A company that makes phone hacking devices claims to have developed a solution that freezes iPhones in a state that lets cops more easily access sensitive data inside them, according to a video obtained by 404 Media.

This is the latest salvo in the never-ending battle between Apple and companies that help cops — sometimes those in authoritarian countries — break into iPhones.

In November 2024, 404 Media revealed Apple quietly introduced a new feature in iOS that automatically reboots an iPhone that has not been unlocked for 72 hours. The idea behind this so-called “inactivity reboot” is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology.

At the time of Apple’s change, law enforcement agents expressed concern about this new feature, given that oftentimes they can’t immediately try to break into iPhones that have been seized. That could be because police are still waiting for a court authorization to do so, or there is simply a backlog of devices to unlock, for example.


Archive: https://ghostarchive.org/archive/DuJxb

  • gravitas_deficiency@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 hour ago

    Reminder: if you anticipate being in contact with law enforcement and have any spare moments at all: restart your phone and do not unlock it. This “before first unlock” (BFU) state does not yet have auth keys loaded and secrets decrypted in active memory, and is thus rather more difficult to exploit and gain entry to.

  • weps@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    12 hours ago

    but that’s only needed when apple doesn’t give access to the phone which they just do when there’s a warrant

    cops have no problems getting in iphones there’s just a little delay sometimes

    they still have all the hacking technology too

    • boonhet@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      16
      ·
      10 hours ago

      [citation needed]

      Apple’s been pretty good at patching vulnerabilities and a pain in the ass for cops trying to get into phones, with the only actually better option being GrapheneOS.

      • weps@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 hours ago

        I get it from watching crime interrogations.

        When they get the warrant they’re allowed to ask for passwords but they don’t need them to read everything on the phone. It goes to the lab.

        If it’s in the cloud then apple reports the crimes anyway.

        • W98BSoD@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          When they get the warrant they’re allowed to ask for passwords…

          Ok; key word is ask. I don’t have to tell. Or what if I’ve genuinely forgotten it?

          … but they don’t need them to read everything on the phone. It goes to the lab.

          So then why ask?

          • weps@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 hours ago

            it’s cheaper to get the passwords. They’re allowed to ask but don’t need them. That’s why they ask. You don’t have to give the passwords because they’re allowed to ask. People often misunderstand and think they have to give the passwords because there’s a warrant but you don’t have to. They take the computer stuff to the lab anyway and the tech companies give access to the cloud stuff.

  • JiveTurkey@lemmy.world
    link
    fedilink
    English
    arrow-up
    63
    ·
    17 hours ago

    If only we could see what apple was doing under the hood. If only companies that constantly pat themselves on the back for being secure could be open source.

      • RedWeasel@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        ·
        11 hours ago

        For chips released in 2018 and 2019. To the best of my knowledge anything newer than a iPhone 11 nothing has yet been found and announced. So 7 years ago. That said you know that if there is some unannounced vulnerability and some spyware company or government knows of it, they are not going to report it.

  • paraphrand@lemmy.world
    link
    fedilink
    English
    arrow-up
    20
    ·
    16 hours ago

    Well, I expect this to be patched asap now that it has leaked. Apple has been quick to patch things when such leaks happen. Hopefully that’s the case here too.

      • MajorasTerribleFate@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        On the assumption Apple wants to facilitate access to such authorities, were I Apple, I’d have either already made available redundant backdoor so disabling any one wouldn’t be a problem; or, I’d have others ready to be opened when I need to shut others down.

    • naught@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      5
      ·
      4 hours ago

      I have a family member who is a cop, and they told me this was possible months ago. I doubt Apple doesn’t know

  • NateNate60@lemmy.world
    link
    fedilink
    English
    arrow-up
    112
    ·
    21 hours ago

    In the US, if cops get into a phone before a warrant, even if a warrant is issued later, all evidence from the phone is suppressed as illegally obtained.

