64 points speckx 1 hour ago 37 comments

TazeTSchnitzel 50 minutes ago | parent

Is it maybe providing a bogus NTP server or something? Maybe the automatic reboot feature can be moved to the Secure Enclave or something, and made to only rely on the hardware RTC in a way that can't be tampered with.

axus 48 minutes ago | parent

Does this mean iPhones are worth more to steal?

klinquist 36 minutes ago | parent

No. This requires an expensive license for a government agency to purchase in order to take advantage of this functionality.

polskibus 16 minutes ago | parent

Can you provide a reference to that?

klinquist 10 minutes ago | parent

Unfortunately not a one I can prove to you online. I have a family member who is a district attorney, so that's my source. He said that that companies like the ones mentioned in the article sell licenses to unlock a single phone to a city or county. The city or county pays if they consider it worth it. The cost can be 5 figures.

klinquist 9 minutes ago | parent

(so the people that discover these exploits will sell them to the companies for 6 or 7 figures, far more than they would get from an Apple/Android bug bounty)

petergs 4 minutes ago | parent

The article references Magnet Forensic’s Graykey being used for this. Wikipedia shows its like 15-30k per year[1]. Doubt the relevant exploit is available to the average phone thief.

[1] https://en.wikipedia.org/wiki/Grayshift

loloquwowndueo 11 minutes ago | parent

Sounds like “this tsa approved lock needs a special key you can totally not just buy on Amazon”

daveoc64 35 minutes ago | parent

This article seems completely unrelated to theft of devices.

quux 35 minutes ago | parent

Perhaps for a short time. As soon as Apple understands the exploit I expect them to patch it. They may even back port the fix to older iOS versions as well.

amluto 45 minutes ago | parent

Ooh, I wonder whether Apple made the classic mistake of using a wall clock timer when they should have used a monotonic (local) clock timer.

edit: having personally gone through this kind of mess, the correct solution is to use strict typing to make sure you keep track of the difference between times and durations and the difference between different clock types. Don’t use plain integers and also don’t try to fudge it the way that Go’s standard library solution does. The modern C++ library is actually pretty good, although you need to use very recent versions of the standard for full functionality.

delichon 44 minutes ago | parent

I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.

As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

pieter_mj 40 minutes ago | parent

If you travel abroad you must unlock. No 4th amendment for you.

skinfaxi 37 minutes ago | parent

You can decline but then they can seize is that right?

jstanley 37 minutes ago | parent

This is mostly FUD. I've never been asked to unlock my phone when travelling abroad.

dana-s 32 minutes ago | parent

I believe the parent comment is talking about leaving US, coming back to the US and then having US's border patrol do so. If that is also what you understood, are you an activist or anyone whom would be of interest to the feds to be asked so? Otherwise saying "I've never been asked" sounds like a common thing for most people.

jimt1234 22 minutes ago | parent

What's the BFD? I have nothing to hide! (I hear that shit all the time. So annoying.)

jstanley 14 minutes ago | parent

Reading this kind of stuff online made me afraid of international travel for many years. When I finally did it literally nothing happened to me.

Yes it's bad that the government overreaches, but it is also bad for your mental health to worry about it.

bryceacc 20 minutes ago | parent

https://arstechnica.com/tech-policy/2026/09/immigration-advo...

>CBP only searched the electronic devices of 55,318 international travelers,” the agency wrote, or 0.0013%.

would suck to be one of those 55 thousand people. I've never been bitten by a shark but I sure care about people that have?

serf 7 minutes ago | parent

I get asked to unlock my dev laptop every single time I go from the US to Montreal. The TSA person sits there and waits for my WM to boot before waving me past.

It seems more like they're trying to determine that it is in fact a laptop and not something resembling one.

jstanley 35 minutes ago | parent

It seems foolhardy to carry your life savings around everywhere, encrypted or not.

If you really want to keep this stuff on a phone at least stretch to a second phone and keep it somewhere safe.

WithinReason 35 minutes ago | parent

If you don't give access to law enforcement when they ask: straight to jail. Encryption is irrelevant in that situation. If they see the encrypted volume you need to provide them access.

ChrisMarshallNY 28 minutes ago | parent

Classic $5 wrench.

Having thugs on speed dial opens a lot of doors.

rdevsrex 26 minutes ago | parent

Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.

Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.

DaveSchmindel 12 minutes ago | parent

That's been my understanding until now as well... the latest on the case against Samuel Tunick has me worried and second guessing that blanket statement though...

https://nccriminallaw.sog.unc.edu/2026/08/03/giving-police-a...

delichon 6 minutes ago | parent

Yeah, if you use it as a way to destroy data that gives them a whole new and powerful attack vector. 18 U.S.C. § 2232 is very broad.

gonzalohm 16 minutes ago | parent

So if an app installs an encrypted volume for which you don't have the password to, you go to jail? That doesn't make sense. How can they know if I have the password or not

wahern 3 minutes ago | parent

They can't know, they infer. AFAIK, normally they just detain you at the airport and harass you to try to break you. To jail you they're technically supposed to be confident enough about you knowing the password to be able to charge you with a crime (presumably something like obstruction, possibly specific to immigration law, otherwise right against self -incrimination might prevent a conviction on failure to disclose alone), or have other evidence of a crime. Then you end up in the legal system, where courts handle due process and a judge, preliminarily, and then a judge or jury decides if you knew the password.

Note that the recent high-profile case of a man being jailed involved him refusing, not claiming he didn't know. He was deliberately trying to test the law in this area, to force the issue onto the courts, and being arrested and charged was part of his plan.

Cider9986 13 minutes ago | parent

It would seem wise to at least keep a backup in an E2EE cloud [1]. This could possibly allow you to not give access even if legally compelled.

>As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

Yes, it seems that way in the US: https://news.ycombinator.com/item?id=49922513

If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.

[1] https://www.privacyguides.org/en/cloud/

ChrisMarshallNY 25 minutes ago | parent

> AFU

Good name.

thraway3837 23 minutes ago | parent

iOS has a remote erase feature. Its also a leaked video and doesn't show which version or model. So it could be something that is already patched, or soon will be. Remember to always keep your OSes update.

Cider9986 18 minutes ago | parent

For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.

GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.

On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.

If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.

[1] https://strongphrase.net give memorable ones which is cool.

Melatonic 12 minutes ago | parent

I wouldnt be surprised if they had a backdoor into the Qualcomm chip that Apple decided to oddly still include in most of their US iPhones vs the international versions that come with their own internal modem

Cider9986 4 minutes ago | parent

[delayed]

ethagnawl 4 minutes ago | parent

> The idea behind this so-called “inactivity reboot” is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology.

This is weird framing. The feature makes it harder for anyone to break into the device.