Hardening modern iPhone against forensic tools

Maybe.

Good morning people. I have a new important recommendation.

  1. Upgrade to 18.4 it includes many anti-forensics

  2. If utilizing Apple Configurator or iMazing to enforce profiles, you have the ability to lower the max password attempts. Here’s what Apple states about this.

Attempts 3 4 5 6 7 8 9 10 or more
iOS and iPadOS Lock Screen None 1 minute 5 minutes 15 minutes 1 hour 3 hours 8 hours Device is disabled and must connect to a Mac or PC

“If the Erase Data option is turned on for iPhone, iPad, or Apple Vision Pro (in Settings > [Optic ID], [Face ID], or [Touch ID] & Passcode), after 10 consecutive incorrect attempts to enter the passcode, all content and settings are removed from storage. Consecutive attempts of the same incorrect passcode don’t count toward the limit.”

You cannot edit the number of consecutive attempts unless you use a profile. The trick is if we configure this option to “3” your phone will instantly factory reset without any of the delays mentioned in the apple chart as soon as you try the 4th time. This might be inconvenient if you don’t use iCloud + ADP.

This payload allows you to wipe your phone faster than a GrapheneOS duress password can be typed. Without a profile, if you have Find My enabled you require internet and typing a password to achieve a factory reset. This completely overrides that :smiling_face_with_sunglasses:

As apple keeps patching more loopholes it is important to keep strengthening iOS as much as we can. Please read all recommendations and lmk if you need assistance.

1 Like

But what if a friend or a kid be your relative or whatever jokingly attempts multiple passwords at a go, wouldn’t that risk losing all of your data? I think GrapheneOS’s approach is more sane.

1 Like

If you are going through all this trouble and aren’t maintaing positive control over your mobile device at all times possible then it’s pointless. I’d rather keep having to restore from a backup then have some random people freely rummage through my personal device.

Thank you for this guide. I have appreciated it and implemented some steps. I had some follow up questions if I may:

  1. For your shortcut, can you clarify its use case and why it would be preferable to vol+power? Here is an instance where it failed to run, and I’m questioning if vol+power is the better move.

  1. It’s my understanding enabling dev beta will disable contact key verification. If that it true, would it be better to stay on latest stable?

update to latest iOS dev beta

  1. Should I use Apple configurator on Mac OS or iMazing? I have not implemented MDM before, but am curious about some of these additional features and settings.

  2. What are your thoughts on physically disabling the USB port and charging via wireless only? Or, Is it possible to software disable the usb port for data?

  1. I’m not sure how you came upon that error but you’re supposed to add the shortcut as a widget or icon on the home screen. When you click it you can swipe to shut the phone down.

  2. If you value that feature then yes. Dev betas give you non-announced security updates quicker though such as the auto-reboot that apple still hasn’t acknowledged publicly.

  3. They accomplish the same thing. If you have a macbook use apple configurator.

  4. If you mean physically tampering with the phone I’m pretty sure they can just fix whatever you did and gain access again. iPhone is already supposed to disable the port for data when usb restricted mode is on but clearly it wasn’t working until the recent security update in iOS 18.3.1. Why? I have no idea. I believe someone did a write-up on it.

Do iPhones disable the USB port on a hardware level like GrapheneOS? I had the impression they don’t from https://xcancel.com/GrapheneOS/status/1855582940568158329#m

Thank you! How can I enable usb restricted mode? I skimmed the thread but I must be missing it. Is it only time based? If only time based - this is why I could see benefit in disabling the usb port. Repairs take time.


Got it. That shortcut makes more sense to me now for post-lockscreen activities. My screen was locked and the shortcut initiated on the lockscreen to produce that error.

I would like to suggest the following workflow that would complement this shortcut for an iPhone in a locked state. Open to any feedback.

  1. Create a shortcut leveraging the native power-off function. (This is native to the shortcut app)
  2. Add this new shortcut as a button on the lockscreen, or to your action button if available.(I replaced my camera launcher since I can always swipe right for camera)

Under duress steps would be:

  1. Initiate vol+power, disabling face-id. - Avoiding need to unlock to shutdown.
  2. Initiate the previously mentioned shortcut
  3. Select shutdown (no need to slide)

In this method, you do not need to unlock your device to quickly power down.

Great advice.

Steps for lockscreen power-button.

  1. Make new shortcut with shut down function
  2. Drag it to be the first shortcut on the “All shortcuts” tab
  3. Long press lockscreen and click Customize
  4. Click Lock screen
  5. Click Add Widgets
  6. Click the Shortcuts option
  7. Click Done

Note: This is only meant to turn off a phone from the lockscreen when face id is enabled. After you run this once face id will be disabled until password is typed.

