‹ BackHN Continuity

Thread

Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones

287 points · 226 comments · speckx

  1. Cider9986 · · focus · HN ↗
    For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.

    GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.

    On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.

    If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.

    [1] <a href="https:&#x2F;&#x2F;strongphrase.net" rel="nofollow">https:&#x2F;&#x2F;strongphrase.net give memorable ones which is cool.

    1. 23ahGa17 · · focus · HN ↗
      People believed the reboot feature last time GrapheneOS was mentioned. It is of course nonsense.

      Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.

      1. Cider9986 · · focus · HN ↗
        &gt; Shut down the phone in areas with a high snatch risk.

        Yes this is of course safer. What evidence do you have that it doesn&#x27;t work on GrapheneOS, though?

        <a href="https:&#x2F;&#x2F;www.computerweekly.com&#x2F;feature&#x2F;Journalist-Richard-Medhurst-had-his-mobile-phone-seized-Did-using-a-secure-phone-protect-his-data" rel="nofollow">https:&#x2F;&#x2F;www.computerweekly.com&#x2F;feature&#x2F;Journalist-Richard-Me...

        1. 1298436 · · focus · HN ↗
          Medhurst has no evidence that it worked either. He hasn&#x27;t tweeted since August 24th, I hope he is well and at liberty.
      2. stefan_ · · focus · HN ↗
        The internet exists and can transfer your data with no customs and borders, so if you are at risk of being snatched, the correct choice is to not carry a phone (or laptop, or..) at all.
        1. Someone · · focus · HN ↗
          <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Great_Firewall" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Great_Firewall:

          “The Great Firewall operates by checking transmission control protocol (TCP) packets for keywords or sensitive words. If the keywords or sensitive words appear in the TCP packets, access will be closed. If one link is closed, more links from the same machine will be blocked by the Great Firewall. The effect includes: limiting access to foreign information sources, blocking popular foreign websites and mobile apps, and requiring foreign companies to adapt to domestic regulations. Due to the Great Firewall, China has one of the lowest cross-border internet traffic rates in the world. Usage of foreign apps in China is minuscule; Asia Society estimated in 2026 that foreign apps blocked by the Great Firewall have extremely low traffic, particularly compared to domestic apps; the top five domestic apps saw traffic that was 1,000 times more than the top five foreign apps.”

          1. oasisaimlessly · · focus · HN ↗
            The Great Firewall doesn&#x27;t restrict SSH, so you can functionally ignore it (assuming using e.g. `ssh -D` is second-nature to you).
            1. wat10000 · · focus · HN ↗
              Last time I tried it (which was quite a while ago, but I&#x27;d be surprised if they became less restrictive) ssh was fine for interactive use, but they did some sort of traffic analysis to kill connections that got used for tunneling other traffic like that.

              When I was there last year, it took some doing to get a VPN working. Mullvad was pretty good but it would take a few tries to find an endpoint I could connect to. The simplest escape hatch is to have a cellular connection from another country, but that&#x27;s either expensive or slow.

        2. alkh-qrt · · focus · HN ↗
          If you live in the UK and travel to the US and are afraid of state actors, leaving your hardware at home seems like a bad idea, too.
          1. gambiting · · focus · HN ↗
            Despite all the nonsense that&#x27;s posted about UK on the internet, British agencies do require a warrant to enter your home. TSA on the other hand does not require a court order to confiscate and mirror your device before giving it back to you.

            Edit: Just to be perfectly clear - Border Force in the UK can do the exact same thing to you once you return, British citizen or not. Leaving your device at home is still the safest choice.

            1. Cider9986 · · focus · HN ↗
              I believe it&#x27;s CBP that does this, not TSA. Therefore Americans don&#x27;t have to worry about it during domestic flights.

              &gt; Despite all the nonsense that&#x27;s posted about UK on the internet

              How is it nonsense? I&#x27;m not debating the warrant thing, but it&#x27;s very reasonable to assume the UK has terrible protections for these sorts of things.

              <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Key_disclosure_law#:~:text=United%20Kingdom,edit" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Key_disclosure_law#:~:text=Uni...

