For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.
GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.
On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.
If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.
People believed the reboot feature last time GrapheneOS was mentioned. It is of course nonsense.
Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.
The internet exists and can transfer your data with no customs and borders, so if you are at risk of being snatched, the correct choice is to not carry a phone (or laptop, or..) at all.
“The Great Firewall operates by checking transmission control protocol (TCP) packets for keywords or sensitive words. If the keywords or sensitive words appear in the TCP packets, access will be closed. If one link is closed, more links from the same machine will be blocked by the Great Firewall. The effect includes: limiting access to foreign information sources, blocking popular foreign websites and mobile apps, and requiring foreign companies to adapt to domestic regulations. Due to the Great Firewall, China has one of the lowest cross-border internet traffic rates in the world. Usage of foreign apps in China is minuscule; Asia Society estimated in 2026 that foreign apps blocked by the Great Firewall have extremely low traffic, particularly compared to domestic apps; the top five domestic apps saw traffic that was 1,000 times more than the top five foreign apps.”
Despite all the nonsense that's posted about UK on the internet, British agencies do require a warrant to enter your home. TSA on the other hand does not require a court order to confiscate and mirror your device before giving it back to you.
Edit: Just to be perfectly clear - Border Force in the UK can do the exact same thing to you once you return, British citizen or not. Leaving your device at home is still the safest choice.
To add an extra layer of safety. Bring a secondary phone when travelling by airplanes, especially to other countries. You should also use it frequently, maybe with some side apps to make it look like it's your daily phone.
Or, just don't bring a phone if you're particularly vulnerable. What are they going to do? Deny you entry because you don't carry a phone? If we're really at that point, where merely not having some item is suspicious, we're in deep shit.
Yes, in fact on GrapheneOS it's less necessary and it's only necessary if you don't want to rely on the secure element rate limiting.
GrapheneOS allows using a passphrase with more convenience because of the fingerprint plus second factor pin (I don't think you can just have a pin as a secondary unlock). You don't need to enter the passphrase every time you unlock with this setup, only when first starting up.
This seems specific to GrapheneOS (unique as far as I know though I'd be happy to learn otherwise) where you could set a very long first unlock passphrase and have a shorter less cumbersome fingerprint plus pin option for subsequent unlocks. I wouldn't want to have to enter a long passphrase every time I unlock but once a day isn't so bad.
I don't run GrapheneOS, but I have an >15 character passphrase that must be used before biometrics can be used after reboot. I haven't used a 4-digit pin since the option to not use it was available.
The specific extra that grapheneOS adds is that you can have a required Fingerprint + PIN with a shorter easier to enter pin while also having a long first unlock passcode. Only a first unlock passcode then biometrics is not secure in the US if your device is in the AFU (after first unlock) state because you can be easily and legally compelled to provide a biometric unlock.
The option was there in Cyanogenmod back during the OnePlus One days. It was such a step backwards when it was removed. You almost had to wonder if it was deliberately done at the request of some TLA to prevent users from using too strong of a password for decryption.
I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.
As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
I believe the parent comment is talking about leaving US, coming back to the US and then having US's border patrol do so.
If that is also what you understood, are you an activist or anyone whom would be of interest to the feds to be asked so? Otherwise saying "I've never been asked" sounds like a common thing for most people.
It's important to separate what can happen from what will happen.
The majority of people walking in the worse neighborhoods of LA or Chicago never have a single crime happen to them. But that doesn't mean that it's safe to go in a bad neighborhood - and it really doesn't mean it's safe to go there wearing designer clothing, gold watches, diamond rings and wearing your Apple VR device.
The same is true for travel. It's perfectly safe for the vast majority - but it's very important to be aware what may make you a target and what can happen to you if you are. Tens of millions of people visit the UK or China every year with no incident. But if you're a public active supporter of Palestine Action, or an active demonstrator against the CCCP respectively, be aware that you personally face a real risk from this travel, and your devices are actually very likely to be searched at those borders. Vice versa though (anti-CCCP activist traveling to UK, PA activist traveling to China) is perfectly safe, though.
I get asked to unlock my dev laptop every single time I go from the US to Montreal. The TSA person sits there and waits for my WM to boot before waving me past.
It seems more like they're trying to determine that it is in fact a laptop and not something resembling one.
