TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

iOS 11.4 to Disable USB Port After 7 Days: What It Means for Mobile Forensics

544 pointsby louis-paulabout 7 years ago

44 comments

davidmrabout 7 years ago
I’m so unused to seeing a corporation act in the interests of their customers explicitly counter to the wishes of law enforcement and the intelligence community that I’m racking my brain trying to think of ulterior motives that explain why Apple might have this.<p>Either way, on the surface, I’m quite pleased by this development.
评论 #17021808 未加载
评论 #17021744 未加载
评论 #17022004 未加载
评论 #17022407 未加载
评论 #17022314 未加载
评论 #17023150 未加载
评论 #17022724 未加载
评论 #17023640 未加载
评论 #17023511 未加载
评论 #17025278 未加载
评论 #17023222 未加载
评论 #17025396 未加载
评论 #17021924 未加载
评论 #17022543 未加载
评论 #17026489 未加载
评论 #17022667 未加载
cromwellianabout 7 years ago
This seems like it’ll just make police departments go to a judge more often alleging probable cause immediately, and judges might be more inclined to grant given the time pressure, thus paradoxically it might end up with more phones being opportunistically subject to warrants by the police as the justice system would be given less time for duebl consideration. A “ticking bomb” tends to produce anti civil liberty behavior on the authorities.<p>they should have a setting to disable it almost immediately.<p>I almost never us the data connection on my iPhone usb except for headphones, yet another downside of losing the audio jack :)
评论 #17022613 未加载
评论 #17021762 未加载
评论 #17023967 未加载
评论 #17026602 未加载
评论 #17023639 未加载
jrowleyabout 7 years ago
Google&#x27;s Cached version if you&#x27;re having issues accessing it:<p><a href="http:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache:https:&#x2F;&#x2F;blog.elcomsoft.com&#x2F;2018&#x2F;05&#x2F;ios-11-4-to-disable-usb-port-after-7-days-what-it-means-for-mobile-forensics&#x2F;" rel="nofollow">http:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache:https:&#x2F;...</a>
评论 #17022077 未加载
评论 #17022010 未加载
评论 #17022122 未加载
Zenstabout 7 years ago
One test I would carry out and well within the remit of geeks and enforcement - would be a femtocell&#x2F;base station with a time update (which mobiles accept blindly if you let them). Forever keep connected devices in a Groundhog day.<p>That would certainly be the go to test for many I suspect, a tried and tested hack from days of old, brought into modern times.
评论 #17021921 未加载
评论 #17022632 未加载
parliament32about 7 years ago
A step in the right direction, but I&#x27;d like to see this interval reduced (12 hours? 1 hour?) or brought down completely (I should have the option to require an unlock before any connection is established). There&#x27;s no reasonable use case where I would want to make a connection while not wanting to unlock the phone.
评论 #17023788 未加载
Ajedi32about 7 years ago
How is this different from how Android works, where you have to unlock your phone and explicitly tell it to connect every time you want to use a USB connection for anything other than charging?
评论 #17021776 未加载
评论 #17021739 未加载
评论 #17021722 未加载
评论 #17021695 未加载
donkeydabout 7 years ago
Blog seems to be hugged to death, so I might be uninformed.<p>What exactly happens after the 7 days? My girlfriend&#x27;s iPad got blocked on vacation (bluetooth keyboard in a bag causing random inputs). To get it fixed, we needed to connect to a computer. Would this mean that if you don&#x27;t get to a computer within 7 days it would be essentially be bricked?
评论 #17022327 未加载
评论 #17022761 未加载
sdtransierabout 7 years ago
Maybe I missed this in the article, but does anyone know if this feature can be turned off? Or if it&#x27;s enabled by default?<p>What happens in the scenario of a consumer having an old iOS device sitting around, they forget the passcode, but now can&#x27;t reset it using iTunes?
评论 #17021685 未加载
评论 #17021777 未加载
评论 #17021697 未加载
Havocabout 7 years ago
Glad to see Apple is at least trying to protect their users.
评论 #17022202 未加载
csenseabout 7 years ago
The obvious flaw in a time-based lockout is that it needs a trusted measurement of the current time.<p>If law enforcement wants to bypass this, the obvious approach would be to just remove the battery (to remove power from any internal RTC chip) and put the device in a Faraday cage (to block external time signals like GPS and the cell network). Then the shutdown clock would literally stop ticking until they turn it on again.
评论 #17023742 未加载
评论 #17025162 未加载
评论 #17023773 未加载
评论 #17029551 未加载
评论 #17024105 未加载
评论 #17024441 未加载
评论 #17023748 未加载
tbyehlabout 7 years ago
Why 7 days? I&#x27;d like a feature to never allow any USB communication until I&#x27;ve unlocked my phone, and then to allow it only for as long as they remain continuously connected.<p>Or to activate this feature with &#x27;Emergency Mode&#x27; (5 power button presses).
评论 #17022750 未加载
评论 #17027084 未加载
评论 #17025030 未加载
MaikuMoriabout 7 years ago
Can someone explain how it is better than android? When I plug in my android, only charging works. I need to unlock the phone and enable data to make the data connection work. There is never trust this computer prompt. I have to do this always, even when due to bad wire the connection is lost for a split second.<p>Some people mentioned that android never shipped this feature and that Apple is first, but it seems to me that android never had this problem in the first place.
51Cardsabout 7 years ago
There are Kiosk uses of iPads where this could be an issue. Often those devices are mounted 24&#x2F;7 inside a secure housing and left on but communicate with external devices. Now someone will have to reset them once a week.<p>Edit: thanks for the clarification below. I had the implementation wrong in my head. And yes, I realize this is a fairly edge use case, just one that affects my industry.
评论 #17022430 未加载
评论 #17022341 未加载
评论 #17022322 未加载
评论 #17022230 未加载
评论 #17022220 未加载