              <a href="https:&#x2F;&#x2F;eylenburg.github.io&#x2F;countries.htm" rel="nofollow">https:&#x2F;&#x2F;eylenburg.github.io&#x2F;countries.htm

              1. gambiting · · focus · HN ↗
                I mean in a broad sense if you read any news about the UK it might looks like a dystopian surveillance state where you get arrested for criticising the king(I kid you not - I&#x27;ve had multiple American coworkers ask me if this is true).

                And yes, UK has some awful laws around this. Yes it has put people in jail just for planning a protest before. Yes you can go to jail for not disclosing your passwords. But what you read on the internet is almost laughably out of proportion - no, you won&#x27;t get arrested for posting a meme about the king.

                1. dmitrygr · · focus · HN ↗
                  &gt; news about the UK it might looks like a dystopian surveillance state where you get arrested for criticising

                  Might it &quot;seem&quot; that way because it is that way?

                  <a href="https:&#x2F;&#x2F;www.forbes.com&#x2F;sites&#x2F;steveforbes&#x2F;2025&#x2F;09&#x2F;09&#x2F;people-are-being-thrown-in-uk-prisons-over-what-theyve-said-online-can-free-speech-be-saved&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.forbes.com&#x2F;sites&#x2F;steveforbes&#x2F;2025&#x2F;09&#x2F;09&#x2F;people-a...

                  <a href="https:&#x2F;&#x2F;www.telegraph.co.uk&#x2F;news&#x2F;2026&#x2F;08&#x2F;22&#x2F;britain-has-become-a-surveillance-state-and-its-not-making&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.telegraph.co.uk&#x2F;news&#x2F;2026&#x2F;08&#x2F;22&#x2F;britain-has-beco...

                  <a href="https:&#x2F;&#x2F;freespeechunion.org&#x2F;news&#x2F;more-than-62-000-people-have-been-arrested-for-speech-offences-over" rel="nofollow">https:&#x2F;&#x2F;freespeechunion.org&#x2F;news&#x2F;more-than-62-000-people-hav...

                  Oh, and your government itself openly states it on record, too: <a href="https:&#x2F;&#x2F;hansard.parliament.uk&#x2F;lords&#x2F;2025-07-17&#x2F;debates&#x2F;F807CB70-D90D-4A19-9433-99539B7CF21F&#x2F;OnlineCommunicationOffenceArrests" rel="nofollow">https:&#x2F;&#x2F;hansard.parliament.uk&#x2F;lords&#x2F;2025-07-17&#x2F;debates&#x2F;F807C...

                  1. gambiting · · focus · HN ↗
                    How many of those people got arrested for criticising the king?

                    Not that this is some kind of great bar to clear, but if you&#x27;re going to argue with what I said, argue with what I actually wrote.

                    1. dmitrygr · · focus · HN ↗
                      Ok then. Soviet Union had free speech too. Nobody got arrested for criticizing Reagan or Churchill.

                      Clearly the point is clear. Why nitpick pointlessly?

                      1. gambiting · · focus · HN ↗
                        You&#x27;ve missed my point entirely, by a country mile.

                        Someone above asked me how it was nonsense. I responded that people parotting the point about getting arrested for criticising the king is nonsense - like for instance, my American coworkers asking if that&#x27;s true, because they read it somewhere on the internet. That is nonsense.

                        If you want to argue with this point please do, but also please observe the rest of my comment and especially the parts that I haven&#x27;t actually said.

                        1. subscribed · · focus · HN ↗
                          Let me repeat reports about these arrests here as well, for your convenience.

                          6 people got arrested for trying to say &quot;Not my king!&quot; BEFORE his coronation: <a href="https:&#x2F;&#x2F;londondaily.com&#x2F;not-my-king-anti-monarchy-protesters-arrested-during-uk-coronation" rel="nofollow">https:&#x2F;&#x2F;londondaily.com&#x2F;not-my-king-anti-monarchy-protesters...

