Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones
speckx
253 points
204 comments
October 01, 2026
Related Discussions
Found 5 related stories in 89.7ms across 8,245 title embeddings via pgvector HNSW
- US Government targets Cop City protester over phone operating system pastemato · 90 pts · July 23, 2026 · 48% similar
- Phones should have a 'guest lock' feature crisdias · 38 pts · August 14, 2026 · 48% similar
- A U.S. Citizen Deleted His Phone's Data. Now He Faces a Felony Charge aarghh · 22 pts · July 29, 2026 · 45% similar
- A BLE device hidden in cars across the US has a universal key enabling theft [video] bounceroundroom · 13 pts · July 21, 2026 · 45% similar
- US accuses American of wiping phone using a duress password during border search OutOfHere · 21 pts · July 24, 2026 · 44% similar
Discussion Highlights (20 comments)
TazeTSchnitzel
Is it maybe providing a bogus NTP server or something? Maybe the automatic reboot feature can be moved to the Secure Enclave or something, and made to only rely on the hardware RTC in a way that can't be tampered with.
axus
Does this mean iPhones are worth more to steal?
amluto
Ooh, I wonder whether Apple made the classic mistake of using a wall clock timer when they should have used a monotonic (local) clock timer. edit: having personally gone through this kind of mess, the correct solution is to use strict typing to make sure you keep track of the difference between times and durations and the difference between different clock types. Don’t use plain integers and also don’t try to fudge it the way that Go’s standard library solution does. The modern C++ library is actually pretty good, although you need to use very recent versions of the standard for full functionality.
delichon
I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence. As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.
ChrisMarshallNY
> AFU Good name.
thraway3837
iOS has a remote erase feature. Its also a leaked video and doesn't show which version or model. So it could be something that is already patched, or soon will be. Remember to always keep your OSes update.
Cider9986
For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels. GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours. On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts. If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections. [1] https://strongphrase.net give memorable ones which is cool.
Melatonic
I wouldnt be surprised if they had a backdoor into the Qualcomm chip that Apple decided to oddly still include in most of their US iPhones vs the international versions that come with their own internal modem
Cider9986
Offtopic: >Even if that device doesn't have the ability to turn on Airplane Mode or to turn off the transmitters through the Control Center of iOS. IIRC, the default on iOS is that anyone with your locked device can enable airplane mode which is concerning simply for thieves. But I suppose they have to use faraday bags anyway because of the Find My network.
ethagnawl
> The idea behind this so-called “inactivity reboot” is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology. This is weird framing. The feature makes it harder for anyone to break into the device.
Cider9986
Huh, so this is essentially very similar be what this guy said to my suggestion of a factory reset timer in GrapheneOS being flawed. Apple's implementation of the reboot timer is flawed. This goes to show for all the people that want GrapheneOS to implement a feature like hidden profiles–flawed features give people a false sense of security and should not be implemented (that's not to mention deniability may not even be a good feature if it was technically possible to implement it well). Me: >What about a duress timer working as the reboot timer but it wipes if you don't unlock within the time period. Would that have any advantages for destruction of evidence or deniability? HybridStatAnim8: >That would not be viable because the hardware does not support it. It cannot be implemented in the OS because the OS can be turned off or exploited endlessly. For GOS to consider it, it would likely need to be backed by the secure element. >Duress PIN is deemed acceptable to implement in the OS because it is expected that the user is the one to enter it, so it has not fallen into the hands of attackers who may bypass it. Once attackers have it, you are effectively gambling. Account for that in your threat model and do not let it get to that point. https://news.ycombinator.com/item?id=49040342
tamimio
Well first on the things you can do right now till apple figures it out, you should have control center disabled while the phone is locked, you can find it under “Allow Access When Locked” in face id and passcode settings, while -per the article- this won’t stop them, it sure will make it harder as by the time they try to gain access the 72h might have passed and a reboot happens. Second, they definitely fake the internal clock through the port, and because connected phone will keep correcting it through the NTP, hence it’s crucial to them to isolate the phone, so your job is to make that harder on them or delay it enough till it reboots itself. I think some of the quick counter measures apple can do now is allowing custom reboot periods, remote reboots through icloud, and disabling the possibility of manipulating the time through the lightning/usbc port.
monneyboi
So we pay Apple for friction. And the state pays for Graykey to remove it. Whoever wins that arm race this quarter determines what our rights are worth in practice.
mmooss
I wonder why Apple, with its resources, doesn't take the lawfare approach to someone attacking its phones, for profit, and damaging its reputation.
childintime
Why don't my credit card and my phone implement a second pincode or password that allows me to signal that I'm in a hostage situation, and want everything (discretely) wiped? So that would do a saldo = sqrt(saldo) for a bank card, for example, and cancel all my limits.
lrvick
Remember that Apple has full remote code execution rights on every device and hands that power over to the CCP in China, and they could do it here too. It is not possible to actually own an Apple device. It will do whatever Apple wants it to do, or whatever anyone that pays them enough wants it to do.
_justinfunk
I kept being thrown off by the headline and article saying "cops".
iancarroll
> “Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost. This is the true magic behind the GrayKey Preserve and the Evidence Preservation Mode function.” Based on this, it seems more likely that this involves exploiting the device to retrieve the underlying keybags present in AFU mode and store them, rather than manipulating the actual feature of automatic reboots. Then the device can be exploited again in BFU mode but with the prior keybag to decrypt everything. It sounds like this feature is being used to exploit and extract keys from devices without a warrant (or in advance of getting one), which seems dubious to me.
t1234s
Graphine needs a triple tap power button for a hard power off.
15155
It's amazing that this hasn't been tried as tortious interference. If MMOGlider can be found liable, why can't Cellebrite or GrayKey? Every TOS has anti-reverse-engineering clauses.