Apple quietly introduced code into iOS 18.1 which reboots the device if it has not been unlocked for a period of time, reverting it to a state which improves the security of iPhones overall and is making it harder for police to break into the devices, according to multiple iPhone security experts.

On Thursday, 404 Media reported that law enforcement officials were freaking out that iPhones which had been stored for examination were mysteriously rebooting themselves. At the time the cause was unclear, with the officials only able to speculate why they were being locked out of the devices. Now a day later, the potential reason why is coming into view.

“Apple indeed added a feature called ‘inactivity reboot’ in iOS 18.1.,” Dr.-Ing. Jiska Classen, a research group leader at the Hasso Plattner Institute, tweeted after 404 Media published on Thursday along with screenshots that they presented as the relevant pieces of code.

    • nicerdicer@feddit.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      Once rebooted, you need to enter your PIN to unlock the phone (and the SIM as well). Before that it is not possible to unlock the phone with biometric credentials (face ID or fingerprint).

      As far as I’m aware, police can force you to hand over your biometric credentials (they can hold the phone to your face to unlock it when you have face ID enabled, or can move your finger to the fingerprint sensor). But they can’t force you to reveal the PIN number.

      • LifeInMultipleChoice@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        14 days ago

        Yeah but that would imply they are bringing the phones to the person multiple times to use their face/finger, or they are keeping the phone active so it never locks, unless they are actively changing the settings to never lock somehow. Seems like an easier fix to just require you to enter your pin to change your lock setting to indefinitely.

        Side note: the last time I was arrested the officer asked me if I wanted to reboot my phone or turn it off before handing it over so I knew they weren’t going to go through it. Was surprised

        • nicerdicer@feddit.org
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          I don’t know how the procedere would be executed, but I imagine that police could have the phone present during an interrogation and try to nlock it there (possibly by making you to look at the phone to unlock it, if the phone has been set up to unlock this way). Once unlocked, it would be sufficient to have a peek into the camera roll or messages, until the phone locks again. I don’t know about the law, but I can imagine that if a police officer had a look into your phone, even briefly, it may be held against the one who is being interrogated.

        • MindlessZ@lemm.ee
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          The more full reason is that the device is still encrypted prior to first unlock and is harder to extract any information from. As to what you said about police requiring you to enter your PIN, they can’t. You can’t be forced to reveal your passwords/PINs but they can legally force you to unlock biometrics (fingerprint/face ID)

          • LifeInMultipleChoice@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            0
            ·
            14 days ago

            I never said they could require you to enter a pin, my words are often a jumble. I was saying cops actually asked me if I wanted to restart or shut down my phone so I had peace of mind that they wouldn’t go through it.

        • chiliedogg@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          Yep: but they can’t force you to give them the password because of 5th Amendment protections from self-incrimination.

          And even if they did have the right to tell you to give them the password, they don’t have access if you simply refuse to cooperate. They can get your fingerprints, face ID, or retina scan by force. They cannot extract information from your brain.

          BTW: Lots if phones also have a “lockout mode” that can be enabled that will give you the option to lock it down to password-only without turning it off. It can be good for recording police interactions, because it will continue to record them while they can’t access the contents of the phone if they swipe it from you.

      • EndlessNightmare@reddthat.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        14 days ago

        or can move your finger to the fingerprint sensor).

        Good luck guessing which finger and on which hand. You have 3 tries before a password is required.

    • ouch@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      Most likely after rebooting but before unlocking the decryption key is not present in memory in plaintext.

    • Kairos@lemmy.today
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      As I understand it, even though after Reboot the OS looks like its in about the same state with the wallpaper and same password to unlock, the fact that it hasn’t been unlocked yet means that certain attacks don’t work as well. I don’t know why specifically. I think it’s because the attack may still work but doesn’t reveal any sensitive data because it’s just the ROM, wallpaper, sim, etc.

    • TaviRider@reddthat.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      When you first boot up a device, most data on that device is encrypted. This is the Before First Unlock (BFU) state. In order to access any of that data, someone must enter the passcode. The Secure Enclave uses it to recreate the decryption keys that allow the device to access that encrypted data. Biometrics like Face ID and Touch ID won’t work: they can’t be used to recreate the encryption keys.

