# The iPhone the FBI Couldn’t Hack

**URL:** https://discuss.privacyguides.net/t/the-iphone-the-fbi-couldn-t-hack/40932
**Category:** Videos
**Created:** 2026-09-24T19:13:05Z
**Posts:** 26

## Post 1 by @jordan — 2026-09-24T19:13:05Z

In 2016, a locked iPhone 5C sparked a massive showdown between Apple and the FBI. When the US government demanded Apple push a modified compromised update to bypass iOS Security, it created a national debate; where does individual privacy end and public safety begin?

https://neat.tube/videos/embed/nX2HLoKpSichKT3qwjPuZD

> **[The iPhone the FBI Couldn’t Hack](https://youtu.be/p5LSaATxA6g)**
>
> In 2016, a locked iPhone 5C sparked a massive showdown between Apple and the FBI. When the US government demanded Apple push a modified compromised update to...

---

## Post 2 by @jordan — 2026-09-23T01:11:51Z



---

## Post 3 by @Expert4870 — 2026-09-26T00:48:11Z

Woah I did not noice this went “viral”. You’ve been popping off @nateb . It’s the most viewed video in a day compared to other videos by almost 4x. The password manager tierlist which was the second most viewed on the channel which was only 4 weeks ago.

150k views for people that don’t use YT.

It went from 148k to 151k in the time I watched it :grinning_face:

I really like how it’s not doomerism at the end. I’ve always wanted those popular videos on privacy to have something actionable for the normies who are interested, and every Privacy Guides video has that through the website.

---

## Post 4 by @privacyisconsent — 2026-09-26T08:11:06Z

Quick mention for Insider Attack Resistance (IAR) [Android Developers Blog: Insider Attack Resistance](https://android-developers.googleblog.com/2018/05/insider-attack-resistance.html) which has been implemented in Google Pixels since 2018 (Pixel 2) and mitigates this problem.

---

## Post 5 by @nateb — 2026-09-26T13:51:07Z

It should be noted that YouTube recently changed the way they count views. They’re more like clicks than actual “engaged views,” but yes it is still our most viewed video to date (and the most viewed video I’ve ever been involved in, personally).

Yeah it’s really important to me that videos give people actionable takeaways wherever possible. Less so on these historical videos but def on ones where we talk about threats to privacy or some big privacy video - like Bullrun. “The NSA hacked everything and spied on everyone - BUT here’s why you shouldn’t just throw up your hands and say ‘fuck it.’”

---

## Post 6 by @Expert4870 — 2026-09-26T17:52:20Z

Oh yeah I forgot about that. I saw a YouTuber say there’s a way to still see the old view count in your dashboard or something.

---

## Post 7 by @Torsten — 2026-09-27T15:40:11Z

Nice one!

I wonder, does this “wipe after x unlock attempts” exist on Android? I don’t think so.

Samsung has implemented increasing delays between unlocks.

Pixels have the secure element doing the unlocking and preventing brute forcing.

Still, such a simple software solution would be a nice add-on.

---

## Post 8 by @nateb — 2026-09-28T16:53:26Z

I don’t think it does. I know Graphene has the duress PIN, which some have suggested setting to something obvious like “1234” or your birthdate so that if an adversary tries to unlock your phone they wipe it instead, though as we’ve seen that could potentially have legal ramifications.

---

## Post 9 by @EsperZero — 2026-09-28T17:20:10Z

There are workarounds while exercising your right to refuse the unlock.

1. Write the BoD in your pin and put it on a folded paper behind the case with something like “Changed pin, noted to remember it again: 120100” Legally you did not tell the law enforcement or security your pin, it was just there and it would be hard to prove whenever you did it intentionally or not, its not impossible but it would just perplex the law enforcement and when it comes to getting into court, if it wasn’t lawful, the paper with the pin wouldn’t even be in the question now
2. Reboot your phone, Cite it as a necessary often move since it might glitch or something like that, Put a straight face as you say that. it should go in BFU and make it impossible to access it even if they gave up on the pin

Obligatory not a lawyer, any proper legal advice should go to them!

---

## Post 10 by @nateb — 2026-09-28T22:08:39Z

I recommend against giving legal advice unless you are a lawyer. I’m sure these aren’t bulletproof. BFU, for example: a judge can legally order you to unlock the device. It’s happened before.

Just FYI.

---

## Post 11 by @blibly — 2026-09-28T22:16:38Z

> I know Graphene has the duress PIN, which some have suggested setting to something obvious like “1234” or your birthdate so that if an adversary tries to unlock your phone they wipe it instead,

Would any adversary believe a GrapheneOS user would have an easy-to-guess PIN?

---

## Post 12 by @nateb — 2026-09-28T22:25:45Z

You’d have to be an idiot not to try.

Also yeah. There’s lots of people who say things like “I got my whole family using Graphene.” You’re telling me all those people are using super secure 86-character alphanumeric passwords? My wife is watching TikTok 3 feet away from me as we speak. Not everyone is living that Secure Life™.

---

## Post 13 by @EsperZero — 2026-09-29T04:56:02Z

That’s fair I added it and yes those are not bulletproof but something you can try to mitigate the ramification.

