‹ BackHN Continuity

Thread

Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones

287 points · 226 comments · speckx

  1. delichon · · focus · HN ↗
    I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.

    As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

    1. WithinReason · · focus · HN ↗
      If you don't give access to law enforcement when they ask: straight to jail. Encryption is irrelevant in that situation. If they see the encrypted volume you need to provide them access.
      1. rdevsrex · · focus · HN ↗
        Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.

        Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.

        1. DaveSchmindel · · focus · HN ↗
          That's been my understanding until now as well... the latest on the case against Samuel Tunick has me worried and second guessing that blanket statement though...

          <a href="https:&#x2F;&#x2F;nccriminallaw.sog.unc.edu&#x2F;2026&#x2F;08&#x2F;03&#x2F;giving-police-a-duress-code-instead-of-a-passcode-to-a-phone&#x2F;" rel="nofollow">https:&#x2F;&#x2F;nccriminallaw.sog.unc.edu&#x2F;2026&#x2F;08&#x2F;03&#x2F;giving-police-a...

          1. rtkwe · · focus · HN ↗
            That case has the specific, very important, wrinkle that he provided a _destructive_ duress code, he could have continued to refuse to provide the unlock code just fine legally. It&#x27;s the use of the duress code that is likely going to be getting him in trouble and that falls outside of the existing defined protections about being compelled to unlock safes&#x2F;computers etc containing possible evidence against yourself.

            We&#x27;ll have to see how that case goes but ultimately the reason he&#x27;s getting in trouble is only tangentially related to his phone being encrypted. It&#x27;s more correct to think of it like he smashed the phone to pieces (and imagine this definitively destroys the data for the sake of the metaphor) instead of it being about the encryption itself.

            1. LoganDark · · focus · HN ↗
              He didn&#x27;t smash the phone to pieces, he gave LE a hammer and they smashed the phone to pieces. It&#x27;s entirely LE&#x27;s own fault this happened -- they shouldn&#x27;t have been trying to get into that phone, and it&#x27;s their own fault it went wrong.

              Though I would expect courts to consider that he knew LE planned to enter the provided PIN, and that the duress PIN would then result in the phone being wiped, and therefore accuse him of doing the wiping anyway.

              But I don&#x27;t think it&#x27;s this guy&#x27;s fault at all. LE is the one who asked him under duress, he easily could&#x27;ve feared for his life, and he did no direct harm. It was self-defense at worst.

              1. rtkwe · · focus · HN ↗
                That&#x27;s too cute by half for the law, this kind of &quot;I&#x27;m not touching you&quot; argument comes up each time and it just doesn&#x27;t work. The guy intentionally provided the code knowing it would destroy the &quot;evidence&quot;&#x2F;contents of his phone if they entered it, it&#x27;s clear what his intent was and the data would not have been destroyed if he did not take that action. The minor separation that he did not enter the code himself is highly unlikely to protect him in this case.

                It&#x27;s been a weakness in destructive duress codes since their inception.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.