      Once you unlock the device by entering the passcode the device generates the encryption keys and uses them to access the data. It keeps those keys in memory. If it didn’t, you’d have to enter your passcode over and over again in order to keep using your device. This is After First Unlock (AFU) state.

      When you’re in AFU state and you lock your device, it doesn’t throw away the encryption keys. It just doesn’t permit you to access your device. This is when you can use biometrics to unlock it.

      In some jurisdictions a judge can legally force someone to enter biometrics, but can’t force them give up their passcode. This legal distinction in the USA is that giving a passcode is “testimonial” because it requires giving over the contents of your mind, and forcing suspects to do that is not legal in the USA. Biometrics aren’t testimonial, and so someone can be forced to use them, similar to how arrested people are forced to give fingerprints.

      Of course, in practical terms this is a meaningless distinction because both biometrics and a passcode can grant access to nearly all data on a device. So one interesting thing about BFU vs AFU is that BFU makes this legal hair-splitting moot: biometrics don’t work in BFU state.

      But that’s not what the 404 Media articles are about. It’s more about the forensic tools that can sometimes extract data even from a locked device. A device in AFU state has lots of opportunities for attack compared to BFU. The encryption keys exist, some data is already decrypted in memory, the lightning port is active, it will connect to Wi-Fi networks, and so on. This constitutes a lot of attack surface that hackers could potentially exploit to pull data off the device. In BFU state, there’s very little data available and almost no attack surface. Automatically returning a device to BFU state improves resistance to hacking.

      • Mongostein@lemmy.ca
        link
        fedilink
        English
        arrow-up
        0
        ·
        14 days ago

        Also, in the BFU state, iPhones at least, won’t allow any data connections through USB

        • TaviRider@reddthat.com
          link
          fedilink
          English
          arrow-up
          0
          ·
          13 days ago

          It’s more complicated than that. It’s called USB restricted mode. The lightning port is always willing to do a minimal subset of the protocols that it supports in order to do smart charging. By default most of the protocols it supports are disabled in BFU state. In AFU state it gets more complex than that. Accessories that you’ve previously connected can connect for one hour after the device is locked. This helps keep USB restricted mode from being really annoying if you briefly disconnect and reconnect an accessory.

          USB restricted mode can be disabled by a user option (Settings > [Touch / Face] ID & Passcode > Allow Access When Locked > Accessories) or by a configuration profile. Disabling it allows accessories to connect at any time, and generally lowers the security of your device. But in some cases that’s necessary, for instance when you use an accessibility accessory to use your device.

          If USB restricted mode is a concern for you, you should consider Lockdown Mode (Settings > Privacy & Security > Lockdown Mode). This changes several settings on your device to make it much more resilient to attack.

      • Excrubulent@slrpnk.net
        link
        fedilink
        English
        arrow-up
        0
        ·
        14 days ago

        Fun fact: in Australia we don’t have a bill of rights of any kind, so the cops can just force you to reveal your passwords. The maximum penalty for refusing is 2 years imprisonment.

        • ferret@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          Honestly, as an american, I could live with watered down rights if it meant a more representative government

          • Excrubulent@slrpnk.net
            link
            fedilink
            English
            arrow-up
            0
            ·
            13 days ago

            Oh yeah, just don’t read about what happens to our prime ministers when they attempt to defy the empire. Totes democracy we got over here.

          • Excrubulent@slrpnk.net
            link
            fedilink
            English
            arrow-up
            0
            ·
            13 days ago

            To the ASIO agent assigned to tracking my every online move:

            1. I didn’t see this comment.
            2. I don’t understand it.
            3. I would never do such a thing.
            4. I’m sorry this is what your life has been reduced to. Your patriotism is misplaced and you would be happier if you worked against the creeping surveillance state rather than for it. You know better than any of us how horrible it is, and you have the skills we need.
      • tupalos@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        12 days ago

        Great explanation. That was super insightful.

        So even with BFU, does the iPhone not connect to the internet? I guess i hadn’t noticed it doesn’t.

        Also are you still about to track via gps an iPhone that is in the off state? Just curious if there’s a lot of other vectors where the iPhone is still connected?

        • TaviRider@reddthat.com
          link
          fedilink
          English
          arrow-up
          0
          ·
          12 days ago

          So even with BFU, does the iPhone not connect to the internet? I guess i hadn’t noticed it doesn’t.