That's been my experience as well. I've visited Sydney twice, and both times I've been asked to light up my devices. Granted, I was on work trips requiring three separate laptops which does probably look suspect, but once they were booted they did not request to browse anything and were satisfied to see them working.
All the more reason to dual boot into a decoy OS. Does not stop a task investigation, but lets pass a cursory examination where some thug might want to rifle through your data.
If you don't give access to law enforcement when they ask: straight to jail. Encryption is irrelevant in that situation. If they see the encrypted volume you need to provide them access.
Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.
Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.
That's been my understanding until now as well... the latest on the case against Samuel Tunick has me worried and second guessing that blanket statement though...
That's completely different. Pleading the 5th and not testifying is completely different from giving false testimony - which is never protected. Even in a trial, if you are asked under oath if you handled the body, you are allowed to say that you invoke your 5th amendment rights not to respond; but you are not allowed to say "no, I didn't" if in fact you did (you can later be accused of perjury in addition to your conviction).
That case has the specific wrinkle that he provided a destructive duress code, he could have continued to refuse to provide the unlock code just fine legally. It's the use of the duress code that is likely going to be getting him in trouble and that falls outside of the existing defined protections about being compelled to unlock safes/computers etc containing possible evidence against yourself.
We'll have to see how that case goes but ultimately the reason he's getting in trouble is only tangentially related to his phone being encrypted. It's more correct to think of it like he smashed the phone to pieces (and imagine this definitively destroys the data for the sake of the metaphor) instead of it being about the encryption itself.
Can't they just hand it to you say "you enter your passphrase, but don't divulge it to us and then hand us the phone". In other words hinging the passphrase divulging to the 5th can backfire in that respect. It like saying we have a search warrant, you open the safe for us, it's fine if you keep the combination to yourself, we just need to get inside.
So if an app installs an encrypted volume for which you don't have the password to, you go to jail? That doesn't make sense. How can they know if I have the password or not
They can't know, they infer. AFAIU, normally they just detain you at the airport and harass you to try to break you. To jail you they're technically supposed to be confident enough about you knowing the password to be able to charge you with a crime (presumably something like obstruction, possibly specific to immigration law, otherwise right against self-incrimination might prevent a conviction on failure to disclose alone), or have other evidence of some other crime. Then you end up in the legal system, where courts handle due process and a judge, preliminarily, and then a judge or jury decides if you knew the password.
Note that the recent high-profile case of a man being jailed involved him refusing to decrypt, rather than claiming he didn't know. He was deliberately trying to test the law regarding the permissible scope of inspection of digital data, to force the matter into the courts so the issues could be litigated in a controlled context untainted by other potential crimes; being arrested and charged was part of his plan.
It would seem wise to at least keep a backup in an E2EE cloud [1]. This could possibly allow you to not give access even if legally compelled.
>As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.
It seems to me you are taking a big risk. Some considerations:
> Cryptomator
Much security is poorly implemented; you can't count on it being effective. Even Apple, which takes security very seriously and has world-class talent and enormous resources, fails to implement security effectively sometimes (as in the OP). Can Cryptomator do better? Find the most respected - by professionals - security solution you can.
And on a device with many other functions - all the things you use your phone for - you risk all sorts of security holes in every function of app you use. And what happens to the data when your phone is backed up? Store the data on a single-purpose device.
Also, on an Internet-connected device, you make the data potentially accessible to the entire Internet. Use offline storage.
Bringing the storage device with you everywhere is asking for a mistake on your part - losing it, etc. Hide it someplace.
> The idea behind this so-called “inactivity reboot” is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology.
This is weird framing. The feature makes it harder for anyone to break into the device.
Not weird, not anyone can buy those equipment to break into a fully updated phone, in fact, it’s pretty much only law enforcement can or will have access to them, so that statement is true, it will make it harder for police to do so.
Huh, so this is essentially very similar be what this guy said to my suggestion of a factory reset timer in GrapheneOS being flawed. Apple's implementation of the reboot timer is flawed.
This goes to show for all the people that want GrapheneOS to implement a feature like hidden profiles–flawed features give people a false sense of security and should not be implemented (that's not to mention deniability may not even be a good feature if it was technically possible to implement it well).