                          Before they had a chance of protest. After months of discussing the planned protest in details and getting a green light from the Met Police: <a href="https:&#x2F;&#x2F;www.bbc.co.uk&#x2F;news&#x2F;uk-65542558" rel="nofollow">https:&#x2F;&#x2F;www.bbc.co.uk&#x2F;news&#x2F;uk-65542558

                          52 people were arrested DURING the coronation, for example for holding a placard &quot;not my king&quot;: <a href="https:&#x2F;&#x2F;londondaily.com&#x2F;over-52-anti-monarchy-protestors-arrested-during-king-charles-coronation" rel="nofollow">https:&#x2F;&#x2F;londondaily.com&#x2F;over-52-anti-monarchy-protestors-arr...

                          Police arrested despite KNOWING it&#x27;s the member of public doesn&#x27;t commit any offence: <a href="https:&#x2F;&#x2F;novaramedia.com&#x2F;2025&#x2F;03&#x2F;11&#x2F;police-officer-who-arrested-anti-monarchy-protester-was-aware-no-offence-had-been-committed&#x2F;" rel="nofollow">https:&#x2F;&#x2F;novaramedia.com&#x2F;2025&#x2F;03&#x2F;11&#x2F;police-officer-who-arrest...

                          I&#x27;m afraid you unwittingly misled your coworkers.

                          1. gambiting · · focus · HN ↗
                            I&#x27;m aware you are still going to twist what I said to prove your point, but I really don&#x27;t fancy repeating the exact same point for the third time just so you can say something unrelated.
                          2. Dylan16807 · · focus · HN ↗
                            They already said you can get in trouble for [planning] protesting. They said you won&#x27;t get in trouble for online criticism. Your links about protests aren&#x27;t proving anything.
                            1. subscribed · · focus · HN ↗
                              It&#x27;s not in the comment I&#x27;m responding to,

                              &gt;&gt; Someone above asked me how it was nonsense. I responded that people parotting the point about getting arrested for criticising the king is nonsense

                              Protesting against the king is criticising the king IMO. I didn&#x27;t see his quantifier, since I would agree that online critique of the king in particular is not yet penalised.

                              Not surprising you&#x27;re implying bad faith though, if we&#x27;re splitting the hair this thin.

                              (and this specific planning of the protest was so heavy handed, because it belong to one of the two naughty protests, environmental. The second naughty one is protesting against the genocide. The rest is okay)

                              1. Dylan16807 · · focus · HN ↗
                                &gt; It&#x27;s not in the comment I&#x27;m responding to,

                                It&#x27;s in the original comment you responded to, and it&#x27;s a critical part of the conversation chain.

                                &quot;And yes, UK has some awful laws around this. Yes it has put people in jail just for planning a protest before. Yes you can go to jail for not disclosing your passwords. But what you read on the internet is almost laughably out of proportion - no, you won&#x27;t get arrested for posting a meme about the king.&quot;

                                I&#x27;m not saying bad faith, I&#x27;m saying you misread their argument pretty badly.

                                Your citations support the problems they already admitted. The hair was split before you got here because they&#x27;re distinguishing in-person and online actions.

                        2. 2ahg7 · · focus · HN ↗
                          Yes, and no one mentioned parroting the king in this thread. Journalists under known observation from the state, which the UK does arrest from time to time, were mentioned however.

                          You can use other European countries like The Netherlands, which is a lawless police state with a liberal cover, as well.

                          1. gambiting · · focus · HN ↗
                            Re-read my comment again.
                2. nostrademons · · focus · HN ↗
                  FWIW the same applies to flying in the U.S. as long as you&#x27;re not a person that the government cares about. I haven&#x27;t had any issues with either TSA or CBP since 2011 (when, apparently, being multiracial with facial hair made me look Middle-Eastern and looking Middle-Eastern is a cardinal sin at U.S. ports of entry). Neither has anyone I&#x27;ve observed at the airport, and that&#x27;s thousands of people per flight, and I fly about 3-4 times per year. There&#x27;s plenty of stories on the Internet, and I don&#x27;t doubt the stories are true, but the Internet can easily make a 1-in-a-million occurrence happen every day (indeed, given the sheer numbers, a 1 in a million occurrence does happen every day, it&#x27;s just that it&#x27;s unlikely to happen to you).
                3. subscribed · · focus · HN ↗
                  Yeah, it&#x27;s true, you should go back to your coworkers and straighten it up.

