According to 404 Media, a company that makes devices to hack phones claims they can bypass iOS's automatic reboot feature and allow police to more easily access data on iPhones.
Power off device if you think it’s going to be seized, even if this feature was working fine, you’d want it in BFU immediately rather than give them 72 hours to try anyway. Otherwise, don’t get into situations that your phone would be seized by LE? If you expect to be defending against forensic companies than GrapheneOS would probably be better. It really depends on your threat model.
The reporting about this tool appears to be quite delayed for 404 Media and I am surprised they did not mention that their competitors also have this same functionality. This is casually advertised on the Magnet Forensics web site and I remember seeing it in DFIR mailing lists prior to that.
I communicated with Osservatorio Nessuno earlier in the year to warn their audiences of these tools in the ‘Demystifying phone unlocking tools’ article. We also mentioned Cellebrite’s equivalent functionality ‘Safeguard Mode’ part of their Inseyets suite there. It was known earlier than this article was made though. The link is available below with countermeasures that you can take, with most being neutral to the platforms.
Multiple members of this forum have already spoken about GrayKey Preserve so I won’t bother saying much. What you should take away from it is that this is a clear example of how mobile forensics companies adjust their strategies when new security / privacy features are introduced.
Today, a technique to prevent automatic reboots is just as much, or more, of a device support target than having an AFU Locked extraction capability. In the future, devices with an automatic reboot functionality will be more commonly used than old devices that do not have this feature. When an AFU Locked extraction is available, it can only be used on phones seized right before or long after the technique is released to customers.
An override of an automatic reboot expands the audience of potential targets for extraction even if an AFU Locked extraction capability is not generally available to that device yet. It would also considerably speed up the time of waiting compared to the time you might have to wait to create a fast brute force for a BFU device with a weak credential protected by a secure element.
We threat modelled that the GrapheneOS auto-reboot feature could be targeted in this way, and that’s why there are other features like the USB-C port control to prevent delivery of exploits through USB. This is not really the context to promote GrapheneOS though.
I’m so disappointed that Apple apparently still hasn’t implemented this, at least in a way that actually properly disables the port and prevents this, and I guess the stock Pixel OS also hasn’t? But great work by GOS as always.