Me:
>What about a duress timer working as the reboot timer but it wipes if you don't unlock within the time period. Would that have any advantages for destruction of evidence or deniability?
HybridStatAnim8:
>That would not be viable because the hardware does not support it. It cannot be implemented in the OS because the OS can be turned off or exploited endlessly.
For GOS to consider it, it would likely need to be backed by the secure element.
>Duress PIN is deemed acceptable to implement in the OS because it is expected that the user is the one to enter it, so it has not fallen into the hands of attackers who may bypass it. Once attackers have it, you are effectively gambling. Account for that in your threat model and do not let it get to that point.
I wouldnt be surprised if they had a backdoor into the Qualcomm chip that Apple decided to oddly still include in most of their US iPhones vs the international versions that come with their own internal modem
>Even if that device doesn't have the ability to turn on Airplane Mode or to turn off the transmitters through the Control Center of iOS.
IIRC, the default on iOS is that anyone with your locked device can enable airplane mode which is concerning simply for thieves. But I suppose they have to use faraday bags anyway because of the Find My network.
So we pay Apple for friction. And the state pays for Graykey to remove it. Whoever wins that arm race this quarter determines what our rights are worth in practice.
Well, that's assuming you are ever able to claim your phone back. From what I understand police might just keep it indefinitely until they are able to access it, unless you get some kind of court order that it he returned to you
Ooh, I wonder whether Apple made the classic mistake of using a wall clock timer when they should have used a monotonic (local) clock timer.
edit: having personally gone through this kind of mess, the correct solution is to use strict typing to make sure you keep track of the difference between times and durations and the difference between different clock types. Don’t use plain integers and also don’t try to fudge it the way that Go’s standard library solution does. The modern C++ library is actually pretty good, although you need to use very recent versions of the standard for full functionality.
Is it maybe providing a bogus NTP server or something? Maybe the automatic reboot feature can be moved to the Secure Enclave or something, and made to only rely on the hardware RTC in a way that can't be tampered with.
I'm wondering if you put the phone into a mode where it thinks it's dialing emergency services or contacting them via crash detection etc that it won't reboot. I could picture a scenario where the code is written to never disrupt an emergency services call.
Full disclosure I don't own an iPhone so this may not even be a thing. Just guessing based on liability risk from Apple of "what's more important than protecting the phone"
Unfortunately not a one I can prove to you online. I have a family member who is a district attorney, so that's my source. He said that that companies like the ones mentioned in the article sell licenses to unlock a single phone to a city or county. The city or county pays if they consider it worth it. The cost can be 5 figures.
(so the people that discover these exploits will sell them to the companies for 6 or 7 figures, far more than they would get from an Apple/Android bug bounty)
The article references Magnet Forensic’s Graykey being used for this. Wikipedia shows its like 15-30k per year[1]. Doubt the relevant exploit is available to the average phone thief.
Perhaps for a short time. As soon as Apple understands the exploit I expect them to patch it. They may even back port the fix to older iOS versions as well.
iOS has a remote erase feature. Its also a leaked video and doesn't show which version or model. So it could be something that is already patched, or soon will be. Remember to always keep your OSes update.
Well first on the things you can do right now till apple figures it out, you should have control center disabled while the phone is locked, you can find it under “Allow Access When Locked” in face id and passcode settings, while -per the article- this won’t stop them, it sure will make it harder as by the time they try to gain access the 72h might have passed and a reboot happens. Second, they definitely fake the internal clock through the port, and because connected phone will keep correcting it through the NTP, hence it’s crucial to them to isolate the phone, so your job is to make that harder on them or delay it enough till it reboots itself. I think some of the quick counter measures apple can do now is allowing custom reboot periods, remote reboots through icloud, and disabling the possibility of manipulating the time through the lightning/usbc port.
For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.
GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.
On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.
If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.
[1] https://strongphrase.net give memorable ones which is cool.
People believed the reboot feature last time GrapheneOS was mentioned. It is of course nonsense.
Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.
> Shut down the phone in areas with a high snatch risk.
Yes this is of course safer. What evidence do you have that it doesn't work on GrapheneOS, though?
https://www.computerweekly.com/feature/Journalist-Richard-Me...
Medhurst has no evidence that it worked either. He hasn't tweeted since August 24th, I hope he is well and at liberty.