                  6 people got arrested for trying to say &quot;Not my king!&quot; BEFORE his coronation: <a href="https:&#x2F;&#x2F;londondaily.com&#x2F;not-my-king-anti-monarchy-protesters-arrested-during-uk-coronation" rel="nofollow">https:&#x2F;&#x2F;londondaily.com&#x2F;not-my-king-anti-monarchy-protesters...

                  Before they had a chance of protest. After months of discussing the planned protest in details and getting a green light from the Met Police: <a href="https:&#x2F;&#x2F;www.bbc.co.uk&#x2F;news&#x2F;uk-65542558" rel="nofollow">https:&#x2F;&#x2F;www.bbc.co.uk&#x2F;news&#x2F;uk-65542558

                  It&#x27;s not like Republicans in the UK are a violent group, unlike far right coddled by the same Met police.

                  52 people were arrested DURING the coronation, for example for holding a placard &quot;not my king&quot;: <a href="https:&#x2F;&#x2F;londondaily.com&#x2F;over-52-anti-monarchy-protestors-arrested-during-king-charles-coronation" rel="nofollow">https:&#x2F;&#x2F;londondaily.com&#x2F;over-52-anti-monarchy-protestors-arr...

                  Police arrested despite KNOWING it&#x27;s baseless and frankly illegal: <a href="https:&#x2F;&#x2F;novaramedia.com&#x2F;2025&#x2F;03&#x2F;11&#x2F;police-officer-who-arrested-anti-monarchy-protester-was-aware-no-offence-had-been-committed&#x2F;" rel="nofollow">https:&#x2F;&#x2F;novaramedia.com&#x2F;2025&#x2F;03&#x2F;11&#x2F;police-officer-who-arrest...

                  Tell me some more how it isn&#x27;t arresting for criticising the king. Oh, well, technically he wasn&#x27;t a king yet.... but that&#x27;s even worse to be fair.

                  1. [deleted] · · focus · HN ↗

                    [deleted]

      3. markus_zhang · · focus · HN ↗
        To add an extra layer of safety. Bring a secondary phone when travelling by airplanes, especially to other countries. You should also use it frequently, maybe with some side apps to make it look like it&#x27;s your daily phone.
        1. ryandrake · · focus · HN ↗
          Or, just don&#x27;t bring a phone if you&#x27;re particularly vulnerable. What are they going to do? Deny you entry because you don&#x27;t carry a phone? If we&#x27;re really at that point, where merely not having some item is suspicious, we&#x27;re in deep shit.
          1. altruios · · focus · HN ↗
            I wouldn&#x27;t want to be the one to test this. That&#x27;s an indication of how deep we dug ourselves in.
          2. midas89 · · focus · HN ↗
            if you don&#x27;t know yet, we are in deep
          3. smuhakg · · focus · HN ↗
            It&#x27;s standard for many multinationals and universities to provide blank secondary devices for travel to China that are synchronized with data after getting past the border. They are then erased after one gets back, because Chinese intelligence has broken into hotel rooms and installed keyloggers before.

            Adding the USA to the list of countries where this is done would increase costs but it wouldn&#x27;t be some nightmarish unprecedented problem.

          4. markus_zhang · · focus · HN ↗
            Not bringing a phone looks suspicious, though. Maybe they will ask you to open all of your suitcases and such, which is annoying at least. Since they just want to do their job, better give them an excuse to wrap up quickly and go to the next one.
      4. 3128128 · · focus · HN ↗
        GrapheneOS is critical infrastructure. Questioning it is not like criticizing Neovim. People can get detained, killed and more.

        Perhaps the reflexive genius downvoters can explain what happened to Richard Medhurst? After his phone was snatched and the authorities pretended not to be able to decrypt it, he went on a GrapheneOS promotion spree on X and wanted to write a book about computer security.

