Magent Forensics, the owner of the GrayKey phone unlocking tool, says it can bypass an iPhone rebooting feature that was locking cops out.

175 points•speckx•about 5 hours ago•127 comments•

127 comments

Cider9986about 3 hours ago
For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.

GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.

On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.

If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.

[1] https://strongphrase.net give memorable ones which is cool.

iamnothereabout 3 hours ago
Never use a website to generate a password for something important like this. You can print out diceware passwords and roll dice.
fluidcruftabout 1 hour ago
You can just take a picture of a pile of dice, a pile of rice, or a tree, patch of grass, etc, and compute a secure hash/whatever and base six it to get the rolls.
dylan604about 3 hours ago
> On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase

Why do you call out just one OS? It's a good idea for any OS.

rtkweabout 3 hours ago
This seems specific to GrapheneOS (unique as far as I know though I'd be happy to learn otherwise) where you could set a very long first unlock passphrase and have a shorter less cumbersome fingerprint plus pin option for subsequent unlocks. I wouldn't want to have to enter a long passphrase every time I unlock but once a day isn't so bad.
Cider9986about 3 hours ago
Yes, in fact on GrapheneOS it's less necessary and it's only necessary if you don't want to rely on the secure element rate limiting.

GrapheneOS allows using a passphrase with more convenience because of the fingerprint plus second factor pin (I don't think you can just have a pin as a secondary unlock). You don't need to enter the passphrase every time you unlock with this setup, only when first starting up.

The official opinion: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

fluidcruftabout 1 hour ago
Why not automatically power down if any unknown USB device is attached?
eliabout 1 hour ago
So like you connect it to your computer for the first time and it shuts off?
23ahGa17about 3 hours ago
People believed the reboot feature last time GrapheneOS was mentioned. It is of course nonsense.

Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.

Cider9986about 3 hours ago
> Shut down the phone in areas with a high snatch risk.

Yes this is of course safer. What evidence do you have that it doesn't work on GrapheneOS, though?

https://www.computerweekly.com/feature/Journalist-Richard-Me...

markus_zhangabout 3 hours ago
To add an extra layer of safety. Bring a secondary phone when travelling by airplanes, especially to other countries. You should also use it frequently, maybe with some side apps to make it look like it's your daily phone.
stefan_about 3 hours ago
The internet exists and can transfer your data with no customs and borders, so if you are at risk of being snatched, the correct choice is to not carry a phone (or laptop, or..) at all.
iancarroll21 minutes ago
> “Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost. This is the true magic behind the GrayKey Preserve and the Evidence Preservation Mode function.”

Based on this, it seems more likely that this involves exploiting the device to retrieve the underlying keybags present in AFU mode and store them, rather than manipulating the actual feature of automatic reboots. Then the device can be exploited again in BFU mode but with the prior keybag to decrypt everything.

It sounds like this feature is being used to exploit and extract keys from devices without a warrant (or in advance of getting one), which seems dubious to me.

delichonabout 4 hours ago
I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.

As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

WithinReasonabout 4 hours ago
If you don't give access to law enforcement when they ask: straight to jail. Encryption is irrelevant in that situation. If they see the encrypted volume you need to provide them access.
rdevsrexabout 4 hours ago
Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.

Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.

ChrisMarshallNYabout 4 hours ago
Classic $5 wrench.

Having thugs on speed dial opens a lot of doors.

gonzalohmabout 3 hours ago
So if an app installs an encrypted volume for which you don't have the password to, you go to jail? That doesn't make sense. How can they know if I have the password or not
Cider9986about 3 hours ago
It would seem wise to at least keep a backup in an E2EE cloud [1]. This could possibly allow you to not give access even if legally compelled.

>As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

Yes, it seems that way in the US: https://news.ycombinator.com/item?id=49922513

If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.

[1] https://www.privacyguides.org/en/cloud/

0x262dabout 1 hour ago
Yeah, getting all your sensitive stuff off your phone onto a secure cloud service seems like the obvious approach here right? They can still escalate what they try to coerce you to do, but they don't have physical access to your data just by taking your phone, and you can also leave the phone with them and only lose the device if needed. In my likely scenario - innocent traveler, they aren't looking for anything specific, but I still don't want them to look through my files and photos just because I happen to travel internationally - that seems like it puts it out of reach (and out of obvious view) for now.
jstanleyabout 4 hours ago
It seems foolhardy to carry your life savings around everywhere, encrypted or not.

