‹ BackHN Continuity

Thread

Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones

287 points · 226 comments · speckx

  1. Cider9986 · · focus · HN ↗
    For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.

    GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.

    On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.

    If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.

    [1] <a href="https:&#x2F;&#x2F;strongphrase.net" rel="nofollow">https:&#x2F;&#x2F;strongphrase.net give memorable ones which is cool.

    1. 23ahGa17 · · focus · HN ↗
      People believed the reboot feature last time GrapheneOS was mentioned. It is of course nonsense.

      Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.

      1. stefan_ · · focus · HN ↗
        The internet exists and can transfer your data with no customs and borders, so if you are at risk of being snatched, the correct choice is to not carry a phone (or laptop, or..) at all.
        1. Someone · · focus · HN ↗
          <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Great_Firewall" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Great_Firewall:

          “The Great Firewall operates by checking transmission control protocol (TCP) packets for keywords or sensitive words. If the keywords or sensitive words appear in the TCP packets, access will be closed. If one link is closed, more links from the same machine will be blocked by the Great Firewall. The effect includes: limiting access to foreign information sources, blocking popular foreign websites and mobile apps, and requiring foreign companies to adapt to domestic regulations. Due to the Great Firewall, China has one of the lowest cross-border internet traffic rates in the world. Usage of foreign apps in China is minuscule; Asia Society estimated in 2026 that foreign apps blocked by the Great Firewall have extremely low traffic, particularly compared to domestic apps; the top five domestic apps saw traffic that was 1,000 times more than the top five foreign apps.”

          1. oasisaimlessly · · focus · HN ↗
            The Great Firewall doesn&#x27;t restrict SSH, so you can functionally ignore it (assuming using e.g. `ssh -D` is second-nature to you).
            1. wat10000 · · focus · HN ↗
              Last time I tried it (which was quite a while ago, but I&#x27;d be surprised if they became less restrictive) ssh was fine for interactive use, but they did some sort of traffic analysis to kill connections that got used for tunneling other traffic like that.

              When I was there last year, it took some doing to get a VPN working. Mullvad was pretty good but it would take a few tries to find an endpoint I could connect to. The simplest escape hatch is to have a cellular connection from another country, but that&#x27;s either expensive or slow.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.