          Well, it’s complicated. Most of these topics are. In BFU state, an iPhone (or iPad with cellular) with an active SIM and active data plan will connect to the Internet. It won’t connect to Wi-Fi at all. If you have USB restricted mode disabled and the right accessory connected it will connect to an Ethernet network, but that may fail if the network requires 802.1x and the credential is not available in BFU state. Similarly if USB restricted mode is disabled you can use tethering to a Mac to share its network.

          For location, there’s two mechanisms. One mechanism relies on directly communicating with the device, which only works if the device has network.

          The other mechanism is the “FindMy network” which uses a Bluetooth low energy (BTLE) beacon to let other nearby devices detect it, and they report that to FindMy. It’s a great technology. The way it uses rotating IDs preserves your privacy while still letting you locate your devices. I know that this works when a device is powered off but the battery is not completely dead. I’m not sure if it works in BFU state… my guess it that it does work. But this is not networking. It’s just a tiny Bluetooth signal broadcasting a rotating ID, so it’s one-way communication.

          Other than that, I’m not as sure how things work. I believe Bluetooth is disabled by default in BFU state, but I suspect users can choose to re-enable Bluetooth in BFU state to connect to accessibility accessories. I’m not sure about the new emergency satellite communication.

          But one thing I know for sure is that Apple has world class security engineers, and one area they work hard to secure is devices in BFU state.

  • dohpaz42@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    15 days ago

    If this is true, then it’s not a setting that users can access. At least not that I can find.

    • vozé 🎀@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      15 days ago

      who cares who invented it first? this is benefiting everyone? this isn’t some console wars bullshit, this is a great feature. if apple gets good press from it, i don’t care.

      • uis@lemm.ee
        link
        fedilink
        English
        arrow-up
        0
        ·
        14 days ago

        Unless when it is the other way around, they will sue you to death.

      • sunzu2@thebrainbin.org
        link
        fedilink
        arrow-up
        0
        ·
        14 days ago

        You don’t understand how propaganda works. An this is what this is…

        There a huge shillop about unlocking some terrorist phone long time ago… FBI asked and Apple refused when FBI used celebrite or whatever in reality.

        Gave bonuses false sense of security. This smells the same IMHO.

        Happy to be wrong but I don’t trust apple.

        • theneverfox@pawb.social
          link
          fedilink
          English
          arrow-up
          0
          ·
          12 days ago

          They got in the phone anyways, Apple just told the FBI to pound sand if they don’t have a court order… Why would they put man hours towards decreasing their reputation if they don’t have to? They’re probably not even geared to break into their own devices. Then their PR team ran with it while one of many companies with the capability to crack the phone took a paycheck

          This is different - this is genuine security, even if easily bypassed with preparation beforehand. Honestly, I credit some random apple dev who may have been looking to fix a bug related to long uptime as easily as they might’ve cared about security. I don’t think this was even on the radar of Apple leadership

          This isn’t some moral superiority on Apple’s part, but it is good practice

          • sunzu2@thebrainbin.org
            link
            fedilink
            arrow-up
            0
            ·
            12 days ago

            My thesis is that GrapheneOS has this feature for a long time as part of the security approach… Apple who love shilling how great they but hey are following a Foss Android project as 3t mega corp.

            I find it comical

            • theneverfox@pawb.social
              link
              fedilink
              English
              arrow-up
              0
              ·
              12 days ago

              I don’t see the humor in it…I mean, mega corps can’t innovate, all they ever do is copy or acquire. It’s because even if they acquire a working rockstar team, they’re categorically unable to just write them paychecks and let them cook until they have something

              It’s absurd, but it’s too predictable for me to find it funny. What’s even more absurd is how little mega corps watch the small teams for ideas

        • vozé 🎀@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          14 days ago

          I understand how “propaganda” works and ultimately realize that Apple included such a feature for good publicity so the normal people of the world who don’t know what a Mulvad or a Tails is, but are still privacy concerned, would go out and shill 1,000$+ for their phones-- I get it. I ain’t saying you don’t have to be distrustful.

          I still think it’s a bit silly to look for problems in what is ultimately a good thing, anyways. I didn’t forget about Apple’s letter-of-the-law following of the DMA, I didn’t forget about Apple suing Samsung for “rectangle with button”, I didn’t even forget about Apple reversing course on scanning everyone’s iCloud photos for CSAM-- that last part which was genuinely privacy concerning. I’m still gonna go out of my way to say “i like this” so Apple and other companies continue to at the very least virtue signal for protecting their consumers against an over-reaching & often times distrustful law enforcement.

