frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones

https://www.404media.co/cops-can-bypass-iphone-automatic-inactivity-reboot-graykey/
72•speckx•1h ago

Comments

TazeTSchnitzel•1h ago
Is it maybe providing a bogus NTP server or something? Maybe the automatic reboot feature can be moved to the Secure Enclave or something, and made to only rely on the hardware RTC in a way that can't be tampered with.
axus•1h ago
Does this mean iPhones are worth more to steal?
klinquist•48m ago
No. This requires an expensive license for a government agency to purchase in order to take advantage of this functionality.
polskibus•28m ago
Can you provide a reference to that?
klinquist•22m ago
Unfortunately not a one I can prove to you online. I have a family member who is a district attorney, so that's my source. He said that that companies like the ones mentioned in the article sell licenses to unlock a single phone to a city or county. The city or county pays if they consider it worth it. The cost can be 5 figures.
klinquist•20m ago
(so the people that discover these exploits will sell them to the companies for 6 or 7 figures, far more than they would get from an Apple/Android bug bounty)
petergs•16m ago
The article references Magnet Forensic’s Graykey being used for this. Wikipedia shows its like 15-30k per year[1]. Doubt the relevant exploit is available to the average phone thief.

[1] https://en.wikipedia.org/wiki/Grayshift

kube-system•7m ago
Government contract data is public

Here's a renewal of one, presumably basic, license:

https://bidbanana.thebidlab.com/contract/4jKIvKMvZdoWo3d6K6q...

The product is not publicly available, and is sold only B2G: https://www.magnetforensics.com/products/magnet-graykey/#par...

loloquwowndueo•23m ago
Sounds like “this tsa approved lock needs a special key you can totally not just buy on Amazon”
daveoc64•47m ago
This article seems completely unrelated to theft of devices.
quux•47m ago
Perhaps for a short time. As soon as Apple understands the exploit I expect them to patch it. They may even back port the fix to older iOS versions as well.
amluto•56m ago
Ooh, I wonder whether Apple made the classic mistake of using a wall clock timer when they should have used a monotonic (local) clock timer.

edit: having personally gone through this kind of mess, the correct solution is to use strict typing to make sure you keep track of the difference between times and durations and the difference between different clock types. Don’t use plain integers and also don’t try to fudge it the way that Go’s standard library solution does. The modern C++ library is actually pretty good, although you need to use very recent versions of the standard for full functionality.

delichon•56m ago
I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.

As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

pieter_mj•52m ago
If you travel abroad you must unlock. No 4th amendment for you.
skinfaxi•49m ago
You can decline but then they can seize is that right?
mmooss•10m ago
It would depend on the country.
jstanley•49m ago
This is mostly FUD. I've never been asked to unlock my phone when travelling abroad.
dana-s•44m ago
I believe the parent comment is talking about leaving US, coming back to the US and then having US's border patrol do so. If that is also what you understood, are you an activist or anyone whom would be of interest to the feds to be asked so? Otherwise saying "I've never been asked" sounds like a common thing for most people.
ChrisMarshallNY•37m ago
> AFU

Good name.

thraway3837•35m ago
iOS has a remote erase feature. Its also a leaked video and doesn't show which version or model. So it could be something that is already patched, or soon will be. Remember to always keep your OSes update.
artisinal•13m ago
It's a bit difficult to remote erase your phone while you are in custody.

Unless you are Norwegian royalty and are notified of your upcoming arrest, then you can wipe all you need.

Cider9986•30m ago
For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.

GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.

On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.

If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.

[1] https://strongphrase.net give memorable ones which is cool.

23ahGa17•12m ago
People believed the reboot feature last time GrapheneOS was mentioned. It is of course nonsense.

Shut down the phone in areas with a high snatch risk. That means during landing for example, because the aircraft can be boarded covertly if on the ground.

Cider9986•7m ago
[delayed]
dylan604•4m ago
> On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase

Why do you call out just one OS? It's a good idea for any OS.

