‹ BackHN Continuity

Thread

Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones

287 points · 226 comments · speckx

  1. Cider9986 · · focus · HN ↗
    For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.

    GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.

    On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.

    If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.

    [1] <a href="https:&#x2F;&#x2F;strongphrase.net" rel="nofollow">https:&#x2F;&#x2F;strongphrase.net give memorable ones which is cool.

    1. 23ahGa17 · · focus · HN ↗
      People believed the reboot feature last time GrapheneOS was mentioned. It is of course nonsense.

      Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.

      1. markus_zhang · · focus · HN ↗
        To add an extra layer of safety. Bring a secondary phone when travelling by airplanes, especially to other countries. You should also use it frequently, maybe with some side apps to make it look like it&#x27;s your daily phone.
        1. ryandrake · · focus · HN ↗
          Or, just don&#x27;t bring a phone if you&#x27;re particularly vulnerable. What are they going to do? Deny you entry because you don&#x27;t carry a phone? If we&#x27;re really at that point, where merely not having some item is suspicious, we&#x27;re in deep shit.
          1. altruios · · focus · HN ↗
            I wouldn&#x27;t want to be the one to test this. That&#x27;s an indication of how deep we dug ourselves in.
          2. midas89 · · focus · HN ↗
            if you don&#x27;t know yet, we are in deep
          3. smuhakg · · focus · HN ↗
            It&#x27;s standard for many multinationals and universities to provide blank secondary devices for travel to China that are synchronized with data after getting past the border. They are then erased after one gets back, because Chinese intelligence has broken into hotel rooms and installed keyloggers before.

            Adding the USA to the list of countries where this is done would increase costs but it wouldn&#x27;t be some nightmarish unprecedented problem.

          4. markus_zhang · · focus · HN ↗
            Not bringing a phone looks suspicious, though. Maybe they will ask you to open all of your suitcases and such, which is annoying at least. Since they just want to do their job, better give them an excuse to wrap up quickly and go to the next one.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.