Cops Can Bypass iPhone's Automatic Reboot To Get Into Locked Phones (404media.co) 41
An anonymous reader quotes a report from 404 Media: A company that makes phone hacking devices claims to have developed a solution that freezes iPhones in a state that lets cops more easily access sensitive data inside them, according to a video obtained by 404 Media. [...] The new technology to get around inactivity reboot was developed by Magnet Forensics, the company behind GrayKey, a popular tool sold to law enforcement agencies that allows them to unlock and access data stored in iPhones and Android smartphones. Magnet has developed a new device called GrayKey Preserve and a feature for its regular GrayKey devices called Evidence Preservation Mode, according to the video.
"This is an absolute game changer for iOS forensics and a function that I wish we had years ago," a Magnet employee says in the leaked video, specifically mentioning that the solution is targeted at the iPhone's inactivity reboot feature and the data it makes unavailable. GrayKey Preserve and Evidence Preservation Mode are also designed to combat another iPhone feature that automatically deletes certain data -- such as cached locations, and recently deleted photos and iMessages -- after a certain number of days. "We're gonna be able to preserve that data for an infinite amount of time."
[...] 404 Media shared a transcript of the video with Jiska Classen, a researcher at the Hasso Plattner Institute who studies iPhone security. While Classen said that it's impossible to know for sure how Magnet's new feature works based on the video, she posited some theories and agreed that it is "quite a game changer" or "at least puts things back to where they were before inactivity reboot." She thinks Magnet has found a way to manipulate the iPhone's clock, effectively "slowing down time" or even "stopping the clock from ticking, even after a reboot." Most likely, according to her, the GrayKey may disable the iPhone tasks that set data to expire. The "inactivity reboot" feature mentioned above was added to iOS in November 2024 and automatically restarts iPhones that have not been unlocked for 72 hours, making them harder for police to access using forensic tools.
"This is an absolute game changer for iOS forensics and a function that I wish we had years ago," a Magnet employee says in the leaked video, specifically mentioning that the solution is targeted at the iPhone's inactivity reboot feature and the data it makes unavailable. GrayKey Preserve and Evidence Preservation Mode are also designed to combat another iPhone feature that automatically deletes certain data -- such as cached locations, and recently deleted photos and iMessages -- after a certain number of days. "We're gonna be able to preserve that data for an infinite amount of time."
[...] 404 Media shared a transcript of the video with Jiska Classen, a researcher at the Hasso Plattner Institute who studies iPhone security. While Classen said that it's impossible to know for sure how Magnet's new feature works based on the video, she posited some theories and agreed that it is "quite a game changer" or "at least puts things back to where they were before inactivity reboot." She thinks Magnet has found a way to manipulate the iPhone's clock, effectively "slowing down time" or even "stopping the clock from ticking, even after a reboot." Most likely, according to her, the GrayKey may disable the iPhone tasks that set data to expire. The "inactivity reboot" feature mentioned above was added to iOS in November 2024 and automatically restarts iPhones that have not been unlocked for 72 hours, making them harder for police to access using forensic tools.
GrapheneOS ftw (Score:3, Insightful)
Re: (Score:2, Funny)
Re:GrapheneOS ftw (Score:5, Insightful)
To everyone who believes that innocent people should not have privacy, may you get all you wish for. But just you. No one else.
Re: (Score:3)
"May you live in interesting times, May you gain the attention of powerful people, May you get what you wish for."
Re: (Score:3)
"May you live in interesting times, May you gain the attention of powerful people, May you get what you wish for."
I have told people, do as you like, commit crimes as you like. You do you.
But I have also told people that if you for a new your second, believe that using your smartphone is at all a good way of assisting in whatever you feel like doing - you are not as smart as you believe you are. They are not secure, they are a little walkie talkie, that transmits radio waves that can be listened to. As noted here, they are not at all secure.
The very technology that allows the cellular system to function is exactly
Re: (Score:2, Interesting)
You're in jail. You did nothing wrong, except to advocate to give whatever power to the state the state wants. Good luck with your lack [google.com]
Re: (Score:2)
It's so interesting to me how people who frequent a site like Slashdot have no imagination. I can decrypt your phone? I can build a motive. I can build a story. What's worse, is I can plant evidence. You were here and there, you google'd for this, read an article about that. Just so happened to be close to this, and that. Suddenly you are arrested and you have no idea why. You're in jail. You did nothing wrong, except to advocate to give whatever power to the state the state wants.
