‹ BackHN Continuity

Thread

Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones

287 points · 226 comments · speckx

  1. Cider9986 · · focus · HN ↗
    For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.

    GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.

    On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.

    If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.

    [1] <a href="https:&#x2F;&#x2F;strongphrase.net" rel="nofollow">https:&#x2F;&#x2F;strongphrase.net give memorable ones which is cool.

    1. iamnothere · · focus · HN ↗
      Never use a website to generate a password for something important like this. You can print out diceware passwords and roll dice.
      1. fluidcruft · · focus · HN ↗
        You can just take a picture of a pile of dice, a pile of rice, or a tree, patch of grass, etc, and compute a secure hash&#x2F;whatever and base six it to get the rolls.
        1. cj · · focus · HN ↗
          I actually have a lava lamp next to my desk for this reason. Snap a photo, compute a hash!
          1. theendisney · · focus · HN ↗
            Count the bubbels with your fingers while you count from 0 to 9. Every x fingers you write down the number.

            Extra points if you hold you face really close and count in a dead language. You can also make ordered hand gestures in stead of counting on your fingers. Be a wizard about it!

            1. cheschire · · focus · HN ↗
              Yer a cryptographer, Harry!
        2. Brybry · · focus · HN ↗
          Are you saying to take a hash of a picture and convert that to base 6 for your dice rolls to plug into a word list for creating a passphrase?

          Is that actually better (in practice, not in terms of entropy) than &#x2F;dev&#x2F;urandom? I have a lot less trust in my ability to successfully scrub a picture from my phone that deterministically created my passphrase.

          1. lisper · · focus · HN ↗
            &gt; Is that actually better (in practice, not in terms of entropy) than &#x2F;dev&#x2F;urandom?

            It offers protection in the event that your &#x2F;dev&#x2F;urandom is compromised. Otherwise no.

            (Of course, if your &#x2F;dev&#x2F;urandom is compromised then whatever process you use to compute a hash of a photo is likely compromised as well.)

          2. Matumio · · focus · HN ↗
            If you&#x27;re concerned about that, you can concat your JPEG with a few bytes from &#x2F;dev&#x2F;random and you&#x27;ll get the security of whichever is stronger. In practice none of this will be your weakest link.
            1. NetMageSCW · · focus · HN ↗
              It is possible that using a JPEG with its known bytes could make the final effort weaker than if you just used &#x2F;dev&#x2F;random.
              1. manwe150 · · focus · HN ↗
                No, that would fundamentally break the way (good) hashing works if I could add known data and get it to reveal the secret data
        3. theendisney · · focus · HN ↗
          If you have a computer do something you cant know if it really did what you wanted.
        4. heelix · · focus · HN ↗
          Three random pictures - man, that gives me a Johnny Mnemonic vibe.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.