Hardening modern iPhone against forensic tools

Good morning people. I have a new important recommendation.

  1. Upgrade to 18.4 it includes many anti-forensics

  2. If utilizing Apple Configurator or iMazing to enforce profiles, you have the ability to lower the max password attempts. Here’s what Apple states about this.

Attempts 3 4 5 6 7 8 9 10 or more
iOS and iPadOS Lock Screen None 1 minute 5 minutes 15 minutes 1 hour 3 hours 8 hours Device is disabled and must connect to a Mac or PC

“If the Erase Data option is turned on for iPhone, iPad, or Apple Vision Pro (in Settings > [Optic ID], [Face ID], or [Touch ID] & Passcode), after 10 consecutive incorrect attempts to enter the passcode, all content and settings are removed from storage. Consecutive attempts of the same incorrect passcode don’t count toward the limit.”

You cannot edit the number of consecutive attempts unless you use a profile. The trick is if we configure this option to “3” your phone will instantly factory reset without any of the delays mentioned in the apple chart as soon as you try the 4th time. This might be inconvenient if you don’t use iCloud + ADP.

This payload allows you to wipe your phone faster than a GrapheneOS duress password can be typed. Without a profile, if you have Find My enabled you require internet and typing a password to achieve a factory reset. This completely overrides that :smiling_face_with_sunglasses:

As apple keeps patching more loopholes it is important to keep strengthening iOS as much as we can. Please read all recommendations and lmk if you need assistance.

1 Like