Action button can be programmed too but is only available on iPhone 15 pro and up.

1 Like

Settings > Face ID & Passcode

Lockdown mode will activate it quicker than one hour. I’ve timed it at 10 seconds after phone is locked. When there’s no fancy zero days circulating these little settings are powerful on iOS.

1 Like

Slight correction. In my testing, running the native shutdown function will not disable face-id unless you shutdown or reboot. Running the native shutdown shortcut without sliding to power down will result in face-id enabled. The native shutdown function does benefit from being able to run when face-id is already disabled through vol+power.

I’ve now made this modification which I’m having success with. However, it does not run in BFU. I have not found a method, native or otherwise, that runs BFU.

OS level.

On this same topic - Do you have an opinion on whether the inclusion of a SIM card tray in devices less secure compared to US models that utilize eSIM technology exclusively? I’m curious about if there is a potential attack where an attacker inserts a malicious SIM card into a locked device, leading it to connect to an insecure network.

Are you able to still install updates through the iMazing app manager portal? Or do you have to set it to true every single time? Perplexity AI said You could install updates because you are using imazing as a source to push updates and not the app store on the phone.

Thanks!

Hello. Graykey has been able to circumvent the new iOS AFU inactivity timer. I recommend not relying on this timer but to instead implement this and keep your phone next to you at all times possible. Maintain iOS backups (with advanced data protection) to ease off the stress of constant resets. You can also peform a “force restart” (not the regular shutdown) when you know you won’t be near your phone for a period of time. Stay vigilant!

Information:
Graykey has created a new hardware solution called Graykey Preserve that will help address the iOS 18 inactivity reboot timer and protect devices in the AFU state.

Graykey Preserve is a new device that has no geolocation restrictions, so it can be deployed to field offices or used outside of the forensics lab to provide your team with the ability to quickly preserve data on iOS devices. Graykey Preserve doesn’t include any extraction or brute force capabilities, but it maintains the AFU state of iOS devices until a full extraction can be completed in the lab using your Graykey.

Graykey Preserve is a portable hardware device that offers all the functionalities of Evidence Preservation Mode in a field unit.

What is Graykey Preserve?
Graykey Preserve is a new device developed to enhance evidence preservation on mobile devices. It specifically offers the ability to:
• Disable the Apple restart timer.
• Preserve the AFU (After First Unlock) state.
• Prevent updates, network connections, and remote wipe capabilities.

Graykey Preserve is a mobile device, but it must have internet access. Unlike the standard Magnet Graykey device, Graykey Preserve does not support extractions or brute force access. Instead, its sole purpose is field mobility to preserve the device’s current state until further forensic analysis can occur.

AppLogic 5.6.0 (regular graykey device) will create an Evidence Preservation Mode option that allows users to gain initial access to a device to protect it without imaging it. The mode will also avoid collecting specific identifiers from the device to ensure that only preservation actions occur.

Is the “force restart” the up/down/power hard reset or something else?

Changing the topic completely…

With recognition that the threat model for this post is defending against physical access, in theory would these measures also protect against commercial spyware (with and without lockdown mode)?

For example, the supervised profile provisions that block various methods of app installation might theoretically protect against the installation of anything.

I haven’t been able to confirm whether supervised device restrictions can be bypassed or not. I always assume Cellebrite/Graykey has something up their sleeve for this. From my understanding, the “mdm profile” is just lines of text in the file system and we already know they can access the file system with their tools. The supervised state may be embedded deeper in the devices firmware but if the configured profile can be modified/bypassed even temporarily, it is useless.

You will most definitely need lockdown mode enabled for commercial spyware.

And yes, up/down/power hard reset.

1 Like

Just wondering if anyone knows the answer to this question?

What is the motive behind unchecking everything in Search? Does that disable app indexing?

I haven’t been able to confirm whether supervised device restrictions can be bypassed or not. I always assume Cellebrite/Graykey has something up their sleeve for this.

Not challenging any of your assertions, thank you for all of your expertise provided here. I just want to confirm that you are referring to this section in the original post:

Create a MDM profile with the following payloads

There seems to be evidence to support this being effective that has been provided in the discussion here. Did something change?

Yes. Elcomsoft blog details a lot about how these extractions work. Although cellebrite and graykey don’t often talk about their weaknesses publicly, elcomsoft does and there’s no reason to believe the methods between these companies are much different on iOS.

All FFS extractions on A12+ require sideloading an agent (app) to to the device. This applies to all forensic vendors and can be easily verified by reading here. That app cannot be installed if you follow this tutorial.

Interesting old CVE I found. The extra mdm payloads I listed would still defeat this though like allowAppInstallation. Lockdown mode also blocks configuration profiles from being configured too. Keep your device up-to-date (model and iOS).