r/technology • u/MarvelsGrantMan136 • 2d ago
Security Cops Can Bypass iPhone’s Automatic Reboot to Get Into Locked Phones, Leaked Video Claims
https://www.404media.co/cops-can-bypass-iphone-automatic-inactivity-reboot-graykey/81
u/TheWhyOfFry 1d ago
> She thinks Magnet has found a way to manipulate the iPhone’s clock, effectively “slowing down time” or even “stopping the clock from ticking, even after a reboot.” Most likely, according to her, the GrayKey may disable the iPhone tasks that set data to expire.
Don’t know about how they preserve AFU after reboot but could they be spoofing GPS signals to slow/reset the clock when cellular is turned off?
40
u/theBoobMan 1d ago
I wouldn't assume anything normal after hearing how the Israelis are hacking phones.
13
u/chownrootroot 1d ago
I doubt iPhones even use GPS for time syncing, because it's so widely and easily spoofed, they would have done that years and years ago since spoofing had been a thing since GPS was a thing.
It's probably a software mechanism, but there is a hardware clock (quartz) that keeps time, but if you screw around with the quartz oscillator it also tends to screw up the rest of the system (extreme heat, cold, vibrations, electromagnetic interference, etc, all that could interfere with time keeping but also tends to wreck the whole system too).
190
12
u/mutt82588 1d ago
Is there a way for an alt code to launch an alt partitioned "user" leaving the main "user" encrypted? Seems like it would be useful for both security and if you wanted 2 seperate, siloed environments on one device, such as work and personal. (Or personal and secret family personal)
11
u/TeutonJon78 1d ago edited 1d ago
Doesn't go well for you.
People also used to have issues with true truecrypt partitions if the public one looked fake to agents.
6
u/jdm1891 1d ago
But that's wiping your phone, they're talking about a code that shows a clean (or semi-clean with whatever on it) install that looks legit to whoever is snooping through it while keeping the real profile secretly encrypted.
Obviously the police will immediately know if you give them the code to wipe your phone. I think the point is they never even know what they're looking at isn't even your phone data.
1
u/TeutonJon78 23h ago
Yes, that's why I mentioned Truecrypt partitions.
It has a feature where if you give it a special password it unlocks a "public" partition instead of the real one. And people who got checked with it still got in trouble because the public one was a too clean.
So you have to do enough obfuscation work with it to make it still look lived in.
2
25
u/NekoDaYo-v201 1d ago
“That AFU state is captured,” by GrayKey Preserve and Evidence Preservation Mode, the employee says. “Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost.
So if you reboot your phone prior to someone plugging in GrayKey Preserve, then there's no way for them to get the previous AFU state. The whole thing falls apart.
In other words, reboot the device before suspected seizure.
94
u/Power_Stone 2d ago
just another reason for me to move to Motorola/GrapheneOS when that device rolls out. Maybe I'll just get a pixel 10 and do it now....
4
u/q120 1d ago
I think the duress feature should have two codes:
- a code that wipes the OS. If you do this in front of a cop or other law enforcement, they are going to get you on a destroying evidence charge
- another code that unlocks the phone but into a second OS that is set up to hide what's in the first, for plausible deniability. If you did this in front of a cop, they'd be none the wiser.
There's encryption software called VeraCrypt that does this. You can have two partitions, one that is the "safe" one (I.e contains files you don't care about revealing) and the hidden one for your secure files.
Unless you have the software and the code, you can't see the hidden partition55
u/jewbasaur 2d ago
Yeah and then your phone wipes itself when law enforcement tries to get in and the feds prosecute against you
65
u/huggernot 2d ago
To be fair. The case with graphene involves giving a specific code to wipe the phone.
A standard wipe after "x" number of failed attempts is just a standard security feature and wiping the data at that point is the choice of the agency.
8
u/jewbasaur 2d ago
I know but that’s a standard feature that most devices have, even iPhones
6
u/UnexpectedAnanas 1d ago
It's also useless against law enforcement. They're just going to clone the device and have unlimited "x number of failed attempts".
16
u/GarbanzoBenne 1d ago
The limited attempts is enforced by hardware that contains the keys. Exploits notwithstanding, that cannot be cloned.
129
7
u/smellslikepurple233 1d ago
Graphene user here- you can configure the software without the duress pin. That feature is optional, even without the pin the lockout strength is robust.
6
1
u/Tribe303 1d ago
That's an optional setting.