        Now he has disappeared for nearly 6 weeks. How many more people do you want to get in trouble with your false promises?

      5. prmoustache · · focus · HN ↗
        What you really want is to wipe the device befoee landing.

        Shutting it down won&#x27;t help if you are forced by law to give out the password, which is the case in more and more countries.

    2. dylan604 · · focus · HN ↗
      &gt; On GrapheneOS, for privacy and convenience, it&#x27;s best to use a long random passphrase

      Why do you call out just one OS? It&#x27;s a good idea for any OS.

      1. Cider9986 · · focus · HN ↗
        Yes, in fact on GrapheneOS it&#x27;s less necessary and it&#x27;s only necessary if you don&#x27;t want to rely on the secure element rate limiting.

        GrapheneOS allows using a passphrase with more convenience because of the fingerprint plus second factor pin (I don&#x27;t think you can just have a pin as a secondary unlock). You don&#x27;t need to enter the passphrase every time you unlock with this setup, only when first starting up.

        The official opinion: <a href="https:&#x2F;&#x2F;hn.algolia.com&#x2F;?dateRange=all&amp;page=0&amp;prefix=true&amp;query=by%3Agrapheneos%20passphrase%20rate%20limit&amp;sort=byDate&amp;type=comment" rel="nofollow">https:&#x2F;&#x2F;hn.algolia.com&#x2F;?dateRange=all&amp;page=0&amp;prefix=true&amp;que...

      2. rtkwe · · focus · HN ↗
        This seems specific to GrapheneOS (unique as far as I know though I&#x27;d be happy to learn otherwise) where you could set a very long first unlock passphrase and have a shorter less cumbersome fingerprint plus pin option for subsequent unlocks. I wouldn&#x27;t want to have to enter a long passphrase every time I unlock but once a day isn&#x27;t so bad.
        1. dylan604 · · focus · HN ↗
          I don&#x27;t run GrapheneOS, but I have an &gt;15 character passphrase that must be used before biometrics can be used after reboot. I haven&#x27;t used a 4-digit pin since the option to not use it was available.
          1. rtkwe · · focus · HN ↗
            The specific extra that grapheneOS adds is that you can have a required Fingerprint + PIN with a shorter easier to enter pin while also having a long first unlock passcode. Only a first unlock passcode then biometrics is not secure in the US if your device is in the AFU&#x2F;biometric-only (after first unlock) state because you can be easily and legally compelled to provide a biometric unlock.

            <a href="https:&#x2F;&#x2F;threecats.au&#x2F;two-factor-pin-fingerprint-unlock-grapheneos" rel="nofollow">https:&#x2F;&#x2F;threecats.au&#x2F;two-factor-pin-fingerprint-unlock-graph...

        2. dataflow · · focus · HN ↗
          The option was there in Cyanogenmod back during the OnePlus One days. It was such a step backwards when it was removed. You almost had to wonder if it was deliberately done at the request of some TLA to prevent users from using too strong of a password for decryption.
          1. rtkwe · · focus · HN ↗
            I doubt it, mostly because phones were a lot easier to crack back in those days already so I doubt a TLA needed to push for it to be removed.
      3. subscribed · · focus · HN ↗
        Because apart of the IOS, according to GrayKey and Cellebrite, GrapheneOS on Pixels is the only phone where it even makes sense (realistically).
    3. iamnothere · · focus · HN ↗
      Never use a website to generate a password for something important like this. You can print out diceware passwords and roll dice.
      1. fluidcruft · · focus · HN ↗
        You can just take a picture of a pile of dice, a pile of rice, or a tree, patch of grass, etc, and compute a secure hash&#x2F;whatever and base six it to get the rolls.
        1. cj · · focus · HN ↗
          I actually have a lava lamp next to my desk for this reason. Snap a photo, compute a hash!
          1. theendisney · · focus · HN ↗
            Count the bubbels with your fingers while you count from 0 to 9. Every x fingers you write down the number.

            Extra points if you hold you face really close and count in a dead language. You can also make ordered hand gestures in stead of counting on your fingers. Be a wizard about it!