Melatonic•24m ago
I wouldnt be surprised if they had a backdoor into the Qualcomm chip that Apple decided to oddly still include in most of their US iPhones vs the international versions that come with their own internal modem
Cider9986•16m ago
>Even if that device doesn't have the ability to turn on Airplane Mode or to turn off the transmitters through the Control Center of iOS.

IIRC, the default on iOS is that anyone with your locked device can enable airplane mode which is concerning simply for thieves. But I suppose they have to use faraday bags anyway because of the Find My network.

ethagnawl•16m ago
> The idea behind this so-called “inactivity reboot” is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology.

This is weird framing. The feature makes it harder for anyone to break into the device.

Cider9986•9m ago
Huh, so this is essentially very similar be what this guy said to my suggestion of a factory reset timer in GrapheneOS. This goes to show for all the people that want GrapheneOS to implement a feature like hidden profiles–flawed features give people a false sense of security and should not be implemented (that's not to mention deniability may not even be a good feature if it was technically possible to implement it well).

Me:

>What about a duress timer working as the reboot timer but it wipes if you don't unlock within the time period. Would that have any advantages for destruction of evidence or deniability?

HybridStatAnim8:

>That would not be viable because the hardware does not support it. It cannot be implemented in the OS because the OS can be turned off or exploited endlessly. For GOS to consider it, it would likely need to be backed by the secure element.

>Duress PIN is deemed acceptable to implement in the OS because it is expected that the user is the one to enter it, so it has not fallen into the hands of attackers who may bypass it. Once attackers have it, you are effectively gambling. Account for that in your threat model and do not let it get to that point.

https://news.ycombinator.com/item?id=49040342

tamimio•9m ago
Well first on the things you can do right now till apple figures it out, you should have control center disabled while the phone is locked, you can find it under “Allow Access When Locked” in face id and passcode settings, while -per the article- this won’t stop them, it sure will make it harder as by the time they try to gain access the 72h might have passed and a reboot happens. Second, they definitely fake the internal clock through the port, and because connected phone will keep correcting it through the NTP, hence it’s crucial to them to isolate the phone, so your job is to make that harder on them or delay it enough till it reboots itself. I think some of the quick counter measures apple can do now is allowing custom reboot periods, remote reboots through icloud, and disabling the possibility of manipulating the time through the lightning/usbc port.
jimt1234•34m ago
What's the BFD? I have nothing to hide! (I hear that shit all the time. So annoying.)
jstanley•26m ago
Reading this kind of stuff online made me afraid of international travel for many years. When I finally did it literally nothing happened to me.

Yes it's bad that the government overreaches, but it is also bad for your mental health to worry about it.

UpsideDownRide•6m ago
It's even worse for your mental to never think about It.
bryceacc•32m ago
https://arstechnica.com/tech-policy/2026/09/immigration-advo...

>CBP only searched the electronic devices of 55,318 international travelers,” the agency wrote, or 0.0013%.

would suck to be one of those 55 thousand people. I've never been bitten by a shark but I sure care about people that have?

serf•19m ago
I get asked to unlock my dev laptop every single time I go from the US to Montreal. The TSA person sits there and waits for my WM to boot before waving me past.

It seems more like they're trying to determine that it is in fact a laptop and not something resembling one.

jstanley•47m ago
It seems foolhardy to carry your life savings around everywhere, encrypted or not.

If you really want to keep this stuff on a phone at least stretch to a second phone and keep it somewhere safe.

WithinReason•47m ago
If you don't give access to law enforcement when they ask: straight to jail. Encryption is irrelevant in that situation. If they see the encrypted volume you need to provide them access.
ChrisMarshallNY•40m ago
Classic $5 wrench.

Having thugs on speed dial opens a lot of doors.

rdevsrex•38m ago
Maybe in a country like the UK, but not in the US. The Fifth Amendment protects against self-incrimination.

Which covers divulging encryption keys because it is treated the same as compelling you to give up the combination to a wall safe which is testimonial and protected.