The internet exists and can transfer your data with no customs and borders, so if you are at risk of being snatched, the correct choice is to not carry a phone (or laptop, or..) at all.
https://en.wikipedia.org/wiki/Great_Firewall:
“The Great Firewall operates by checking transmission control protocol (TCP) packets for keywords or sensitive words. If the keywords or sensitive words appear in the TCP packets, access will be closed. If one link is closed, more links from the same machine will be blocked by the Great Firewall. The effect includes: limiting access to foreign information sources, blocking popular foreign websites and mobile apps, and requiring foreign companies to adapt to domestic regulations. Due to the Great Firewall, China has one of the lowest cross-border internet traffic rates in the world. Usage of foreign apps in China is minuscule; Asia Society estimated in 2026 that foreign apps blocked by the Great Firewall have extremely low traffic, particularly compared to domestic apps; the top five domestic apps saw traffic that was 1,000 times more than the top five foreign apps.”
The Great Firewall doesn't restrict SSH, so you can functionally ignore it (assuming using e.g. `ssh -D` is second-nature to you).
If you live in the UK and travel to the US and are afraid of state actors, leaving your hardware at home seems like a bad idea, too.
Despite all the nonsense that's posted about UK on the internet, British agencies do require a warrant to enter your home. TSA on the other hand does not require a court order to confiscate and mirror your device before giving it back to you.
Edit: Just to be perfectly clear - Border Force in the UK can do the exact same thing to you once you return, British citizen or not. Leaving your device at home is still the safest choice.
I believe it's CBP that does this, not TSA. Therefore Americans don't have to worry about it during domestic flights.
> Despite all the nonsense that's posted about UK on the internet
How is it nonsense? I'm not debating the warrant thing, but it's very reasonable to assume the UK has terrible protections for these sorts of things.
https://en.wikipedia.org/wiki/Key_disclosure_law#:~:text=Uni...
https://eylenburg.github.io/countries.htm
To add an extra layer of safety. Bring a secondary phone when travelling by airplanes, especially to other countries. You should also use it frequently, maybe with some side apps to make it look like it's your daily phone.
Or, just don't bring a phone if you're particularly vulnerable. What are they going to do? Deny you entry because you don't carry a phone? If we're really at that point, where merely not having some item is suspicious, we're in deep shit.
I wouldn't want to be the one to test this. That's an indication of how deep we dug ourselves in.
> On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase
Why do you call out just one OS? It's a good idea for any OS.
Yes, in fact on GrapheneOS it's less necessary and it's only necessary if you don't want to rely on the secure element rate limiting.
GrapheneOS allows using a passphrase with more convenience because of the fingerprint plus second factor pin (I don't think you can just have a pin as a secondary unlock). You don't need to enter the passphrase every time you unlock with this setup, only when first starting up.
The official opinion: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
This seems specific to GrapheneOS (unique as far as I know though I'd be happy to learn otherwise) where you could set a very long first unlock passphrase and have a shorter less cumbersome fingerprint plus pin option for subsequent unlocks. I wouldn't want to have to enter a long passphrase every time I unlock but once a day isn't so bad.
I don't run GrapheneOS, but I have an >15 character passphrase that must be used before biometrics can be used after reboot. I haven't used a 4-digit pin since the option to not use it was available.
The specific extra that grapheneOS adds is that you can have a required Fingerprint + PIN with a shorter easier to enter pin while also having a long first unlock passcode. Only a first unlock passcode then biometrics is not secure in the US if your device is in the AFU (after first unlock) state because you can be easily and legally compelled to provide a biometric unlock.
https://threecats.au/two-factor-pin-fingerprint-unlock-graph...
The option was there in Cyanogenmod back during the OnePlus One days. It was such a step backwards when it was removed. You almost had to wonder if it was deliberately done at the request of some TLA to prevent users from using too strong of a password for decryption.
I doubt it, mostly because phones were a lot easier to crack back in those days already so I doubt a TLA needed to push for it to be removed.
Never use a website to generate a password for something important like this. You can print out diceware passwords and roll dice.
I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.
As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
If you travel abroad you must unlock. No 4th amendment for you.
You can decline but then they can seize is that right?
It would depend on the country.