        • sunzu2@thebrainbin.org
          link
          fedilink
          arrow-up
          0
          ·
          14 days ago

          This is issue of security, no privacy. And I highly doubt Apple is on team peasant here. They are biggest beneficiaries of US government, they play for that team.

      • theneverfox@pawb.social
        link
        fedilink
        English
        arrow-up
        0
        ·
        12 days ago

        Sure, F-Droid. It’s an app store that not only is exclusively foss, they only host things they can build from source in house and seem to have a decent review process - they tag anything from ads to integration with paid services, and those features are often buried so it seems like they’re pretty militant about it

        It comes with all the drawbacks that entails, but I generally check there first myself

  • uis@lemm.ee
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    Meanwhile security-oriented Android forks: “You didn’t do that?”

    • shortwavesurfer@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      14 days ago

      Actually, Graphene and Calyx have this feature. I believe graphene may have it on by default at 18 hours, but I do not know about Calyx.

        • shortwavesurfer@lemmy.zip
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          I was unable to find this on lineage 21 and I don’t think it would work as well on lineage anyway, since the vast majority of the bootloaders cannot be locked once lineage is installed, which would negate a lot of this I would think.

          • a Kendrick fan@lemmy.ml
            link
            fedilink
            English
            arrow-up
            0
            ·
            14 days ago

            my bad, i just checked on lineage 21 again and i can’t find it, but i’m sure it’s on divestOS

        • shortwavesurfer@lemmy.zip
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          Well, if graphene turned it down to 18 hours, then they should as well. But I guess 72 hours is better than nothing.

          • TheLowestStone@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            14 days ago

            This is good but it isn’t quite the same thing. I want my phone to auto restart if I haven’t unlocked in for 12 hours.

        • Ghostalmedia@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          Looks like the big difference is that this is on by default, it appears to get enabled when cops turn off internet access to prevent access to FindMy and remote lockdowns.

          • Suburbanl3g3nd@lemmings.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            14 days ago

            There’s also a feature to disable the biometrics for unlocking in general but to stay active to unlock apps (like bank apps or password managers). I like this because no matter what you can’t unlock my phone without the pin but I still get the convenience of using it for my app security

    • oldfart@lemm.ee
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      iPhone? Don’t these kill apps after a few minutes in background?

      • TaviRider@reddthat.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        14 days ago

        It’s not that simple. iOS has a really sophisticated system for deciding which things to keep in memory and which to evict, and it only does that when it needs more resources. Choosing which apps to kill is based on how recently an app was used, how much of share resources are in use, how often the app gets used, if it’s doing background processing, and other more subtle signals.

        Usually if people notice apps being killed when in the background a lot it’s because one of the apps they’re switching to is using a lot of resources, which forces the eviction of other apps.

    • lemmyingly@lemm.ee
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      Interesting, tell me more please. I presume it requires loading a different OS image as standard iPhone/android OS images will pause apps and attempt to go into a deep sleep after a long enough period?

      • thermal_shock@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        14 days ago

        could be a simple hot spot cell backup, like for reporting network outage, remoting in to certain devices, etc. essentially a secondary ISP to report on main isp and troubleshoot. especially if you have smart devices you could reboot remotely.

        • wholookshere@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          An iPhone is not going to be that. This isn’t phones in general doing this, just iPhones.

          There are also far more efficient devices for that. More cost effective and more energy efficient.

          I understand wanting to reuse old devices for something, but there’s a limit to what is power efficient as well.

            • wholookshere@lemmy.blahaj.zone
              link
              fedilink
              English
              arrow-up
              0
              ·
              14 days ago

              When it comes to iPhones, it’s not a shouldn’t, it’s a can’t.

              The way iOS limits background process means you can’t. I develop for iOS apps for a living.

              There’s still you should never under any circumstances allow unsupported devices to be exposed to the internet or any way. Because that’s how we get bot nets causing DDOS attacks.

      • herrvogel@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        14 days ago

        You joke but people do that. I’ve seen people repurpose their old android phones to host small services on their home networks. I won’t comment on how reasonable it is because battery, but it’s a thing.

        • Klear@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          I really doubt an iOS update will affect people using android phones as servers.