DaveSchmindel•24m ago
That's been my understanding until now as well... the latest on the case against Samuel Tunick has me worried and second guessing that blanket statement though...

https://nccriminallaw.sog.unc.edu/2026/08/03/giving-police-a...

delichon•17m ago
Yeah, if you use it as a way to destroy data that gives them a whole new and powerful attack vector. 18 U.S.C. § 2232 is very broad.
glitchc•13m ago
> The Fifth Amendment protects against self-incrimination.

You can still be held in custody for obstruction of justice:

https://www.findlaw.com/legalblogs/third-circuit/man-held-in...

It took four years before he could secure his release:

https://www.sophos.com/en-us/blog/suspect-who-refused-to-dec...

izacus•7m ago
Self-incrimination yes, but not for cases when the person compelled has evidence to incriminate another process in a case.
gonzalohm•28m ago
So if an app installs an encrypted volume for which you don't have the password to, you go to jail? That doesn't make sense. How can they know if I have the password or not
wahern•15m ago
They can't know, they infer. AFAIU, normally they just detain you at the airport and harass you to try to break you. To jail you they're technically supposed to be confident enough about you knowing the password to be able to charge you with a crime (presumably something like obstruction, possibly specific to immigration law, otherwise right against self-incrimination might prevent a conviction on failure to disclose alone), or have other evidence of some other crime. Then you end up in the legal system, where courts handle due process and a judge, preliminarily, and then a judge or jury decides if you knew the password.

Note that the recent high-profile case of a man being jailed involved him refusing to decrypt, rather than claiming he didn't know. He was deliberately trying to test the law regarding the permissible scope of inspection of digital data, to force the matter into the courts so the issues could be litigated in a controlled context untainted by other potential crimes; being arrested and charged was part of his plan.

Cider9986•25m ago
It would seem wise to at least keep a backup in an E2EE cloud [1]. This could possibly allow you to not give access even if legally compelled.

>As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

Yes, it seems that way in the US: https://news.ycombinator.com/item?id=49922513

If your threat model includes someone using violence to coerce you, an option could be to use a cloud storage account entirely over Tor from the browser (preferably download the app because of web cryptography risks) with the login memorized. That way you can access it on any computer even if yours is lost and you can remove traces of it from your phone.

[1] https://www.privacyguides.org/en/cloud/

StreetComplete on iOS is now in public beta

https://github.com/streetcomplete/StreetComplete/issues/5421
350•Snowly•5h ago•71 comments

How to speed up the Rust compiler in September 2026

https://nnethercote.github.io/2026/09/30/how-to-speed-up-the-rust-compiler-in-september-2026.html
137•trickypr•3h ago•68 comments

OpenID Foundation: Identity Management for Agentic AI [pdf] (2025)

https://openid.net/wp-content/uploads/2025/10/Identity-Management-for-Agentic-AI.pdf
27•cgeier•1h ago•6 comments

RacketCon Is Saturday

https://con.racket-lang.org/
28•spdegabrielle•1h ago•10 comments

Polyedergarten: Garden of Paper Polyhedron Models

https://www.polyedergarten.de/e_index.htm
16•isaacimagine•1h ago•1 comments

Cloudflare K2: serverless event streams

https://blog.cloudflare.com/cloudflare-k2-streams/
41•elffjs•2h ago•6 comments

Google breaks promise to provide 10 years of updates to Chromebooks

https://www.osnews.com/story/146052/google-breaks-promise-to-provide-10-years-of-updates-to-chrom...
296•speckx•3h ago•130 comments

GPT-Synopsys: Frontier Intelligence to Revolutionize Chip Design

https://news.synopsys.com/2026-09-30-OpenAI-and-Synopsys-Announce-GPT-Synopsys-Frontier-Intellige...
118•giuliomagnifico•5h ago•66 comments