In the US, that is generally true. They cannot prevent entry (by citizens), but can keep the phone for a period.
This is mostly FUD. I've never been asked to unlock my phone when travelling abroad.
I believe the parent comment is talking about leaving US, coming back to the US and then having US's border patrol do so. If that is also what you understood, are you an activist or anyone whom would be of interest to the feds to be asked so? Otherwise saying "I've never been asked" sounds like a common thing for most people.
What's the BFD? I have nothing to hide! (I hear that shit all the time. So annoying.)
Reading this kind of stuff online made me afraid of international travel for many years. When I finally did it literally nothing happened to me.
Yes it's bad that the government overreaches, but it is also bad for your mental health to worry about it.
It's even worse for your mental to never think about It.
It's important to separate what can happen from what will happen.
The majority of people walking in the worse neighborhoods of LA or Chicago never have a single crime happen to them. But that doesn't mean that it's safe to go in a bad neighborhood - and it really doesn't mean it's safe to go there wearing designer clothing, gold watches, diamond rings and wearing your Apple VR device.
The same is true for travel. It's perfectly safe for the vast majority - but it's very important to be aware what may make you a target and what can happen to you if you are. Tens of millions of people visit the UK or China every year with no incident. But if you're a public active supporter of Palestine Action, or an active demonstrator against the CCCP respectively, be aware that you personally face a real risk from this travel, and your devices are actually very likely to be searched at those borders. Vice versa though (anti-CCCP activist traveling to UK, PA activist traveling to China) is perfectly safe, though.
Last time I checked, the Soviet Union was dissolved.
(CCCP = Union of Soviet Socialist Republics...)
https://arstechnica.com/tech-policy/2026/09/immigration-advo...
>CBP only searched the electronic devices of 55,318 international travelers,” the agency wrote, or 0.0013%.
would suck to be one of those 55 thousand people. I've never been bitten by a shark but I sure care about people that have?
I get asked to unlock my dev laptop every single time I go from the US to Montreal. The TSA person sits there and waits for my WM to boot before waving me past.
It seems more like they're trying to determine that it is in fact a laptop and not something resembling one.
That's been my experience as well. I've visited Sydney twice, and both times I've been asked to light up my devices. Granted, I was on work trips requiring three separate laptops which does probably look suspect, but once they were booted they did not request to browse anything and were satisfied to see them working.
All the more reason to dual boot into a decoy OS. Does not stop a task investigation, but lets pass a cursory examination where some thug might want to rifle through your data.
Dismissing something as false just because you haven’t personally experienced it is quite something
It seems foolhardy to carry your life savings around everywhere, encrypted or not.
If you really want to keep this stuff on a phone at least stretch to a second phone and keep it somewhere safe.
or a separate hard drive in a fireproof safe or something.
Exactly. Don't keep your life on your phone. We shouldn't have to take these precautions but unfortunately we do.
If you don't give access to law enforcement when they ask: straight to jail. Encryption is irrelevant in that situation. If they see the encrypted volume you need to provide them access.
Classic $5 wrench.
Having thugs on speed dial opens a lot of doors.
Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.
Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.
That's been my understanding until now as well... the latest on the case against Samuel Tunick has me worried and second guessing that blanket statement though...
https://nccriminallaw.sog.unc.edu/2026/08/03/giving-police-a...
Yeah, if you use it as a way to destroy data that gives them a whole new and powerful attack vector. 18 U.S.C. § 2232 is very broad.
That's completely different. Pleading the 5th and not testifying is completely different from giving false testimony - which is never protected. Even in a trial, if you are asked under oath if you handled the body, you are allowed to say that you invoke your 5th amendment rights not to respond; but you are not allowed to say "no, I didn't" if in fact you did (you can later be accused of perjury in addition to your conviction).
That case has the specific wrinkle that he provided a destructive duress code, he could have continued to refuse to provide the unlock code just fine legally. It's the use of the duress code that is likely going to be getting him in trouble and that falls outside of the existing defined protections about being compelled to unlock safes/computers etc containing possible evidence against yourself.
We'll have to see how that case goes but ultimately the reason he's getting in trouble is only tangentially related to his phone being encrypted. It's more correct to think of it like he smashed the phone to pieces (and imagine this definitively destroys the data for the sake of the metaphor) instead of it being about the encryption itself.