    This is a bigger concern with respect to intelligence agencies who conduct mass surveillance.

    • Séimhe (sé / é)@lemmy.world
      link
      fedilink
      English
      arrow-up
      148
      ·
      21 hours ago

      even if a warrant is issued later, all evidence from the phone is suppressed as illegally obtained.

      This assumes a healthy and functioning country. I wouldn’t assume that of the US in particular. People are being hunted, kidnapped, imprisoned and murdered by the government as we speak.

      • NateNate60@lemmy.world
        link
        fedilink
        English
        arrow-up
        62
        ·
        20 hours ago

        I’m a law student in the US, so I’m actually privy to this information in the form of all the talks that they have judges and lawyers giving.

        You may not assume that the US judiciary is healthy and functioning, but it is not as broken as most international observers (or chronically online Americans) think it is. In particular, if you have been observing the Department for Justice’s results recently, you’ll notice a few things:

        1. Because the Department has been hiring for loyalty and not legal skill, the Department has lost most of its prior prestige. Previously, clerking for the Department was a competitive law school position. Now, the top legal minds then to avoid it. As a result, the quality of legal skill at the Department has decreased, drastically.
        2. Judges in the federal judiciary, with the exception of some notable Trump cronies, is actually very willing to uphold existing procedural law and rule against the government. It happens extremely regularly.
        3. When judicial orders are ignored, it is almost always temporary and not in any lasting way. Federal judges still do threaten and issue contempt of court penalties and disciplinary referrals to officials who blatantly disobey court orders.

        So in short, you are partially correct and partially wrong. The judiciary of the US has shown to be remarkably resilient considering it has withstood two years of a fascist in power and in full control of the legislature.

        • someone@lemmy.today
          link
          fedilink
          English
          arrow-up
          1
          ·
          56 minutes ago

          Go learn about the harmless error rule. You are incredibly naive. DAs and cops break the rules ALL THE TIME because once there’s a conviction the burden of proof shifts and a defendant, now convicted, in prison has the burden of proving (somehow, while behind bars) that in a theoretical other version of reality they wouldn’t have been convicted had the error not been made.

          It’s a nearly impossible standard to meet, especially difficult after conviction, and the remedy is not even necessarily release, merely a new trial.

          Not only that, even if a judge and DA and cops violate a defendant’s rights OVER AND OVER they still almost always apply the harmless error rule. Even if the trial is essentially infected with bias and procedural corruption (what could be deemed structural error), courts do not care.

          Many decisions the court makes are just denials without opinions also, so it’s not like the court always even justifies why they ignore a convicted person’s request. In other words, the appellate cases you’re reading as a law student showing one defendant got released over an error is a cherry picked case chosen by the court either to create the illusion of a fair functioning system or chosen because the situation is so egregious (that means terrible) that courts will look bad if they don’t overturn it.

          But no, there’s nothing functional here.You’re privy to nothing if you don’t understand that things haven’t really been functioning for a long time, primarily because the harmless error rule allows corrupt DAs cops and judges to do almost anything.

          • NateNate60@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            36 minutes ago

            With respect, we might not be observing the same things at the same places. I saw an DDA blow up her own case (defendant accused of putting GPS tracker on ex-girlfriend’s car) by accidentally mentioning that they traced a GPS tracker back to [defendant’s first name].[defendant’s surname]@gmail.com, and the judge decided this was fatal to their case because they forgot to put the name of the GPS tracker company employee on their witness list.

            This guy was 100% guilty. Two witnesses saw him do it and they found his fingerprints on the tracker.

            State v. Landon Heath Higgins, Oregon Circuit Court, case number 23CR14417 if interested.