Amd of course if law enforcement or judge has a valid warrant or order on unlocking your phone then you cannot give or leave a duress pin, you have to give the actual pin on that as the ramification would be worse

> [@EsperZero](#):
>
> Obligatory not a lawyer, any proper legal advice should go to them!

---

## Post 14 by @kjyr — 2026-09-29T05:38:11Z

No. Assuming they have sufficient information about who you are, which includes how security conscious you are, which they will find out if the crime they suspect you may have committed is serious enough (therefore they have the motivation and resources), unlike what Nate said, there’s simply no chance they would attempt that PIN unless a cop decided to try to open the phone before it made its way to cipher / forensic analysis. If they know you’re using GrapheneOS, they know you might be using a duress PIN. And finding out that you have GrapheneOS could either be easy, or potentially legally enforceable to disclose (IANAL).

I don’t think assuming law enforcement are dumb is a good assumption, especially when it comes to digital forensics. Those beat cops you see on social media fumbling around trying to detain a suspect might not be the brightest, but I wouldn’t put it past detectives and lab techs to figure this stuff out. They’re betting on you to assume that you can outsmart them and then use your hubris against you. They deal with those kinds of people all the time, that’s literally their job.

I don’t really believe there is a good strategy against this threat except not getting on their radar in the first place.

---

## Post 15 by @nateb — 2026-09-29T21:47:06Z

> [@EsperZero](#):
>
> you have to give the actual pin

I’m not a lawyer either, but I have it on good authority that you don’t have to give them the PIN or password as that’s a violation of both the first and fifth amendments, you simply have to unlock the device and hand them the unlocked device.

When in doubt, just say “I want an attorney” and “I invoke my right to remain silent.” That’s what my sticker from EFF says, so I’ll just defer to them lol

---

## Post 16 by @overdrawn98901 — 2026-09-29T22:03:59Z

I’d do something funnier. Same thing, but write “PIN: do not enter 123456”.

Then if it’s entered, it was clearly explained not to enter that PIN. Good ol reverse psychology.

---

## Post 17 by @overdrawn98901 — 2026-09-29T23:25:05Z

> [@nateb](#):
>
> living that Secure Life™

> **New Merch Drop Idea**
>
> ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/2/4/24200bfbb62fd673cc6e050415d739c8b7667f24.jpeg)

---

## Post 18 by @freddy — 2026-09-30T00:06:08Z

Such good content! Absolutely killing it team :raising_hands:

---

## Post 19 by @EsperZero — 2026-09-30T04:41:46Z

Agreed here didn’t think the part that you could just unlock the phone and hand it over, even then you could just change it after they issue their investigation and they return it. But yes that’s a far better option than the former

@overdrawn98901 Obligatory not a lawyer, consult with one for legal advice but isnt like “do not type 123456” just essentially make it more suspicious than if you just made it look like a normal note like my proposal?

---

## Post 20 by @jonah — 2026-09-30T17:34:18Z

![CleanShot 2026-09-30 at 11.58.08 AM@2x](https://forum-uploads.privacyguidesusercontent.com/original/3X/5/2/523f6d0d38812e88514d57b429ea7d093d4bf77f.jpeg)

 ![CleanShot 2026-09-30 at 12.33.35 PM@2x](https://forum-uploads.privacyguidesusercontent.com/original/3X/7/5/7535a195498021a7126694ec46e2950692a29d51.png)

---

## Post 21 by @Expert4870 — 2026-09-30T17:40:18Z

The YouTube shadowbanning privacy content is fake?

I know the Hated One has complained about it but it may just be a skill issue.

---

## Post 22 by @jonah — 2026-09-30T17:40:42Z

No, we are shadowbanned on YouTube. This should’ve gotten 10M

---

## Post 23 by @overdrawn98901 — 2026-09-30T18:01:46Z

Probably, mine was more as a joke. But if I put my **fake** lawyer hat on, I’d assume you’d want plausible deniability that the PIN was not placed there to fool someone (police) into entering it to get them to wipe the device. Reverse psychology does not pass if it’s apparent I meant for them to find it to wipe it. Essentially raising legality of an [information hazard](https://en.wikipedia.org/wiki/Information_hazard) conducted by individuals.

---

## Post 24 by @nateb — 2026-10-02T02:13:18Z

So not to start drama, but years ago a mentor of sorts once told me that he thinks that shadowbanning is MOSTLY just a persecution complex because in his experience, if a video bombs on YT it also bombs on other platforms like Odysee & PeerTube, showing that it’s not that the algorithm is trying to censor you but you just made a dud video. It happens. They’re not all winners. Rather than cry about it, you just gotta shake it off and keep going.

Maybe it’s confirmation bias but ever since he told me that, I’ve noticed it to be mostly true in most places I look.

That’s not to say it NEVER happens, but more often than not…

---

## Post 25 by @Torsten — 2026-10-03T11:21:33Z

Apparently there is a cooldown embedded in the secure element, the longest being 41 days. Afterwards it is locked entirely somehow.

> **[GrapheneOS protections against data extraction from locked devices -...](https://discuss.grapheneos.org/d/40700)**
>
> GrapheneOS discussion forum

---

## Post 26 by @Torsten — 2026-10-03T11:26:09Z

\*in the USA

This is an international community, making legal advice even harder XD