            1. cheschire · · focus · HN ↗
              Yer a cryptographer, Harry!
        2. Brybry · · focus · HN ↗
          Are you saying to take a hash of a picture and convert that to base 6 for your dice rolls to plug into a word list for creating a passphrase?

          Is that actually better (in practice, not in terms of entropy) than &#x2F;dev&#x2F;urandom? I have a lot less trust in my ability to successfully scrub a picture from my phone that deterministically created my passphrase.

          1. lisper · · focus · HN ↗
            &gt; Is that actually better (in practice, not in terms of entropy) than &#x2F;dev&#x2F;urandom?

            It offers protection in the event that your &#x2F;dev&#x2F;urandom is compromised. Otherwise no.

            (Of course, if your &#x2F;dev&#x2F;urandom is compromised then whatever process you use to compute a hash of a photo is likely compromised as well.)

          2. Matumio · · focus · HN ↗
            If you&#x27;re concerned about that, you can concat your JPEG with a few bytes from &#x2F;dev&#x2F;random and you&#x27;ll get the security of whichever is stronger. In practice none of this will be your weakest link.
            1. NetMageSCW · · focus · HN ↗
              It is possible that using a JPEG with its known bytes could make the final effort weaker than if you just used &#x2F;dev&#x2F;random.
              1. manwe150 · · focus · HN ↗
                No, that would fundamentally break the way (good) hashing works if I could add known data and get it to reveal the secret data
        3. theendisney · · focus · HN ↗
          If you have a computer do something you cant know if it really did what you wanted.
        4. heelix · · focus · HN ↗
          Three random pictures - man, that gives me a Johnny Mnemonic vibe.
      2. throw0101c · · focus · HN ↗
        &gt; You can print out diceware passwords and roll dice.

        Or on the CLI:

        * <a href="https:&#x2F;&#x2F;packages.debian.org&#x2F;search?keywords=diceware" rel="nofollow">https:&#x2F;&#x2F;packages.debian.org&#x2F;search?keywords=diceware

        * <a href="https:&#x2F;&#x2F;packages.debian.org&#x2F;search?keywords=pwgen" rel="nofollow">https:&#x2F;&#x2F;packages.debian.org&#x2F;search?keywords=pwgen

      3. busssard · · focus · HN ↗
        you can play a round of scrabble and build the passphrase out of that
        1. iamnothere · · focus · HN ↗
          The entropy wouldn’t be very good compared to repeated dice rolls.
          1. busssard · · focus · HN ↗
            is there a comparison? i would assume depending on the limits you set yourself while playing scrabble (min 5letter words, selected for beauty) this can be alleviated
    4. fluidcruft · · focus · HN ↗
      Why not automatically power down if any unknown USB device is attached?
      1. eli · · focus · HN ↗
        So like you connect it to your computer for the first time and it shuts off?
        1. isoprophlex · · focus · HN ↗
          Better wire it up to a thermite charge just to be sure. Untrusted USB device? Hope you enjoy 1400 degree molten iron
          1. dessimus · · focus · HN ↗
            And now you&#x27;re in violation of booby trap laws.
        2. olyjohn · · focus · HN ↗
          Yeah... that could be an option you configure.
        3. 83 · · focus · HN ↗
          that doesn&#x27;t seem unreasonable. You only have one first time. Maybe two if you upgrade your computer more often than your phone.
          1. [deleted] · · focus · HN ↗

            [deleted]

          2. LorenPechtel · · focus · HN ↗
            My Android certainly doesn&#x27;t know my computer. Every single time it defaults to charging only and I have to select if I want data transfer.
            1. Telaneo · · focus · HN ↗
              Is that because it cannot know your computer without you telling it every time, or is it just Android providing that default and not having a way to change that default?
              1. hulitu · · focus · HN ↗
                is it just Android. SW is hard.
        4. nkrisc · · focus · HN ↗
          Or it’s not enabled by default.
        5. sellmesoap · · focus · HN ↗
          Could request unlock and reboot if no valid pass is accepted within n minutes.
        6. usern20260720 · · focus · HN ↗
          1. disable shutting down. 2. connect device and fingerprint it. 3. enable shutting down
          1. NetMageSCW · · focus · HN ↗
            How do you disable shutting down?
            1. Telaneo · · focus · HN ↗
              By changing a settibg in the settings menu?
        7. dzhiurgis · · focus · HN ↗
          TBF pretty much no one connects their devices anymore to anything other than charging. For those who do some timeout could work.
      2. ssl-3 · · focus · HN ↗
        Or shut down when any USB device is attached while the phone is locked&#x2F;inactive?