            • someone@lemmy.today
              link
              fedilink
              English
              arrow-up
              1
              ·
              16 minutes ago

              I don’t know the circumstances, but occasionally judges toss trivial things to punish DAs for messing up. It rarely impacts cases with larger punishments. You’re likely referring to a misdemeanor case where the defendant may have gotten a plea deal for 6 months and had a good job and time in jail would have messed that up and resulted in a waste of county resources. Also, things like this occasionally happen to create the illusion of legitimacy. I am not sure if this is a case you read or if you witnessed the judge’s ruling, but the fact that you’re using what is likely a case that carries less than 365 days max time as an example of how a judge will destroy a DAs entire case is in itself revealing.

              Have any circuit court examples of cases carrying 10 years? 20 years? Life? No? Oh, I wonder why. Are you a clerk? Assisting an ADA? You’re completely biased and want to see things working. Go read about how impossible it is for the harmless error rule to get overcome on appeal, go read about how structural errors are essentially ignored or the remedy isn’t even release but just go back to start. There’s plenty of articles about this.

              https://harvardlawreview.org/print/vol-131/harmless-errors-and-substantial-rights/

              https://columbialawreview.org/content/criminal-procedure-rights-and-harmless-error-a-response-to-professor-epps/

              I also once saw someone steal a soda from a store and was going to get a month in jail but the judge tossed the entire case because the DA made a procedural error! The system must work!

        • Séimhe (sé / é)@lemmy.world
          link
          fedilink
          English
          arrow-up
          26
          ·
          19 hours ago

          First of all, you’re doing important work and I wish you well in your studies and career, for everyone’s sake.

          Thanks for the insight. Definitely some positives there. When ICE have added an innocent person’s data to be absorbed into (eg) Palantir’s database, how confident can we be that it is actually removed again?

          • NateNate60@lemmy.world
            link
            fedilink
            English
            arrow-up
            10
            ·
            16 hours ago

            If this is illegal (which I am not convinced that it is, even though it certainly should be), then a judge can order Palantir or the relevant government agencies to destroy the data. If there is a question about whether this order will be complied with, the court can appoint a special master to oversee it, but this is rare. Usually what happens is the court will take their word on it, but if it turns out they lied, then the court will impose a stiff penalty for contempt of court.

        • FaceDeer@fedia.io
          link
          fedilink
          arrow-up
          13
          ·
          18 hours ago

          Federal judges still do threaten and issue contempt of court penalties and disciplinary referrals to officials who blatantly disobey court orders.

          I guess this is my main point of concern right now, as an outsider. I know that the courts are still ruling against Trump and the Republicans fairly regularly, but then I hear about situations where they’re simply ignoring the courts’ rulings and little seems to actually happen as a result.

          What do those “disciplinary referrals” actually do? Do people actually get fired, or is it just something else for the Republicans to ignore?

          • NateNate60@lemmy.world
            link
            fedilink
            English
            arrow-up
            10
            ·
            edit-2
            16 hours ago

            Disciplinary referrals are issued against lawyers who break the court rules. Contempt of court is used against anyone (lawyer or not) who violates a direct order from the court. A lawyer who blatantly violates an order may receive both a disciplinary referral and also a contempt of court penalty.

            Before a court issues a penalty of any kind against anyone, they usually issue what is called an order to show cause, which essentially means the party accused of violating the rules must appear before the judge and explain why they should not receive a penalty.

            Disciplinary referrals are addressed to the state bar association, which are organisations comparable to guilds which license lawyers. The bar association can impose penalties against the lawyer which include:

            • Censure, a formal finger-wagging which leaves a permanent mark on their licence and is generally considered detrimental to future job prospects
            • Mandatory ethics training or re-take bar exam
            • Temporary suspension of their licence to practise law
            • Disbarment and expulsion from the bar association, which permanently revokes the lawyer’s licence to practise law. This typically cascades to all bar associations across the country.

            An example: Rudy Guiliani was a Trump lawyer who filed submissions before several courts containing information he knew to be false and raising allegations he knew were unsubstantiated, as a part of Trump’s scheme to overturn the 2020 presidential election. The New York bar association disbarred him for this, and the DC bar association took note and automatically disbarred him as well. His legal career is finished; he cannot legally be employed as a lawyer anywhere in the country.