If you really want to keep this stuff on a phone at least stretch to a second phone and keep it somewhere safe.

ryandrakeabout 2 hours ago
Exactly. Don't keep your life on your phone. We shouldn't have to take these precautions but unfortunately we do.
devinabout 3 hours ago
or a separate hard drive in a fireproof safe or something.
pieter_mjabout 4 hours ago
If you travel abroad you must unlock. No 4th amendment for you.
eliabout 1 hour ago
That’s not the full story and not really correct.

https://www.aclu.org/news/privacy-technology/can-border-agen...

skinfaxiabout 4 hours ago
You can decline but then they can seize is that right?
jstanleyabout 4 hours ago
This is mostly FUD. I've never been asked to unlock my phone when travelling abroad.
mmoossabout 3 hours ago
It seems to me you are taking a big risk. Some considerations:

> Cryptomator

Much security is poorly implemented; you can't count on it being effective. Even Apple, which takes security very seriously and has world-class talent and enormous resources, fails to implement security effectively sometimes (as in the OP). Can Cryptomator do better? Find the most respected - by professionals - security solution you can.

And on a device with many other functions - all the things you use your phone for - you risk all sorts of security holes in every function of app you use. And what happens to the data when your phone is backed up? Store the data on a single-purpose device.

Also, on an Internet-connected device, you make the data potentially accessible to the entire Internet. Use offline storage.

Bringing the storage device with you everywhere is asking for a mistake on your part - losing it, etc. Hide it someplace.

> or legal access

Ask a lawyer.

ethagnawlabout 3 hours ago
> The idea behind this so-called “inactivity reboot” is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology.

This is weird framing. The feature makes it harder for anyone to break into the device.

tamimioabout 3 hours ago
Not weird, not anyone can buy those equipment to break into a fully updated phone, in fact, it’s pretty much only law enforcement can or will have access to them, so that statement is true, it will make it harder for police to do so.
nikanj25 minutes ago
You can buy the mandatory TSA key for your suitcase lock from eBay for a few bucks. Tools have a way of falling off the truck at the loading dock
ethagnawlabout 2 hours ago
That's not how exploits work, though. This is also the reason why backdoors in encryption and the like are never a good idea. Sure, "police" are the ones _most likely_ to use this tool (developed by a private company...) to use this exploit to break into iPhones. However, anyone who is motivated enough and/or has the resources _could_ also do it.
Melatonicabout 3 hours ago
I wouldnt be surprised if they had a backdoor into the Qualcomm chip that Apple decided to oddly still include in most of their US iPhones vs the international versions that come with their own internal modem
canada_dry7 minutes ago
This extremely well hidden backdoor was an interesting find:

https://news.ycombinator.com/item?id=38783112

cluelessabout 1 hour ago
that Qualcomm chip that apple uses is a modem, so not sure it's that relevant to the phone's security in this case...
bigyabaiabout 2 hours ago
I wouldn't be surprised if they had a backdoor into the Secure Enclave. Apple is definitely a part of the US' NOBUS scheming, whether or not cops get to use it.
monster_truck42 minutes ago
The past few weeks of people ripping into it have demonstrated that SE is mostly reality distortion and does not offer any unique or meaningful protection. I have no doubt the old modems had deficiencies, the new ones assuredly do too. Just a changing of the guard for however long it lasts.

I wouldn't call it scheming though. The approach of choice to (scare quotes) ensuring continued access has traditionally been one where there is no overt coordination or communication. The ideal case is one where every engineer, pm, qa, leadership earnestly believe that they have done a good job/the correct thing... and then there is some deficiency that handily bypasses all of that, exposed publicly, without any authentication and a convenient lack of logging, or some oversight in the specification/standard everything operates against. Real world examples of this include backends to vehicle telemetry/connectivity apps that hand over complete driving histories with the right ip, json and a vin, or flock somehow deploying ~nationwide with a static password and no append only logging in each device. They're flagrant violations of best practices, without conseqeuences or liability.

That's one of the more incredible things about LLMs, the rate at which they are finding these needles in haystacks is only going to accelerate. It's the end of an era. These things were never used for what they should have been, I struggle to imagine a legitimate argument in favor for them that isn't carrying water for the wrong team.

eliabout 1 hour ago
So the FBI publicly fueding with Apple over encryption is all just misdirection? I dunno about that

Read the full thread on Hacker News →

Related stories