          • modus@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            14 days ago

            It would affect me. I have an android virtual machine running on my iPhone.

        • BaroqueInMind@lemmy.one
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          Literally no difference between a low power SOC RaspberryPi or a fucking phone which is the same thing with a built-in display.

          • Aceticon@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            edit-2
            14 days ago

            Except the price, which is much lower for the SBC, way much lower if one uses one of the lower end Orange Pi or Banana Pi SBCs.

            Also you can put Linux on the SBCs (which always come unlocked) hence do way more with them as servers than if one has to use Android as the OS.

            I mean, I can get it if people with the technical chops, love for technical challenges and an old and pretty much worthless Android phone, configure it as a server if only because “why not?!”, but it’s not exactly a great option considering that a 40 bucks SBC can do the same, only better, more easily and with far more possibilities (given that it will be running Linux rather than Android).

            PS: Actually somebody below mention mobile network connection, which, thinking about it, would be a good reason to use an old Android phone as a server since it has built-in support for 3G (unless it’s quite old) whilst the SBC needs it add to it which might be a problem for the cheaper SBCs (just wondering about how I would get around to do it, I think you need to connect a USB dongle to it and it has to be something compatible with Armbian Linux)

            • __matthew__@lemmy.world
              link
              fedilink
              English
              arrow-up
              0
              ·
              14 days ago

              When you consider the price of a used android (ie. Oneplus 6T for $80 on ebay) and compare it spec for spec with a raspberry pi, it’s actually a really good deal. Like you get:

              • Built in backup power supply (battery)
              • 8-core power-efficient CPU (SDM845)
              • Embedded sensors (microphone, magnetometer, gyro)

              The way I set mine up is to run the server directly on Android using Termux, having an app autostart Termux on boot, and making sure to disable battery optimizations on the app. And then I just had the phone always plugged into the outlet to maintain the battery (and of course android would just trickle charge / disable once full charged).

              Of course this isn’t perfect because you still have much more variability in play (at the OS level) than an RPi (along with not having a standard environment like debian unless you use proot), but it overall is a very powerful setup that works quite well.

    • pycorax@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      Samsung does too but I’ve not set it up as such. Instead, it automatically locks the device from biometric unlocks every 24 hours until you login with your pin again.

    • catloaf@lemm.ee
      link
      fedilink
      English
      arrow-up
      0
      ·
      15 days ago

      It does not. I don’t have it on my Pixel 6. From other people’s comments, it sounds like Samsung and other OEMs have added their version, though.

    • umami_wasabi@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      15 days ago

      It does, labled “Auto Restart”, but only when “preformance issues detected” or time specified. Apple is quite late on this feature.

      Screenshot of Android Auto Restart Settings page

      • fuckwit_mcbumcrumble@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        15 days ago

        This is rebooting for a different reason. That auto reboot just kind assumes that the software on your phone sucks and it needs to reboot to stay running fast.

        Graphene and now iOS auto reboot for security/privacy reasons.

          • NotMyOldRedditName@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            15 days ago

            It’s not the same.

            On an iPhone it’ll reboot after X hours of no use. That means it could go months without rebooting and the day after it’s in police hands it reboots.

            The feature you’re talking about would need to be set to reboot every day at a specific time. Now you personally have to deal with that. Also until you unlock the phone as well there could be reduced functionality making it annoying.

            Very different.

            • umami_wasabi@lemmy.ml
              link
              fedilink
              English
              arrow-up
              0
              ·
              edit-2
              15 days ago

              Not that hard to deal with honestly. Rebooting at night which I’m sleeping does not reduces any functionality, cuz I’m not using it. If someone needs to find me during the night he better call me cuz I won’t wake up by notification which is also suppressed by DND. Yeah it is not design for security but a solution better than none.

              Furthermore, rebooting the device periodically is good for security, especially for non-persistent fileless malware.

      • Album@lemmy.ca
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        15 days ago

        This is clearly the Samsung interface and thus not stock Android. Doesn’t even really look like the same feature.

        • WhyJiffie@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          15 days ago

          depends on your phone. at first encryption was done in an all-or-nothing style, so system startup couldn’t complete without a first unlock. then android started using file based encryption, which was used selectively, encrypting certain things so that they are accessible without an unlock.

          the best way to figure it out is to set a new alarm 10 minutes from now, reboot your phone manually, and see whether the alarm goes off

      • azron@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        15 days ago

        on GrapheneOS it is labeled auto reboot and it specifically says “automatically reboot device if it hasn’t been unlocked in xxx hours” with a default of 18.