> The Fifth Amendment protects against self-incrimination.
You can still be held in custody for obstruction of justice:
https://www.findlaw.com/legalblogs/third-circuit/man-held-in...
It took four years before he could secure his release:
https://www.sophos.com/en-us/blog/suspect-who-refused-to-dec...
Self-incrimination yes, but not for cases when the person compelled has evidence to incriminate another process in a case.
Can't they just hand it to you say "you enter your passphrase, but don't divulge it to us and then hand us the phone". In other words hinging the passphrase divulging to the 5th can backfire in that respect. It like saying we have a search warrant, you open the safe for us, it's fine if you keep the combination to yourself, we just need to get inside.
So if an app installs an encrypted volume for which you don't have the password to, you go to jail? That doesn't make sense. How can they know if I have the password or not
They can't know, they infer. AFAIU, normally they just detain you at the airport and harass you to try to break you. To jail you they're technically supposed to be confident enough about you knowing the password to be able to charge you with a crime (presumably something like obstruction, possibly specific to immigration law, otherwise right against self-incrimination might prevent a conviction on failure to disclose alone), or have other evidence of some other crime. Then you end up in the legal system, where courts handle due process and a judge, preliminarily, and then a judge or jury decides if you knew the password.
Note that the recent high-profile case of a man being jailed involved him refusing to decrypt, rather than claiming he didn't know. He was deliberately trying to test the law regarding the permissible scope of inspection of digital data, to force the matter into the courts so the issues could be litigated in a controlled context untainted by other potential crimes; being arrested and charged was part of his plan.
It would seem wise to at least keep a backup in an E2EE cloud [1]. This could possibly allow you to not give access even if legally compelled.
>As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
Yes, it seems that way in the US: https://news.ycombinator.com/item?id=49922513
If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.
[1] https://www.privacyguides.org/en/cloud/
It seems to me you are taking a big risk. Some considerations:
> Cryptomator
Much security is poorly implemented; you can't count on it being effective. Even Apple, which takes security very seriously and has world-class talent and enormous resources, fails to implement security effectively sometimes (as in the OP). Can Cryptomator do better? Find the most respected - by professionals - security solution you can.
And on a device with many other functions - all the things you use your phone for - you risk all sorts of security holes in every function of app you use. And what happens to the data when your phone is backed up? Store the data on a single-purpose device.
Also, on an Internet-connected device, you make the data potentially accessible to the entire Internet. Use offline storage.
Bringing the storage device with you everywhere is asking for a mistake on your part - losing it, etc. Hide it someplace.
> or legal access
Ask a lawyer.
> The idea behind this so-called “inactivity reboot” is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology.
This is weird framing. The feature makes it harder for anyone to break into the device.
Not weird, not anyone can buy those equipment to break into a fully updated phone, in fact, it’s pretty much only law enforcement can or will have access to them, so that statement is true, it will make it harder for police to do so.
Huh, so this is essentially very similar be what this guy said to my suggestion of a factory reset timer in GrapheneOS being flawed. Apple's implementation of the reboot timer is flawed.
This goes to show for all the people that want GrapheneOS to implement a feature like hidden profiles–flawed features give people a false sense of security and should not be implemented (that's not to mention deniability may not even be a good feature if it was technically possible to implement it well).
Me:
>What about a duress timer working as the reboot timer but it wipes if you don't unlock within the time period. Would that have any advantages for destruction of evidence or deniability?
HybridStatAnim8:
>That would not be viable because the hardware does not support it. It cannot be implemented in the OS because the OS can be turned off or exploited endlessly. For GOS to consider it, it would likely need to be backed by the secure element.
>Duress PIN is deemed acceptable to implement in the OS because it is expected that the user is the one to enter it, so it has not fallen into the hands of attackers who may bypass it. Once attackers have it, you are effectively gambling. Account for that in your threat model and do not let it get to that point.
https://news.ycombinator.com/item?id=49040342
I wouldnt be surprised if they had a backdoor into the Qualcomm chip that Apple decided to oddly still include in most of their US iPhones vs the international versions that come with their own internal modem
Offtopic:
>Even if that device doesn't have the ability to turn on Airplane Mode or to turn off the transmitters through the Control Center of iOS.