            Contempt of court is an inherent power of the court to punish people who violate its orders. A judge can, on their own initiative, declare someone guilty of contempt of court and impose a punishment for it, which could include:

            • A fine, possibly an increasing fine until the order is complied with. The fine is paid personally by the person found guilty of contempt of court and no immunities apply.
            • Imprisonment for a fixed term, usually not more than a month
            • Imprisonment until the person complies with the order
            • Anything else the judge comes up with, that does not violate Amendment 8 of the US Constitution or relevant laws

            Example: A lawyer was fined $10,000 in March 2026 by my state’s Court of Appeal for submitting a brief containing AI hallucinations.

            • FaceDeer@fedia.io
              link
              fedilink
              arrow-up
              6
              ·
              16 hours ago

              Ah, so as this progresses the Republicans steadily run out of “competent” lawyers because they keep getting disbarred (or quitting to save their legal skins), leaving them with increasingly incompetent ones that have an even harder time accomplishing stuff.

              Here’s hoping their legal wells run dry quickly, I suppose.

              • NateNate60@lemmy.world
                link
                fedilink
                English
                arrow-up
                9
                ·
                16 hours ago

                Remember in the early days of Trump II when we were hearing about entire US Attorney’s offices quitting in protest? That no longer happens, but that’s what happens when top brass asks experienced, career lawyers to defend positions they know are indefensible, and insists they sign their name to hot garbage, that they know is the same kind as what got Rudy Guiliani disbarred.

                So yes, the Trump Justice Department is indeed running out of good lawyers and that’s why the US Attorney’s Office for DC is led by a Fox News commentator who happens to have a law degree.

              • Tollana1234567@lemmy.today
                link
                fedilink
                English
                arrow-up
                1
                ·
                15 hours ago

                they will have to keep sourcing them from legit law firms, but law firms require them to disassociate from the firm before working for someone like trump or gop.

            • grue@lemmy.world
              link
              fedilink
              English
              arrow-up
              4
              ·
              16 hours ago

              The judiciary really needs to start using “Imprisonment until the person complies with the order” a lot more early, often, and against people higher up in the DoJ org chart.

              • NateNate60@lemmy.world
                link
                fedilink
                English
                arrow-up
                4
                ·
                14 hours ago

                Judges generally issue escalating sanctions. A verbal admonition first, then a verbal threat to impose sanctions, then an order to show cause, then actual penalties.

                Despite what the media reports, the Administration always folds and complies because it would be embarrassing to have senior officials or government lawyers actually penalised for failing to comply with a court order.

      • BooBees@fedinsfw.app
        link
        fedilink
        English
        arrow-up
        20
        ·
        21 hours ago

        Yep, and the concern shouldn’t just be for yourself - authorities will clone the phones and then comb your contacts and social media and then add to their systems compiling relational data and use that to target people, often innocent people. Your phone data won’t just be used to harass or inconvenience or stress you out, it’ll be used to harm other people. You should care about that.

        • foodandart@lemmy.zip
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 hours ago

          Yup.

          This is why it is critical to have the numbers and contact info of as many of one’s family committed to memory, not the Contact list, as possible. Cops can’t get at what’s in one’s head (for the most part)…

    • halcyoncmdr@piefed.social
      link
      fedilink
      English
      arrow-up
      26
      ·
      17 hours ago

      In the US, if cops get into a phone before a warrant, even if a warrant is issued later, all evidence from the phone is suppressed as illegally obtained.

      This is not a hard and fast rule. There is the concept of Inevitable Discovery.

      If they find evidence during an illegal entry, they may later seize it lawfully under a search warrant and prosecutors may use it in court if they can supply an independent source, rather than benefit from the earlier violation.