        It&#x27;d work like this: Unlock phone, plug in USB widget; it works.

        Or: Plug in USB widget without first unlocking phone; phone shuts down.

        1. fluidcruft · · focus · HN ↗
          That&#x27;s a great option.

          I just wonder whether that could be too annoying for Android Auto &#x2F; Car Play. But to be fair wireless is an option.

          The other downside I guess is that a thief would just plug a USB drive in to disable device tracking. But they could just wrap the damn thing in foil so dunno if that should matter.

          1. ssl-3 · · focus · HN ↗
            It&#x27;s either that, or maintain a database of trusted USB devices...which seems iffy, at best.

            And by that I mean, using the database itself is simple. But when it exists, then a list of targets for an attacker to emulate also exists.

            Those boys at Cellebrite aren&#x27;t dummies, at all, and they&#x27;ve been doing this stuff for quite a long time. They&#x27;re a formidable opponent.

            We used to use their kit to clone personal data between very different devices back in the dumb phone days. They were the only ones to get it right out of a sea of others that were also evaluated.

            1. ssl-3 · · focus · HN ↗
              I should mention: Cellebrite&#x27;s methods would tend to walk completely around whatever the phone thought was a normal, good idea.

              When the usual manufacturer-prescribed method for reading contacts said to take some long-winded steps to put the phone into a special mode, Cellebrite&#x27;s hardware just usually skipped that shit and read the data very directly without any fuss.

              Plug it in, push the button, and the Cellebrite box just did the appropriate magic. It then interpreted the data and munged it into a useful form to shove into the next phone.

              After that: The recovered personal data was pushed right up into the ass of the next phone with the same lack of consent. It was succinct and brutal in operation.

              And: It worked. It was so dead-nuts simple that a cell phone salesperson could run it with ease. I stopped getting phone calls from the field about transfer problems when we started using Cellebrite kit.

              Nothing else did this stuff with that measure of resolute nonchalance.

              So at this point they&#x27;ve been uniquely hooning with cell phones for decades. It&#x27;s kind of their schtick.

              If we can speculate that something like the the USB-C charge rate negotiation on a given phone can open a pathway into the system, then it can be safe to say that Cellebrite is already using that method to get things done -- and that a person at the border can exploit it even if they&#x27;re &quot;not a tech person&quot;.

              Simplifying these kinds of hacks is what they do.

            2. yencabulator · · focus · HN ↗
              &gt; And by that I mean, using the database itself is simple. But when it exists, then a list of targets for an attacker to emulate also exists.

              Recognize USB devices by serial numbers, not the manufacturer ID. Even if they could get their hands on the serial number of my car stereo, that&#x27;s going to be after the same warrant delay this thing protects against.

              1. ssl-3 · · focus · HN ↗
                The car stereo that&#x27;s in the car parked just outside the airport, in the long-term lot, which is conveniently within 100 miles of a border crossing?

                The lot they tracked you going into? The lot that gets scanned by mobile ALPRs on the regular?

                Yeah, so. About that... :-&#x2F;

    5. burningChrome · · focus · HN ↗
      &gt;&gt; then a fingerprint with a second factor pin as the secondary unlock

      Unless you have a 4 or 4XL which are pretty popular with graphene os users. The weird thing is the 4 and 4XL are the only models without fingerprint because Google was pushing its #D Face Unlock System at the time.

      The funny part is Graphene by default now disables face unlock on newer Pixel models.

    6. NetMageSCW · · focus · HN ↗
      Note that the iPhone also can be set to use a complicated password instead of a PIN and it will require it on first unlock.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.