Magent Forensics, the owner of the GrayKey phone unlocking tool, says it can bypass an iPhone rebooting feature that was locking cops out.
127 comments
GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.
On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.
If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.
[1] https://strongphrase.net give memorable ones which is cool.
Why do you call out just one OS? It's a good idea for any OS.
GrapheneOS allows using a passphrase with more convenience because of the fingerprint plus second factor pin (I don't think you can just have a pin as a secondary unlock). You don't need to enter the passphrase every time you unlock with this setup, only when first starting up.
The official opinion: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.
Yes this is of course safer. What evidence do you have that it doesn't work on GrapheneOS, though?
https://www.computerweekly.com/feature/Journalist-Richard-Me...
Based on this, it seems more likely that this involves exploiting the device to retrieve the underlying keybags present in AFU mode and store them, rather than manipulating the actual feature of automatic reboots. Then the device can be exploited again in BFU mode but with the prior keybag to decrypt everything.
It sounds like this feature is being used to exploit and extract keys from devices without a warrant (or in advance of getting one), which seems dubious to me.
As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.
Having thugs on speed dial opens a lot of doors.
>As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
Yes, it seems that way in the US: https://news.ycombinator.com/item?id=49922513
If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.
If you really want to keep this stuff on a phone at least stretch to a second phone and keep it somewhere safe.
https://www.aclu.org/news/privacy-technology/can-border-agen...
> Cryptomator
Much security is poorly implemented; you can't count on it being effective. Even Apple, which takes security very seriously and has world-class talent and enormous resources, fails to implement security effectively sometimes (as in the OP). Can Cryptomator do better? Find the most respected - by professionals - security solution you can.
And on a device with many other functions - all the things you use your phone for - you risk all sorts of security holes in every function of app you use. And what happens to the data when your phone is backed up? Store the data on a single-purpose device.
Also, on an Internet-connected device, you make the data potentially accessible to the entire Internet. Use offline storage.
Bringing the storage device with you everywhere is asking for a mistake on your part - losing it, etc. Hide it someplace.
> or legal access
Ask a lawyer.
This is weird framing. The feature makes it harder for anyone to break into the device.
I wouldn't call it scheming though. The approach of choice to (scare quotes) ensuring continued access has traditionally been one where there is no overt coordination or communication. The ideal case is one where every engineer, pm, qa, leadership earnestly believe that they have done a good job/the correct thing... and then there is some deficiency that handily bypasses all of that, exposed publicly, without any authentication and a convenient lack of logging, or some oversight in the specification/standard everything operates against. Real world examples of this include backends to vehicle telemetry/connectivity apps that hand over complete driving histories with the right ip, json and a vin, or flock somehow deploying ~nationwide with a static password and no append only logging in each device. They're flagrant violations of best practices, without conseqeuences or liability.
That's one of the more incredible things about LLMs, the rate at which they are finding these needles in haystacks is only going to accelerate. It's the end of an era. These things were never used for what they should have been, I struggle to imagine a legitimate argument in favor for them that isn't carrying water for the wrong team.
Read the full thread on Hacker News →
Related stories
- The Verge · 0 points · 8 days ago
- Phones don’t have lightstheverge.comThe Verge · 0 points · 6 days ago
- The Verge · 0 points · about 17 hours ago
- Hacker News · 1 points · about 11 hours ago
- Apple Excludes Older iPhones from New Camera Featuremacrumors.comHacker News · 2 points · 9 days ago
- Can Phones Explain Pisa?commonreader.co.ukHacker News · 1 points · 9 days ago