‹ BackHN Continuity

Thread

Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones

287 points · 226 comments · speckx

  1. Cider9986 · · focus · HN ↗
    For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.

    GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.

    On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.

    If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.

    [1] <a href="https:&#x2F;&#x2F;strongphrase.net" rel="nofollow">https:&#x2F;&#x2F;strongphrase.net give memorable ones which is cool.

    1. fluidcruft · · focus · HN ↗
      Why not automatically power down if any unknown USB device is attached?
      1. ssl-3 · · focus · HN ↗
        Or shut down when any USB device is attached while the phone is locked&#x2F;inactive?

        It&#x27;d work like this: Unlock phone, plug in USB widget; it works.

        Or: Plug in USB widget without first unlocking phone; phone shuts down.

        1. fluidcruft · · focus · HN ↗
          That&#x27;s a great option.

          I just wonder whether that could be too annoying for Android Auto &#x2F; Car Play. But to be fair wireless is an option.

          The other downside I guess is that a thief would just plug a USB drive in to disable device tracking. But they could just wrap the damn thing in foil so dunno if that should matter.

          1. ssl-3 · · focus · HN ↗
            It&#x27;s either that, or maintain a database of trusted USB devices...which seems iffy, at best.

            And by that I mean, using the database itself is simple. But when it exists, then a list of targets for an attacker to emulate also exists.

            Those boys at Cellebrite aren&#x27;t dummies, at all, and they&#x27;ve been doing this stuff for quite a long time. They&#x27;re a formidable opponent.

            We used to use their kit to clone personal data between very different devices back in the dumb phone days. They were the only ones to get it right out of a sea of others that were also evaluated.

            1. ssl-3 · · focus · HN ↗
              I should mention: Cellebrite&#x27;s methods would tend to walk completely around whatever the phone thought was a normal, good idea.

              When the usual manufacturer-prescribed method for reading contacts said to take some long-winded steps to put the phone into a special mode, Cellebrite&#x27;s hardware just usually skipped that shit and read the data very directly without any fuss.

              Plug it in, push the button, and the Cellebrite box just did the appropriate magic. It then interpreted the data and munged it into a useful form to shove into the next phone.

              After that: The recovered personal data was pushed right up into the ass of the next phone with the same lack of consent. It was succinct and brutal in operation.

              And: It worked. It was so dead-nuts simple that a cell phone salesperson could run it with ease. I stopped getting phone calls from the field about transfer problems when we started using Cellebrite kit.

              Nothing else did this stuff with that measure of resolute nonchalance.

              So at this point they&#x27;ve been uniquely hooning with cell phones for decades. It&#x27;s kind of their schtick.

              If we can speculate that something like the the USB-C charge rate negotiation on a given phone can open a pathway into the system, then it can be safe to say that Cellebrite is already using that method to get things done -- and that a person at the border can exploit it even if they&#x27;re &quot;not a tech person&quot;.

              Simplifying these kinds of hacks is what they do.

            2. yencabulator · · focus · HN ↗
              &gt; And by that I mean, using the database itself is simple. But when it exists, then a list of targets for an attacker to emulate also exists.

              Recognize USB devices by serial numbers, not the manufacturer ID. Even if they could get their hands on the serial number of my car stereo, that&#x27;s going to be after the same warrant delay this thing protects against.

              1. ssl-3 · · focus · HN ↗
                The car stereo that&#x27;s in the car parked just outside the airport, in the long-term lot, which is conveniently within 100 miles of a border crossing?

                The lot they tracked you going into? The lot that gets scanned by mobile ALPRs on the regular?

                Yeah, so. About that... :-&#x2F;

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.