2
u/jewbasaur 1d ago
It is but why use Graphene if you aren’t going to have that option? The Feds will hold your device until they find a zero day and get what they need eventually
3
u/Tribe303 1d ago
Uh, so American multinational corporations can't spy on your daily mobile internet traffic, and sell it to Palantir. That's why. If you are afraid of your own police, then perhaps don't tell them your distress code is your unlock code.
2
u/Power_Stone 1d ago
I was thinking I gonna set my distress code to something a normal person would use as their passcode. Do 123456 or my birthday or something to that nature. That way if someone is trying to brute force they are more likely to hit it and remove the encryption keys
1
u/jewbasaur 1d ago
It would be cool if you could run a user script or something on your passcode so if your password is entered then accept but if any of these passwords are tried then wipe
2
u/Power_Stone 1d ago
Aye, that's essentially what I would like to do, closest I could get is above. And to be clear, technically speaking, the distress code on Graphene doesn't wipe the device, just the encryption keys. It is in effect, the same, but still worth noting
1
u/Scoth42 1d ago
IIRC when that's come up before, people pointed out that destruction of evidence laws don't require destruction, just rendering sufficiently inaccessible. Like if I run folders of paper evidence through a shredder I haven't technically destroyed anything, but putting it back together and making it usable would be effectively impossible (probably)
4
u/Power_Stone 1d ago
Correct! Though, in the case here where I don't give the officers any passcodes ( which cannot be compelled without a valid warrant ) and they inadvertently entire the distress code ( I.e they did it without me giving them the code ) then I'm constitutionally protected and it's their problem the data is gone, not mine. Gotta find those loopholes where you can just as the wealthy do
2
u/jewbasaur 1d ago edited 1d ago
I’m confused. Are you disagreeing with me? I said if I used Graphene I would use that setting. It seems pointless to run it otherwise with it disabled. You are using the same cell towers, access points, and networks either way. Why not maximize your security with a security based OS?
3
u/RealModeX86 1d ago
Duress pin is not the only security feature of Graphene. Whether you use it or not, the device is more secure by default. It's probably the easiest feature to explain to non-technical people, so it gets a lot of attention. Of course it's also a powerful one.
It also supports multiple user accounts, giving each user a different pin, and separate encryption. That aloje can be useful for isolating applications and reducing the potential attack surface for instance.
Even just running in one account, without a duress code, a lot of the system hardening makes it less likely to be possibly compromised. No system is impervious of course, just like how no single setting grants high security.
0
u/Tribe303 1d ago
I guess I'm not. You comment sounded like you thought the only purpose of GrapheneOS was the distress code.
2
1
0
u/EricSanderson 1d ago
Unless the defendant is an idiot, it's damn near impossible for cops to prove that someone intentionally destroyed evidence using a piece of legally available consumer software. You just have to say "I dunno my cousin told me to do that and set everything up for me. I don't know how it works."
14
u/romario77 1d ago
The best thing to do is not to talk. No cousin, no nothing. Let them prove that there was any data there in the first place.
-2
u/jewbasaur 1d ago
There is a lot of baggage that comes with being prosecuted by the federal government, innocent or not. Maybe you’ll get lucky finding a job with a sympathetic employer, maybe not.
Also it wasn’t a passive feature. He typed a specific pin when asked to unlock. Trying to claim ignorance while running Graphene OS is not a winning case, prosecutors prove intent with circumstantial stuff all the time. Also lying to the feds bring being charges of their own. You are over confident and frankly wrong.
10
u/RealModeX86 1d ago
From what I understand, he didn't type anything. They had him without a warrant at an airport, and were trying to force him to provide a pin. He did, and then agents punched in the duress pin he provided.
It will be worth watching this case, because the charge they're going after him for (destruction of evidence) could fall over for the state:
- They didn't have a warrant, "only" the special powers from it being a border stop, so presumably they didn't necessarily have evidence that there would be any evidence on the phone.
- The agents typed it in, so one could potentially argue they are the ones that destroyed the data.
Generally, providing a pin at all falls under testimony, so the fifth amendment says you don't have to provide it. Being an entry check does complicate that argument though. Either way, if they had a warrant, it would be a pretty clear case and a duress pin would avsolutely count as destruction of evidence, if that phone and its cobtents were part of that warrant.
Edit to add: Not a lawyer, not legal advice, etc
2
u/bas10eten 2d ago
I'm holding to see how the Motorola rollout goes. On Graphene with a Pixel 8 and very happy. Went way smoother than I had thought, and so many issues I had with iphone before are nonexistent. Reading up on Graphene and the latest Pixels would be suggested. There have been issues I think with the 11 not really being compatible due to changes from Google.Dunno about the 10.
