contacts said to take some long-winded steps to put the phone into a special mode, Cellebrite's hardware just usually skipped that shit and read the data very directly without any fuss.
Plug it in, push the button, and the Cellebrite box just did the appropriate magic. It then interpreted the data and munged it into a useful form to shove into the next phone.
After that: The recovered personal data was pushed right up into the ass of the next phone with the same lack of consent. It was succinct and brutal in operation.
And: It worked. It was so dead-nuts simple that a cell phone salesperson could run it with ease. I stopped getting phone calls from the field about transfer problems when we started using Cellebrite kit.
Nothing else did this stuff with that measure of resolute nonchalance.
So at this point they've been uniquely hooning with cell phones for decades. It's kind of their schtick.
If we can speculate that something like the the USB-C charge rate negotiation on a given phone can open a pathway into the system, then it can be safe to say that Cellebrite is already using that method to get things done -- and that a person at the border can exploit it even if they're "not a tech person".
Simplifying these kinds of hacks is what they do.
yencabulator · · focus · HN ↗
Recognize USB devices by serial numbers, not the manufacturer ID. Even if they could get their hands on the serial number of my car stereo, that's going to be after the same warrant delay this thing protects against.
ssl-3 · · focus · HN ↗
The lot they tracked you going into? The lot that gets scanned by mobile ALPRs on the regular?
Yeah, so. About that... :-/
burningChrome · · focus · HN ↗
Unless you have a 4 or 4XL which are pretty popular with graphene os users. The weird thing is the 4 and 4XL are the only models without fingerprint because Google was pushing its #D Face Unlock System at the time.
The funny part is Graphene by default now disables face unlock on newer Pixel models.
NetMageSCW · · focus · HN ↗