      Real world example: In Nix v. Williams, decided in 1984, the Supreme Court considered evidence of a child’s body found after police obtained incriminating statements from Williams. Those statements were later determined to have been illegally obtained and were excluded. However, the body was located in the existing search area and the same type of location (a culvert) they were searching. It was simply in a search quadrant they had not gotten to yet. So the searchers would likely have found the body anyway even without those statements.

      • NateNate60@lemmy.world
        link
        fedilink
        English
        arrow-up
        7
        ·
        16 hours ago

        Well, as I’ve quickly learned, pretty much nothing in law is an absolute rule. Judges love making their exceptions.

        • IronBird@lemmy.world
          link
          fedilink
          English
          arrow-up
          5
          ·
          8 hours ago

          kinda the entire point of common law, just a vibes legal system designed around enabling english aristocrats to hold onto their power longer

        • halcyoncmdr@piefed.social
          link
          fedilink
          English
          arrow-up
          4
          ·
          16 hours ago

          That’s part for sure, but I’d argue that it’s more often lawmakers trying to phrase things to specifically carve out loopholes their donors want to exploit. Then judges having to work through the bullshit to determine what it actually says and whether those specific circumstances are covered.

          That example I have above for instance, should the body not be admissible as evidence just because the killer told Police where it was a few hours before they would have found it anyway?

    • W98BSoD@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 hours ago

      Ahh, yes. The old “I use this thing and because I use this thing it must be better than your thing.”

    • CompactFlax@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      44
      ·
      18 hours ago

      The companies who sell these bypass devices spend time on graphene too, don’t worry.

      The price of iOS exploits would suggest Apple’s doing a pretty good job in this area.

      • grue@lemmy.world
        link
        fedilink
        English
        arrow-up
        20
        ·
        16 hours ago

        I’m sure they do spend time on Graphene OS, but that’s not the same as being successful in cracking it.

      • Default Username@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        9
        ·
        18 hours ago

        I wonder if they spend time on Linux mobile devices, considering how niche they are.

        But then again, security through obscurity is not real security, and I’m not aware of any reasonable way to run something like QubesOS on a phone in any way that would be usable.

        • senko@ani.social
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 hours ago

          Smartphones had been vulnerable for pretty much it’s entire existence, and most of time, while true software do play a role, it’s been more about stuff such as bootloader exploits.

          Sadly Linux phones on it’s state are insecure by design.

        • Cethin@lemmy.zip
          link
          fedilink
          English
          arrow-up
          7
          ·
          12 hours ago

          I’m sure they spend time on Linux in general, since it is the most common operating system (and includes Android, so even bigger). I doubt they spend much, if any, effort on the specific subset of systems that make a Linux phone different from another Linux device.

      • halcyoncmdr@piefed.social
        link
        fedilink
        English
        arrow-up
        14
        ·
        17 hours ago

        On Graphene, Lockdown mode disables biometric login until you unlock it manually with your passcode, but the device is still in the less secure AFU (After First Unlock) state.

        You can also set it to restart the device if not used within a set time period. Various settings from 10 minutes to 72 hours. So if you haven’t touched your device within that time period, it will shutdown and restart, going back to the more secure BFU (Before First Unlock) state.

        • boonhet@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          2
          ·
          10 hours ago

          That’s no different than iOS in that regard then (minus the configurable restart time). But that’s about what I’d expect, not sure you could have a useable phone if it didn’t have an AFU state at all.

          • halcyoncmdr@piefed.social
            link
            fedilink
            English
            arrow-up
            5
            ·
            16 hours ago

            It’s almost like there’s only two ways to actually accomplish this type of thing. You can do the same basic thing but use different names to differentiate where/how that function is used.

            Lock it and require the passcode where the decryption key is still in memory because the system is running, or shutdown/restart the device so the decryption key isn’t in memory anymore.

            What would a third option even look like?

              • halcyoncmdr@piefed.social
                link
                fedilink
                English
                arrow-up
                6
                ·
                15 hours ago

                Are you. Understanding a standard shut down does what you want?