IIRC, the default on iOS is that anyone with your locked device can enable airplane mode which is concerning simply for thieves. But I suppose they have to use faraday bags anyway because of the Find My network.
So we pay Apple for friction. And the state pays for Graykey to remove it. Whoever wins that arm race this quarter determines what our rights are worth in practice.
Well, that's assuming you are ever able to claim your phone back. From what I understand police might just keep it indefinitely until they are able to access it, unless you get some kind of court order that it he returned to you
Even then, who enforces the court order? :/
Ooh, I wonder whether Apple made the classic mistake of using a wall clock timer when they should have used a monotonic (local) clock timer.
edit: having personally gone through this kind of mess, the correct solution is to use strict typing to make sure you keep track of the difference between times and durations and the difference between different clock types. Don’t use plain integers and also don’t try to fudge it the way that Go’s standard library solution does. The modern C++ library is actually pretty good, although you need to use very recent versions of the standard for full functionality.
Is it maybe providing a bogus NTP server or something? Maybe the automatic reboot feature can be moved to the Secure Enclave or something, and made to only rely on the hardware RTC in a way that can't be tampered with.
Here's a deeper dive on that question:
https://naehrdine.blogspot.com/2024/11/reverse-engineering-i...
Tl,dr: it's likely baked into the sep, no ntp
I'm wondering if you put the phone into a mode where it thinks it's dialing emergency services or contacting them via crash detection etc that it won't reboot. I could picture a scenario where the code is written to never disrupt an emergency services call.
Full disclosure I don't own an iPhone so this may not even be a thing. Just guessing based on liability risk from Apple of "what's more important than protecting the phone"
Does this mean iPhones are worth more to steal?
No. This requires an expensive license for a government agency to purchase in order to take advantage of this functionality.
Can you provide a reference to that?
Unfortunately not a one I can prove to you online. I have a family member who is a district attorney, so that's my source. He said that that companies like the ones mentioned in the article sell licenses to unlock a single phone to a city or county. The city or county pays if they consider it worth it. The cost can be 5 figures.
(so the people that discover these exploits will sell them to the companies for 6 or 7 figures, far more than they would get from an Apple/Android bug bounty)
The article references Magnet Forensic’s Graykey being used for this. Wikipedia shows its like 15-30k per year[1]. Doubt the relevant exploit is available to the average phone thief.
[1] https://en.wikipedia.org/wiki/Grayshift
But still available to the above average phone thief that has a buddy in digital forensics that helps him prep the goods for sale.
Government contract data is public
Here's a renewal of one, presumably basic, license:
https://bidbanana.thebidlab.com/contract/4jKIvKMvZdoWo3d6K6q...
The product is not publicly available, and is sold only B2G: https://www.magnetforensics.com/products/magnet-graykey/#par...
Sounds like “this tsa approved lock needs a special key you can totally not just buy on Amazon”
This article seems completely unrelated to theft of devices.
Perhaps for a short time. As soon as Apple understands the exploit I expect them to patch it. They may even back port the fix to older iOS versions as well.
iOS has a remote erase feature. Its also a leaked video and doesn't show which version or model. So it could be something that is already patched, or soon will be. Remember to always keep your OSes update.
It's a bit difficult to remote erase your phone while you are in custody.
Unless you are Norwegian royalty and are notified of your upcoming arrest, then you can wipe all you need.
The first thing the authorities know to do is put your phone in an RFID bag/enclosure so it can't talk to the outside world.
I wonder why Apple, with its resources, doesn't take the lawfare approach to someone attacking its phones, for profit, and damaging its reputation.
Well first on the things you can do right now till apple figures it out, you should have control center disabled while the phone is locked, you can find it under “Allow Access When Locked” in face id and passcode settings, while -per the article- this won’t stop them, it sure will make it harder as by the time they try to gain access the 72h might have passed and a reboot happens. Second, they definitely fake the internal clock through the port, and because connected phone will keep correcting it through the NTP, hence it’s crucial to them to isolate the phone, so your job is to make that harder on them or delay it enough till it reboots itself. I think some of the quick counter measures apple can do now is allowing custom reboot periods, remote reboots through icloud, and disabling the possibility of manipulating the time through the lightning/usbc port.
> AFU
Good name.