    • rockSlayer@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      15 days ago

      That seals the deal for me on rooting my pixel. I’ve been hesitant about rooting ever since I bricked an extra galaxy s3 and nearly bricked my (main device) Verizon galaxy s5

      • iturnedintoanewt@lemm.ee
        link
        fedilink
        English
        arrow-up
        0
        ·
        15 days ago

        GrapheneOS is the easiest ROM install bar none. Get the en browser (needs to be chrome-based) to the install url, hook the phone cable, and let it run. It’s super straightforward. It’s not rooting though, you don’t get root access by default.

        • rockSlayer@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          15 days ago

          Wow things sure changed about Android roms! I still remember how difficult it was to try to simply install a rom through Knox

          • WhyJiffie@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            0
            ·
            15 days ago

            samsung devices are still a different beast, they have their unique little everything and the standard tools don’t work there

      • 𝕸𝖔𝖘𝖘@infosec.pub
        link
        fedilink
        English
        arrow-up
        0
        ·
        15 days ago

        If you have a factory pixel, you don’t need to root. You can unlock bootloader and install a rom that has it (calyxos or grapheneos I know have them). You can root, but you don’t have to.

      • dumbass@leminal.space
        link
        fedilink
        English
        arrow-up
        0
        ·
        15 days ago

        Putting graphineos onto my pixel was the easiest thing I’ve done in a long time, the installer is just pressing buttons and waiting for the next button to be ready pretty much.

        • catloaf@lemm.ee
          link
          fedilink
          English
          arrow-up
          0
          ·
          15 days ago

          How does it work for stuff like bank apps? Do they freak out about it?

          And does it require unlocking the bootloader? I prefer to keep mine locked if possible.

          • dumbass@leminal.space
            link
            fedilink
            English
            arrow-up
            0
            ·
            15 days ago

            My bank app works fine and I can use the NFC chip for payments as well, it might pay to search up your bank name and graphineos to see if anyone’s had an issue, that’s what I did to make sure.

            You have to unlock it to install but once installed they prefer you lock the bootloader back up again.

        • trolololol@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          Same question as catloaf but with less ambiguous things like banks: does Netflix, safety net, fox sports Australia and Google pay work with graphene os?

          • dumbass@leminal.space
            link
            fedilink
            English
            arrow-up
            0
            ·
            edit-2
            12 days ago

            Google wallet doesn’t work at all, but if your bank offers its own NFC payment system then that should work.

            The only app that I’ve had an issue with was uber, that refused to install from either play store or aurora store, but beyond that I haven’t had any issues. Just search graphineos and the app you want to check, or check out their forum.

          • higgsboson@dubvee.org
            link
            fedilink
            English
            arrow-up
            0
            ·
            14 days ago

            My bank apps all work (though YMMV.) Ticket app worked (AXS.) I haven’t actually used google pay or google wallet for anything to know if they work.

            Authy is the only miss I’ve found and it wouldn’t have mattered if i hadnt been caught in the midst of migrating to another app for that when they decided to be assholes.

  • forest5@lonestarlemmy.mooo.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    15 days ago

    As a member of the intelligence community, I can almost guarantee that this is directed at the increased use of Cellebrite UFED hardware, specifically putting the device back into BFU mode, which removes cryptography-related memory allocations. This is also why you’re asked for your password instead of face or fingerprint upon reboot.

    • phoneymouse@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      I don’t know how Cellebrite is a legally operating company. Their entire business model is a violation of the computer fraud and abuse act.

      • Andromxda 🇺🇦🇵🇸🇹🇼@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        14 days ago

        Cellebrite is developed in Israel, a country that legally should even exist, and is known for genocide, crime, espionage, manipulation and propaganda, more war crimes, illegal settlements, using their intelligence agency to assassinate political opponents abroad, etc.

        The so-called “only democracy in the middle east”

      • catloaf@lemm.ee
        link
        fedilink
        English
        arrow-up
        0
        ·
        14 days ago

        When the government does it, it’s not illegal.

        I’m sure the CFAA has an explicit exception for law enforcement anyway. Laws always do.