                What are you babbling about? Of course, that’s why I already said it. Twice.

                Both comments I have made in thi thread have mentioned shutting down or restarting the device to put it back into a BFU state.

                Since you clearly didn’t actually read the comments you are replying to… I’ll include the relevant parts from both below:

                You can also set it to restart the device if not used within a set time period. Various settings from 10 minutes to 72 hours. So if you haven’t touched your device within that time period, it will shutdown and restart, going back to the more secure BFU (Before First Unlock) state.

                Lock it and require the passcode where the decryption key is still in memory because the system is running, or shutdown/restart the device so the decryption key isn’t in memory anymore.

                You still didn’t answer the question I posed though… before replying in way that seems to indicate you either can’t, or refuse to actually read before responding condescendingly.

                Since you seem to think there should be another choice instead of doing the same two things to protect the device/data… what would a third option look like? Other than locking and disabling biometrics, or a shutdown/restart putting the device back into BFU mode.

                Or are you just stuck thinking a shutdown and reboot are technically different things? Even though that makes no difference here since they both put a device into BFU.

      • feannag@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        6
        ·
        18 hours ago

        You can disable. You can also two factor it e.g. fingerprint and pin, with also a long password for BFU.

        • LifeInMultipleChoice@lemmy.world
          link
          fedilink
          English
          arrow-up
          6
          ·
          18 hours ago

          The fingerprint is the way in they are using. Bio entries are owned by the police if arrested. Finger/face/eye. Passwords/passcodes are not.

          (Basically they own your body, not your mind without a warrant)

          • feannag@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            3
            ·
            15 hours ago

            Let me clarify: when I meant two factor, I mean both. You need both the print AND the pin to unlock. So its more convenient than a full passphrase (for first unlock) but still requires knowledge not just biometrics.

            • youmaynotknow@lemmy.zip
              link
              fedilink
              English
              arrow-up
              1
              ·
              10 hours ago

              Genuine question here. I don’t really get the idea of using print and then a pin. If I want more security, then I use the pin alone, if I want more convenience, then I use a print. Can someone please give me an example in which using both actually makes sense? I honestly don’t see how using both would benefit security, it certainly does not benefit convenience.

              I can see the use of 2 factor with a PIN and then a hardware key like a yubikey, or a pin and then a password, that does make sense to me, focused on security alone and doing away with convenience.

              • feannag@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                2
                ·
                3 hours ago

                The benefit is if your PIN was compromised your phone would still be inaccessible, barring them having you physically. It’s another layer of defense. Similar to a yubikey, if someone had your phone but not the extra hardware. Although I think using a yubikey every time I wanted to use my phone would be prohibitively inconvenient.

                Also, I don’t think PIN and password would be considered 2 Factor. That’s essentially just a longer password.

          • halcyoncmdr@piefed.social
            link
            fedilink
            English
            arrow-up
            5
            ·
            17 hours ago

            Lockdown mode disables biometrics while still leaving your device on, say if you know you’re going to talk to the police and don’t want to be forced to provide biometrics to unlock the device. And you can setup an automatic reboot after a set time period where it would return to a BFU state automatically.

    • glitch1985@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      17 hours ago

      And a removable battery. One I can guarantee the battery will pop off if I accidentally drop it while my hands are in the air.

  • trailee@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    12
    ·
    20 hours ago

    If Apple really cared, they would make it so that a Shortcut that performed the Reboot action was allowed to run on a schedule, unattended. But no, that’s specifically disallowed.

    • LifeInMultipleChoice@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      19 hours ago

      I assume that would just be shutting down the phone. When it boots up it required the passcode, which is what they want to bypass here

      • feannag@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        10
        ·
        18 hours ago

        No, this preserves the phone in an “after first unlock” state. They specifically dont want a phone to reboot or shutdown because then the encryption keys get dumped from memory and require the password to decrypt the keys.

