GrayKey Freezes iPhones to Defeat Apple's Anti-Forensics Reboot

Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones

GrayKey Freezes iPhones to Defeat Apple's Anti-Forensics Reboot

Magnet Forensics, maker of the GrayKey phone-unlocking tool, has developed GrayKey Preserve and Evidence Preservation Mode to bypass the iPhone's inactivity reboot, which normally locks out police after 72 hours. Leaked training video shows the tool forces Airplane Mode to cut off radios and keep the phone in an After First Unlock state, preserving sensitive data indefinitely. A security researcher calls it a game changer, and the ball is now in Apple's court.

That AFU state is captured. Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost. This is the true magic behind the GrayKey Preserve and the Evidence Preservation Mode function.
  1. int0x29

    These three quotes make me wonder if the police are effectively searching the phone before getting a warrant

    > given that oftentimes they can’t immediately try to break into iPhones that have been seized. That could be because police are still waiting for a court authorization to do so

    > GrayKey Preserve and Evidence Preservation Mode are also designed to combat another iPhone feature that automatically deletes certain data — such as cached locations, and recently deleted photos and iMessages — after a certain number of days. “We're gonna be able to preserve that data for an infinite amount of time.”

    > “That AFU state is captured,” by GrayKey Preserve and Evidence Preservation Mode, the employee says. “Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost. This is the true magic behind the GrayKey Preserve and the Evidence Preservation Mode function.”

    The power loss tolerance in particular looks iffy. The photo and iMessage bits are a bit more problematic in that light. I get that they claim the police aren't seeing the data but if they are extracting before a warrant that is effectivly the same as pre searching everyone and promising not to read it.

  2. Cider9986

    For those who don't know, automatic reboot restarts your device if you haven't unlocked it in a set amount of time. Cellebrite and other digital forensics companies are able to get into AFU devices much more often. The automatic reboot feature was first introduced by GrapheneOS and was later added to iOS and stock Pixels.

    GrapheneOS's default is 18 hours and it can be set to between 10 minutes and 72 hours. iPhones and Stock pixels have it non customizable at 72 hours.

    On GrapheneOS, for privacy and convenience, it's best to use a long random passphrase [1] for your primary unlock and then a fingerprint with a second factor pin as the secondary unlock. You enter the passphrase every time the device restarts.

    If you're encountering someone that's going to seize your phone, try to restart/shut it down yourself so you don't have to trust the AFU protections.

    [1] https://strongphrase.net give memorable ones which is cool.

  3. iancarroll

    > “Even if that device does reboot for any number of reasons, memory maintenance or the power is lost or whatever, the AFU state is not lost. This is the true magic behind the GrayKey Preserve and the Evidence Preservation Mode function.”

    Based on this, it seems more likely that this involves exploiting the device to retrieve the underlying keybags present in AFU mode and store them, rather than manipulating the actual feature of automatic reboots. Then the device can be exploited again in BFU mode but with the prior keybag to decrypt everything.

    It sounds like this feature is being used to exploit and extract keys from devices without a warrant (or in advance of getting one), which seems dubious to me.

  4. delichon

    I keep all of my most sensitive personal documents on my phone, as an emergency backup, but in an encrypted (Cryptomator) volume that requires a separate password. Given the routine news of such exploits this seems like due diligence.

    As I understand it this encryption is a significant additional barrier to technical or legal access to those files. If someone knows otherwise, please let me know. Being wrong could cost me my home and life savings.

  5. ethagnawl

    > The idea behind this so-called “inactivity reboot” is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology.

    This is weird framing. The feature makes it harder for anyone to break into the device.

  6. 15155

    It's amazing that this hasn't been tried as tortious interference. If MMOGlider can be found liable, why can't Cellebrite or GrayKey? Every TOS has anti-reverse-engineering clauses.

  7. Melatonic

    I wouldnt be surprised if they had a backdoor into the Qualcomm chip that Apple decided to oddly still include in most of their US iPhones vs the international versions that come with their own internal modem

  8. Cider9986

    Huh, so this is essentially very similar be what this guy said to my suggestion of a factory reset timer in GrapheneOS being flawed. Apple's implementation of the reboot timer is flawed.

    This goes to show for all the people that want GrapheneOS to implement a feature like hidden profiles–flawed features give people a false sense of security and should not be implemented (that's not to mention deniability may not even be a good feature if it was technically possible to implement it well).

    Me:

    >What about a duress timer working as the reboot timer but it wipes if you don't unlock within the time period. Would that have any advantages for destruction of evidence or deniability?

    HybridStatAnim8:

    >That would not be viable because the hardware does not support it. It cannot be implemented in the OS because the OS can be turned off or exploited endlessly.

    For GOS to consider it, it would likely need to be backed by the secure element.

    >Duress PIN is deemed acceptable to implement in the OS because it is expected that the user is the one to enter it, so it has not fallen into the hands of attackers who may bypass it. Once attackers have it, you are effectively gambling. Account for that in your threat model and do not let it get to that point.

    https://news.ycombinator.com/item?id=49040342

More from this day

2026-10-01