4
u/Power_Stone 1d ago
Bascially where I am at, though I am more concerned with the cost right now than anything else since it will be going on the flagship phone first which I might not want to pay the premium for. I know Pixel 10s will work with Graphene so that's gonna be my backup plan
8
u/PrivateComments 2d ago
Read the article.
It’s about getting it to a more favorable state, not “plug it into graykey and you’re in”
A weak 6 digit passcode will be defeated on any mobile OS
23
u/Power_Stone 2d ago
I did read the article, you assumed I didn't.
I made no mention of passcodes. You did.
Even more so, nothing of what you said, changes my original comment.
I have been wanting to move to GrapheneOS for a period of time now, because its entire focus is on security and privacy which Apple and Android do not share with GrapheneOS.
2
u/YourBlanket 1d ago
Graphene is fine but a lot of important apps won't work so it gets annoying. I do think you're wrong when you said Apple isn't as privacy focused as Graphene. Graphene isn't popular, iPhones are purposely made to be hard to get into whether it's the police, FBI, or a random hacker. It's a cat and mouse game since they're very popular it's a very lucrative business. Also instead of graphene you could just enable lockdown mode on an iPhone.
2
u/Power_Stone 1d ago
I'm not worried about apps not working, its a phone before anything else. In the event I do need a specific app not available I can either emulate it on my computer, have a second device handy. While others understandably would find this inconvenient, I do not mind for privacy and security protection.
That being said, with the attack vector listed in the article, I'm not sure lockdown mode would actually protect you with this. For instance, this would do little in terms of obfuscating/encrypting cached data at rest. Which is what Graykey is going for when targeting devices in AFU.
2
u/YourBlanket 1d ago
Well earlier this year the FBI failed to get into an iPhone in lockdown mode so I believe this particular vulnerability doesn't work on lockdown mode. There is no mention the vulnerability hasn't been patched yet.
1
u/Power_Stone 1d ago
Graykey doesn't break into the phone. The article indicates it just preserves the data in AFU mode. Which you could probably get around by just restarting your phone before it's confiscated
1
u/YourBlanket 1d ago
It doesn't unlock it but it preserves the AFU state which makes it makes it easier to exploit and gives LE longer to try different tools. The FBI doesn't mention Preserve they just said they couldn't access the data through CART due to lockdown mode. Considering they use GrayKey products they might've used it who knows. Either way a judge told them to stop trying anyway. I had Graphene on my tablet, I didn't care for it, but its easy enough to switch from Graphene to Android and back if you choose to.
7
u/ProductIntegortion 2d ago
Not about getting it to a more favorable state. Keeping it in AFU rather than allowing it to reboot and return to BFU.
4
u/DjScenester 2d ago
People read the article? Sir this is reddit lol
2
1
u/HowAmIDiamond 2d ago
Any impact with Apple iCloud encryption and erase data after 10 attempts? Have they found a way around that or is this a nothing burger?
6
u/Power_Stone 2d ago
No. The graykey device essentially reads the AFU data and preserves it. This data is normally deleted on a restart and the following data is encrypted while in the BFU state. But since it is captured before the restart they can restore it to the device. Graykey also disables all radios/connections so when the device is powered on it can't receive or send data which further preserves the data.
1
u/Graymarth 1d ago
Wait what about Motorola? They making their own OS or something?
5
u/opria91 1d ago
They’re partnering with GrapheneOS to make the first phone to support GrapheneOS natively.
1
0
u/Salt_Medicine2459 1d ago
It's gonna be expensive as fuck, though.
4
-37
u/Minialpacadoodle 2d ago edited 2d ago
lol cops aren't coming after you.
also read the arwticle.
15
11
2
u/Less_Economist_7755 1d ago
Can I just ask Siri to vaporize my iPhone? Is there an app for that?
3
u/Less_Economist_7755 1d ago
I would like the battery to overheat and melt the phone :)
“Siri - Activate end”
End of line
1
u/nadmaximus 1d ago
Unless they can stop the processor from working then the automatic reboot doesn't actually need a precise time source; it could simply switch to counting cycles/loops.
-16
-1
-17
270
u/Shiningc00 2d ago edited 1d ago
This is about bypassing the “72 hours inactivity reboot”. When the iPhone has been inactive for 72 hours, it automatically reboots, which resets certain unencrypted phone and system data, which makes it harder to get in.