Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones
A leaked video suggests that GrayKey, a prominent phone hacking tool used by law enforcement, has found a way to bypass Apple's 72-hour inactivity reboot feature on iPhones. This new capability, dubbed 'GrayKey Preserve,' allows authorities to indefinitely maintain an iPhone in an After First Unlock (AFU) state, thus circumventing a key privacy measure Apple implemented to protect user data from forensic extraction. The development re-ignites debates on digital privacy, law enforcement access, and the ongoing technological arms race between device manufacturers and forensic companies.
The Lowdown
A recently surfaced video obtained by 404 Media reveals that Magnet Forensics, the company behind the widely used GrayKey device, has developed new technology to overcome Apple's 72-hour inactivity reboot security feature. This feature, introduced by Apple in November 2024, was designed to automatically reboot iPhones that hadn't been unlocked within 72 hours, pushing them into a 'Before First Unlock' (BFU) state where data is significantly harder to access. Law enforcement had previously expressed concerns about this, as it hampered their ability to access seized devices.
GrayKey Preserve and its 'Evidence Preservation Mode' aim to:
- Keep iPhones perpetually in an 'After First Unlock' (AFU) state, which provides much easier access to data for forensic tools.
- Disable radio transmissions (cellular, Wi-Fi, Bluetooth) to isolate the device and prevent remote wipes or data changes.
- Potentially manipulate the iPhone's internal clock to stop data expiration, preserving cached locations, recently deleted photos, and iMessages indefinitely.
While the video doesn't detail the technical specifics, a security researcher speculates that Magnet may be manipulating the iPhone's clock or disabling data expiry tasks. This development effectively neutralizes Apple's recent privacy enhancement, placing the burden back on Apple to devise new countermeasures against such forensic bypasses.
The Gossip
Cracking the Clock Code
Commenters delved into the technical mechanisms GrayKey Preserve might employ to bypass the inactivity reboot. Many speculated that the exploit likely involves manipulating the iPhone's internal clock, differentiating between 'wall clock' and 'monotonic clock' timers. Suggestions included providing a bogus NTP server, tampering with the hardware RTC, or directly interfering with the Secure Enclave. There was discussion about whether Apple made a fundamental mistake in its timer implementation and how difficult it would be to patch.
Privacy vs. Policing Predicament
A significant portion of the discussion centered on the ongoing tension between individual privacy rights and law enforcement's access to digital data. Users debated the effectiveness of personal security measures like encrypted volumes (e.g., Cryptomator) and GrapheneOS, and the legal complexities of resisting demands for phone access, especially at borders where Fourth and Fifth Amendment protections may be limited or ignored. The concept of 'duress codes' and the legal ramifications of using them to destroy data were also hotly debated, with recent court cases cited as examples of the risks involved.
Apple's Security Scrutiny
Commenters scrutinized Apple's role and responsibility in this arms race. Questions arose about whether Apple's security measures are genuinely universal or selectively permeable for certain entities. Some suggested that Apple's 'feud' with agencies like the FBI might be performative, or that Apple itself could have backdoors, citing its past actions in lawsuits against companies like NSO Group. The discussion also covered how Apple could quickly respond to this new exploit, such as by allowing custom reboot periods or disabling time manipulation via ports.