A company that makes phone hacking devices claims to have developed a solution that freezes iPhones in a state that lets cops more easily access sensitive data inside them, according to a video obtained by 404 Media.

This is the latest salvo in the never-ending battle between Apple and companies that help cops — sometimes those in authoritarian countries — break into iPhones.

In November 2024, 404 Media revealed Apple quietly introduced a new feature in iOS that automatically reboots an iPhone that has not been unlocked for 72 hours. The idea behind this so-called “inactivity reboot” is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology.

At the time of Apple’s change, law enforcement agents expressed concern about this new feature, given that oftentimes they can’t immediately try to break into iPhones that have been seized. That could be because police are still waiting for a court authorization to do so, or there is simply a backlog of devices to unlock, for example.


Archive: https://ghostarchive.org/archive/DuJxb

  • SirEDCaLot@lemmy.today
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    1
    ·
    15 hours ago

    Most smartphones encrypt the majority of their storage these days.

    This means there are two states the phone can be in.

    BFU, or Before First Unlock, is the most secure. When you power on the phone it has just enough software in unencrypted storage to come on, initialize its hardware, start some background processes, and display an unlock screen. This is the most secure state for the phone. When you type in your password, the password itself decrypts the actual key which is used to decrypt the main storage. Without that password, the data is essentially useless as it cannot be decrypted. Also, most phones are now set up so that if you try the wrong password 10 times, it will erase the main storage encryption key which means the data is completely unrecoverable forever. In general, it doesn’t matter what you can exploit BFU because there’s very little running to exploit and the storage encryption key is usually stored in a secure enclave, that is a special part of a chip that is designed to resist tampering.

    Once you type in your password the first time, the phone is AFU, or After First Unlock. The key to access main storage is held in memory, it is being actively used to read and write from that storage as software is running on the phone like email, background apps, etc. The prompt to unlock the phone looks exactly the same, but in reality the phone is in a much less secure state. There’s plenty of software, both system and apps, running for you to try to exploit.

    The point here is that if you set the phone to regularly reboot, or to reboot if you haven’t logged in in a day or two, each time it reboots it switches back to BFU state.

    And so if some government agency has arrested you and seized your phone, you want that reboot to happen because if the phone automatically reboots before they manage to get into it, it becomes much much harder for them to get in.

    • trailee@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 hours ago

      Well said, that’s exactly what I was getting at. Apple has a Shortcut command that can switch to BFU - it’s called Reboot - but they specifically prevent users from setting it up to run on a schedule of their convenience. They might be afraid of accidental boot loops, or breaking wake up alarms, or something else - they haven’t published reasoning anywhere I’ve seen. But I think it’s pretty poor of them to restrict the feature.