So is it your thesis that the police can and will plant information on my phone for the Lulz?
I suppose there is a no-zero chance, just like there is a none-zro chance I can shit out a singularity.
Yeah, everyone in jail is innocent. And you are quite paranoid.
Now ima gonna give you nightmares. I make certain when I am at a store that I look at and wave to the cameras. I'ma going to buy everything on credit cards. In the even I am arrested in one of your Cops plant evidence schemes, I'ma going to sub
Re: (Score:1)
https://www.themarshallproject... [themarshallproject.org]
Re: (Score:2)
That's great. But until they do prove your innocence, I guess you can just enjoy your time in prison. It'll be a nice little holiday for you!
First off my fear filled friend, I'm exposing my innocence, not proving it. I'm providing an alibi.
Perhaps you do not like alibis? If a gas station has me on camera, time stamped, and my credit card was used to purchase gas, or a soda, on my credit card, while my cell phone pings off a local tower, that goes a hella long way to provide an alibi.
What is your solution, homie? I just gave a fine way to show your location, and show your innocence if questioned. All by outside sources.
And yes, not all pol
Re: (Score:2, Informative)
So you're cool with the Government having a remote VNC connection to your phone and computer, that they can view at all times?
After all you aren't doing anything wrong and it can prove your innocence if you are ever accused of anything; the Government already has full access to your Computer usage history right? Every good Citizen should let their Government have full view rights to their systems. And why not write access, after all they may need it?
Better just hope that the pretty new colleague you took o
Re: (Score:2, Flamebait)
So you're cool with the Government having a remote VNC connection to your phone and computer, that they can view at all times?
After all you aren't doing anything wrong and it can prove your innocence if you are ever accused of anything; the Government already has full access to your Computer usage history right? Every good Citizen should let their Government have full view rights to their systems. And why not write access, after all they may need it?
Better just hope that the pretty new colleague you took out to lunch last week; her ex boyfriend isn't a police officer and isn't of the very jealous type. Do we not see such stories appear on Slashdot regularly?
I feel sorry for people like you. Living constantly in terror and fear of popo, Why do you not move to another country where there is total privacy.
My entire point in all of this, is that you can do whatever you want to do. But using insecure devices is stupid. But you have a narrative that must be served.
Re: (Score:1)
Re: (Score:2)
"Give me the man and I'll give you the case against him." -- Soviet secret police chief Lavrently Beria
Re: (Score:3)
I think it is more the famous quote: "If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him," Cardinal Richelieu. Applied to your phone there's far more than six lines to trawl and disingenuously piece together a narrative of ones' choosing from.
Yes, so what on earth are you doing on Slashdot? This certainly has morphed, from me making a truthful admonition to people that their phones are not a safe space to me somehow being part of the police state, where they are gonna get ya, and can manufacture all the evidence needed, and all citizens are doomed.
This isn't even to make some sort of statement that bad things can't happen. Of course there are bad police, just like there are bad people. Are all people evil? Are they evil because some people mak
It's a brain problem (Score:2)
If you put a lot of effort into it you can take somebody like that and compensate. Like taking a scrawny kid and getting them in shape maybe with a little bit of HGH or the mental equivalent. But good luck doing that. Guys like Elon Musk and Bill Gates aren't go
Re: GrapheneOS ftw (Score:1)
isn't this a form of DRM piracy? (Score:5, Insightful)
how is overcoming a game's DRM and related IP theft-prevention efforts 'illegal' any different than this?
or maybe reverse engineering an app so you don't have to pay for it
legit quesion requesting thoughtful feedback, not politics nor a zealot's rantings
Re:isn't this a form of DRM piracy? (Score:5, Informative)
Re: isn't this a form of DRM piracy? (Score:3)
Which of course is how you know that we're slaves
Re: (Score:2)
replying to myself... from the summary, it appears to be a private company that does this and then sells the capability to police/govt; that's not the same as the govt doing it
Re: isn't this a form of DRM piracy? (Score:2)
Re: (Score:2)
I was thinking the same thing. Of course the government has their own way around the rules. However, what if you turn off your device before arriving? It's current state is off and encrypted and will remain encrypted until you unlock it. if you don't unlock the device then the "current state" of the device is not as useful.