        • LifeInMultipleChoice@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          18 hours ago

          Yeah… Aka if it was shutdown. It isn’t before first unlock state. So if you are going to get arrested, shutting the phone off mitigates all of this

          • Septimaeus@infosec.pub
            link
            fedilink
            English
            arrow-up
            3
            ·
            17 hours ago

            Disclaimer: I only use iPhones for security testing, so this is more from related literature rather than first-hand experience.

            IIRC the hardening unattended reboot could offer is already covered better by options like disabling biometric unlock, security key 2FA, enabling lockdown mode, enabling advanced data protection, disabling iCloud, disabling USB accessories, and so forth. Also unattended reboot seems like an easy prank vector or foot gun to render a device permanently inaccessible (i.e., device always reboots immediately after pin entry) requiring recovery mode reset or restore to fix.

            • LifeInMultipleChoice@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              ·
              17 hours ago

              A. If you want 2fa to unlock a phone fuck off B. One has to opt in to iCloud. (It’s way to fucking motivated and absolutely a forced thing in my opinion though)

              If you can’t download an app without being signed into an account… You paved the way for Microsoft. Literally were the worst of the worst and made it so. Even the Microsoft store allowed $0 purchase without sign in for years after if not possibly still today. (I don’t use them).

              That said… Security testing anything should tell you the Apple/Google/Microsoft system is all wayyyy more secure using 2FA and activation locks we all hate because theft is a thing. We shouldn’t need an original proof of purchase to unlock a device, yet we do because social engineering makes it that way.

              • Septimaeus@infosec.pub
                link
                fedilink
                English
                arrow-up
                4
                ·
                17 hours ago

                Agreed, I’m pretty used to security key unlocks and still wouldn’t want that friction on a personal device.

                Also just for completeness, since I forgot to mention: enabling stolen device protection and findmy/mdm to enable remote wipe.

      • SirEDCaLot@lemmy.today
        link
        fedilink
        English
        arrow-up
        7
        ·
        18 hours ago

        Most smartphones encrypt the majority of their storage these days.

        This means there are two states the phone can be in.

        BFU, or Before First Unlock, is the most secure. When you power on the phone it has just enough software in unencrypted storage to come on, initialize its hardware, start some background processes, and display an unlock screen. This is the most secure state for the phone. When you type in your password, the password itself decrypts the actual key which is used to decrypt the main storage. Without that password, the data is essentially useless as it cannot be decrypted. Also, most phones are now set up so that if you try the wrong password 10 times, it will erase the main storage encryption key which means the data is completely unrecoverable forever. In general, it doesn’t matter what you can exploit BFU because there’s very little running to exploit and the storage encryption key is usually stored in a secure enclave, that is a special part of a chip that is designed to resist tampering.

        Once you type in your password the first time, the phone is AFU, or After First Unlock. The key to access main storage is held in memory, it is being actively used to read and write from that storage as software is running on the phone like email, background apps, etc. The prompt to unlock the phone looks exactly the same, but in reality the phone is in a much less secure state. There’s plenty of software, both system and apps, running for you to try to exploit.

        The point here is that if you set the phone to regularly reboot, or to reboot if you haven’t logged in in a day or two, each time it reboots it switches back to BFU state.

        And so if some government agency has arrested you and seized your phone, you want that reboot to happen because if the phone automatically reboots before they manage to get into it, it becomes much much harder for them to get in.

        • trailee@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          ·
          7 hours ago

          Well said, that’s exactly what I was getting at. Apple has a Shortcut command that can switch to BFU - it’s called Reboot - but they specifically prevent users from setting it up to run on a schedule of their convenience. They might be afraid of accidental boot loops, or breaking wake up alarms, or something else - they haven’t published reasoning anywhere I’ve seen. But I think it’s pretty poor of them to restrict the feature.

  • rose56@lemmy.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    14 hours ago

    Cops in USA? Is this only for USA? If yes, I don’t care. The article tittle suggests police all over the world.