          • Echo Dot@feddit.uk
            link
            fedilink
            English
            arrow-up
            0
            ·
            14 days ago

            I assume being blown up by a terrorist is not everyone’s idea of a good time. Oh indeed anyones.

        • shortwavesurfer@lemmy.zip
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          When they say they’re part of the intelligence community, it seems highly likely that they are spying on their own citizens, or at least that’s what their job entails.

      • Echo Dot@feddit.uk
        link
        fedilink
        English
        arrow-up
        0
        ·
        14 days ago

        The phrase “as a member of the intelligence community” is not the same “as as a mother”.

        Assuming it is true, always a caveat on the internet, It would actually give them a unique perspective into the situation rather than just using it as a catch-all excuse for Karen’s to be an uninformed twit.

  • CaptSneeze@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    15 days ago

    The way this article is framed sounds like bullshit to me. 18.1 was released less than 2 weeks ago. Any phone running this version of iOS would have had to already been in custody and somehow upgraded to this version, or otherwise brought into custody very recently—too recently for this to have already posed such a problem that law enforcement is “freaking out” and reporting it to the media.

    • viking@infosec.pub
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      Don’t they auto update the OS when connected to a charger? But even then, that would have triggered a reboot already.

      • ziggurat@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        14 days ago

        This is the easiest thing for people with money, and motivation to avoid happening.

        Remove the sim card if it’s an older device, use a Faraday cage (your microwave is one) or a jammer. If you are the government you can also tell the telecom to block the phone from connecting

        • Aceticon@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          14 days ago

          I think you’re seriously overestimating the technical prowess of the average law enforcement officer…

        • bassomitron@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          14 days ago

          Police may be leaving phones online in case it continues receiving relevant evidence (texts, emails, etc).

    • mrvictory1@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      iOS has auto update for a while and iOS users update their devices more often than Android. 2 weeks is not a long time for adoption of new version for iOS.

    • Ghostalmedia@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      The way this article is framed sounds like bullshit to me. 18.1 was released less than 2 weeks ago. Any phone running this version of iOS would have had to already been in custody and somehow upgraded to this version, or otherwise brought into custody very recently—too recently for this to have already posed such a problem that law enforcement is “freaking out” and reporting it to the media.

      A non-insignificant amount of people have been running the public betas because of Apple intelligence, RCS / iMessage toys, UI customization, etc. For example, MixPanel reported about 2% of the iOS install base running 18.0 before 18.0’s launch. IMHO, that’s pretty crazy for a beta OS.

      https://mixpanel.com/trends/#report/ios_18

    • jfrnz@lemm.ee
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      All six GrapheneOS users should be proud that the developers of their phone software are genius inventors!

      • ArcaneSlime@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        14 days ago

        For sure I’m just joking about apple’s habit of taking a feature that has been around for YEARS and claiming they “innovated” it, usually after they strip it down a little no less (like in this case where it appears to be a setting users can’t access, but Graphene lets you turn it on/off or adjust the time between lock and reset.)

    • BorgDrone@lemmy.one
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      don’t let apple tell you they invented it.

      Why always the knee-jerk anti-apple reaction even if they do something good?

      FYI: Apple isn’t telling anyone they invented this. In fact, they didn’t even tell anyone about this feature and declined to comment after it was discovered and people started asking questions.

    • Ghostalmedia@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      IMHO, the novelty of the feature isn’t what makes this headline worthy. This is noteworthy because of the scale. iOS is over a quarter of phones on earth, and in English speaking countries and Japan, you’re looking at numbers that are often over 50%.

      This will impact a LOT more investigations than Graphene, and I imagine Apple will be back in court fighting cops who want to remove privacy and security features. Hopefully this stuff stands up to the autocrats coming into power in the states.

  • Teknikal@eviltoast.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    14 days ago

    I think this used to be possible with tasker, ironically though probably not anymore before of all Google’s restrictions on Android. (maybe if you have root)

    • ProgrammingSocks@pawb.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      14 days ago

      GrapheneOS periodically (once a day or so) forces me to put in the passcode. If this isn’t a stock Android feature that’s another reason to use Graphene. It also has a “lockdown” button in the power button menu that forces the same behaviour.

    • John@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      I think there is no such Option in LOS yet. GrapheneOS on the other Hand has this Option for years. If you want to safe at least your signal messages/contacts Molly has a similar function to encrypt after a setted time of not using it.