Just a thought.
Seems like a business opportunity (Score:2)
Re:Seems like a business opportunity (Score:4)
The government makes an example out of you. https://arstechnica.com/gadget... [arstechnica.com]
Re: Seems like a business opportunity (Score:2)
That would be destruction of evidence, we just had a whole discussion about this recently where it was established that this is the legal reality. Please please please look up how it works before saying anything at all, please.
Re: (Score:3)
Quite. Invoking a self-destruct mode within sight of whatever cop wants the data is a Bad Idea. There's room to argue whether this is how it ought to be, but this is currently how it is. Don't wipe your phone after being asked to hand it over, unless you KNOW it contains data that will get you (or others you care about) in more trouble than a 'destruction of evidence' charge, or unless you want to make an expensive stand on principle. There are legitimate folks who live in that gray area: political diss
Re: (Score:2)
If you can't VPN - a popular thing for teenagers is to use Hidden Containers to hide their porn. Load up a fake calculator, put in the right digits and there it is.
Would not having 2 logon codes - 1 a normal one, the other one also logs you on as normal but discretely wipes the hidden containers - be a better thing?
A wipe code or a "honeypot" code is no good because the police can tell and thus will charge you. If they log on and they see a "honeypot" environment with a few token internet searches and no c
Re: (Score:2)
And the public arms race continues (Score:4, Interesting)
But we the people only know that we can't trust the government to control themselves, and we can't trust the tech giants to control themselves, and we can't trust the government to control the tech giants, and we can't trust the tech giants to protect us from the government.
Where is King Ludd when you need him?
Correction (Score:2)
"This is an absolute game changer for iOS forensics and a function that I wish we had years ago," a Magnet employee says in the leaked video
"This is an absolute game changer for iOS forensics and a function that I wish we had years ago," a Magnet privacy rapist says in the leaked video
There FTFY.
Surprise? (Score:3)
I won't expect US devices not to have government backdoors in one way or another. Sure they can talk a lot about secure elements and so on. The actual backdoor is then placed somewhere else and doesn't need to crack that.
If a device is in regular use (no before first unlock state), I for example expect that both Apple and Google are willing to push a special update to the device. Both stores are capable of installing apps without user interaction on the device and any limitations why this usually needs user confirmation when triggered via web can be bypassed by the companies. Both stores run with elevated privileges and can probably push more changes than just installing and updating apps (which still would run in a sandbox).
I would not even fully trust the hardware. It is way harder to find backdoors in there. Again they probably rather target the firmware of the modem or something like this and not the secure element. Every security researcher focuses on if the security features are watertight, so you place something that can access data once the secure element is unlocked somewhere where nobody is looking for it.
That's also why Graykey has less options (they leaked slides some time ago) in the before first unlock state: If the encrypted partition is not mounted (or the FS based encryption not unlocked) you need to target the secure components instead of having some trojan software exfilterating the unlocked data.
Re: (Score:2)
What else should they do? You cannot write in the ToS "We reject to follow the governing laws". The only thing you can do is to minimize your own options, like verifying a PIN against a secure element that has a baked in backoff delay.
Even then it is unclear if laws like the patriot act cannot force the company to implement a backdoor in this process so they are able the next time. So maybe the secure element enforces the brute-force protection, but the next update can make the pin entry screen save the pin
Do not trust your phone (Score:3)
It should really not be needed to say this, but apparently it is: Do NOT trust your phone. Your phone is not your friend. Unless you are an expert user of encryption, whatever is on your phone is not secure. Your phone will record your location and track you. Your phone is an attack vector.
is it just a fake NTP server? (Score:3)
From the description, I would bet it is just a metal box with inside a 5G spoofer wich provides a fake network time which does not advance.
If you think this may impact you, set the iphone time and date to "manual"
And maybe it's time to do NTP over SSL, and for clients to only accept network time from well reputed sources