Meta Uses A.I. Data Centers to Avoid Billions in Federal Taxes

https://www.nytimes.com/2026/09/30/technology/meta-ai-data-centers-taxes.html
195•gmays•3h ago•146 comments

OpenDLSS: A Vulkan Reimplementation of Nvidia's DLSS 5 Neural Rendering Network

https://github.com/maanHimself/OpenDLSS-NR
200•sagacity•1d ago•96 comments

RIP, vector database

https://turbopuffer.com/blog/rip-vector-database
6•razin•14m ago•0 comments

Gemini 4 Argon

https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-4-argon/
1565•bradleyg223•20h ago•1037 comments

Figma restricts MCP access to whitelisted clients, excluding Pi

https://twitter.com/GayaniFigma/status/2105295629941350454
51•thdr•1h ago•23 comments

FTC is investigating OpenAI, Anthropic and other AI companies over product risks

https://www.cnbc.com/2026/09/30/ftc-ai-probe-openai-anthropic.html
121•dgellow•3h ago•71 comments

Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones

https://www.404media.co/cops-can-bypass-iphone-automatic-inactivity-reboot-graykey/
74•speckx•1h ago•46 comments

Red Hat Being Phased Out of Existence (Like Many Other Companies IBM Bought)

https://techrights.org/n/2026/10/01/Red_Hat_Being_Phased_Out_of_Existence_Like_Many_Other_Compani...
27•amcclure•43m ago•14 comments

Book of Shapes – Collection of minimal, generative and customizable SVG-patterns

https://bookofshapes.com/
185•eustoria•2d ago•14 comments

Truemetrics (YC S23) Is Hiring a GTM Founder's Associate

https://www.ycombinator.com/companies/truemetrics/jobs/THLEzXI-gtm-founder-s-associate
1•truemetricsIngo•6h ago

The top secret URSALA, RAQUEL, and FARRAH satellites (2025)

https://www.thespacereview.com/article/4951/1
279•Bluestein•18h ago•141 comments

Adding Floating-Point Decimals for Fun and Profit

https://blog.vero.site/post/float
44•ibobev•2d ago•21 comments

Before pixels: Modular industrial dashboards

https://unsung.aresluna.org/before-pixels-modular-industrial-dashboards/
249•leephillips•21h ago•46 comments

Why the Bronze Age Collapsed

https://www.worksinprogress.news/p/why-really-caused-the-bronze-age
343•AnodicElegy•2d ago•229 comments

Micron CEO Says Memory Supply Will Be Much Tighter in 2027 and 2028 Than in 2026

https://www.techpowerup.com/353296/micron-ceo-says-memory-supply-will-be-much-tighter-in-2027-and...
174•speckx•3h ago•201 comments

Los Alamos bets on ENIAC: Nuclear Monte Carlo simulations, 1947–1948 (2014) [pdf]

https://www.tomandmaria.com/Tom/Writing/LosAlamosBetsOnENIAC.pdf
43•nill0•1d ago•1 comments

A brief history of the Bloomberg terminal

https://spectrum.ieee.org/bloomberg-terminal
350•rbanffy•1d ago•149 comments

Surprisingly complex waves reveal the brain's inner workings

https://www.quantamagazine.org/surprisingly-complex-waves-reveal-the-brains-inner-workings-20260930/
232•ibobev•21h ago•92 comments

Launch HN: Magnitude (YC S25) – Self-optimizing inference engine for agents

https://github.com/magnitudedev/magnitude
181•anerli•22h ago•88 comments

Halfspace experimental IDE for solid modeling with distance fields

https://www.mattkeeter.com/projects/halfspace/
171•luu•20h ago•10 comments

Returning from vacation? The government can search your phone without a warrant

https://arstechnica.com/tech-policy/2026/09/immigration-advocate-sues-border-agents-for-demanding...
252•rbanffy•5h ago•239 comments

5x faster Edge Functions: V8 isolates to Firecracker MicroVMs

https://www.netlify.com/blog/edge-functions-firecracker-microvms/
208•jbott•21h ago•89 comments