ape4about 7 years ago
The time deadline might have some unintended consequences. Maybe law enforcement will proactively image people&#x27;s phones early knowing it will be harder later. eg you are stopped at the airport. A judge may give give quick search warrants since its &quot;now or never&quot;.
kiddicoabout 7 years ago
I&#x27;m really not a fan of the hardware design choices of apple devices recently, but the focus on security&#x2F;privacy might pull me back in.
paulsutterabout 7 years ago
I wish I could just disable the data connection permanently<p>&gt; Restricted USB Mode requires an iPhone running 11.3 to be unlocked at least once every 7 days. Otherwise, the Lightning port will lock down to charge only mode. The iPhone or iPad will still charge, but it will no longer attempt to establish a data connection. Even the “Trust this computer?” prompt will not be displayed once the device is connected to the computer
k_szeabout 7 years ago
I wonder how iOS keeps track of the 7 days in question.<p>For an iOS device still connected to the internet or to a mobile phone network, I presume it will periodically make an NTP request or get the date&#x2F;time from the mobile phone carrier, to adjust its clock. What if those requests are MITM&#x27;ed?
评论 #17026990 未加载
vbezhenarabout 7 years ago
Is it known how those greykey devices even work? AFAIK iOS blocks many consecutive attempts to enter pin, so brute force would take too much time. It seems that greykey device can bypass this restriction using USB. Why Apple didn&#x27;t just patch this vulnerability instead of disabling USB?
评论 #17022277 未加载
评论 #17023403 未加载
评论 #17022669 未加载
exabrialabout 7 years ago
I fear this is really only going to have the reverse effect, instead of carefully examining whether or not 4th Amndment protections apply, &quot;Out of an abundance of caution&quot;, courts will immediately seize and decrypt your phone.<p>Not to nitpick, but I wish these things were opt-in. For instance, I don&#x27;t really care if I&#x27;ve restarted my mac and have to use my password again to log in, I&#x27;d rather use my fingerprint. I just need to prevent casual attackers, there is _literally nothing_ on here that needs to be protected with fort-knox level security.
blueseaadminabout 7 years ago
Two ideas:<p>What about paired hardware? Imagine buying an iPhone and pairing it with your charger and they share keys. Any other charger used would immediately wipe the phone. There could be settings to tweak this.<p>what about wiping the phone if it has not been logged into a certain amount of time with a certain password (not normal PIN)?<p>The current crop of phone busters completely bypasses the 10 wrong pin and wipe option. The idea is to immediately wipe the phone without using Find my iPhone (defeated with airplane mode).
评论 #17023194 未加载
plussed_readerabout 7 years ago
Can I still kick the device into recovery mode with a cable after 7 days with this mode? Or would I have to unlock the device to re-enable recovery mode?
评论 #17031635 未加载
jldabout 7 years ago
Say a user drops their phone in a desk drawer and goes on an 8 day hiking trip.<p>He&#x2F;she comes back and can&#x27;t remember their passcode. Is the phone now a brick?
评论 #17022416 未加载
评论 #17022197 未加载
nneonneoabout 7 years ago
To me, it feels like Apple is trying to figure out how GreyKey and Cellebrite are getting in - and patching every vector they can think of in the meantime. I suspect that if law enforcement agencies are suddenly told they have to unlock new Apple devices within 7 days of acquisition, Apple will find out and can infer that the exploits have (e.g.) something to do with USB accessory access.
mdeslaurabout 7 years ago
Can a device still be wiped when this happens? I&#x27;m wondering how to recycle or recover locked devices if the USB port is disabled...
评论 #17022512 未加载
post_breakabout 7 years ago
Will this cause warrants to be rushed through and much more often? Just to get the phone unlocked in case something is in there, even if there may be no burden of proof. Better to overnight it to a facility with a tool to unlock it and sign off on a quick warrant.
dwighttkabout 7 years ago
Why seven days? How about 24 hours? Or even better if the device is locked I have to unlock it to use the port for anything besides charging (and it can then lock on its usual schedule)
kevin_b_erabout 7 years ago
This doesn&#x27;t quite sound as amazing as a first look, because this is not a full &quot;data connectivity&quot; kill. Data connectivity is always required whenever people use headphones due to headphone jack removal.
评论 #17022073 未加载
评论 #17022698 未加载
评论 #17023799 未加载
rad_gruchalskiabout 7 years ago
403 Forbidden in Germany.
评论 #17022775 未加载
评论 #17022702 未加载
jiveturkeyabout 7 years ago
i suspect this will be a net negative. now that law enforcement has a time limit, graybox sales will flourish, and law enforcement will access your phone ASAP before collecting other evidence. then the phone evidence itself will give them the clues they want and they’ll get the warrant after the fact. or the court may even be complicit and issue a warrant without enough supporting evidence due to the risk of evidence destruction.
x0054about 7 years ago
Why 7 days though. It&#x27;s should disable within 2 hours at most, and users should have the option to disable USB when ever the phone is locked.
gaiusabout 7 years ago
Why 7 days? 24 hours should be enough - who connects devices but doesn’t unlock in that time? Can’t think of a scenario for that.
nottorpabout 7 years ago
Like everyone else, I&#x27;m curious how you recover your forgotten pass code after 7 days.<p>Also, what happens if you don&#x27;t use a passcode?
评论 #17025848 未加载
linarismabout 7 years ago
Is there any security reason someone would purchase a security-focused Android phone (Blackphone, Blackberry) over an iPhone?
评论 #17023759 未加载
qnttyabout 7 years ago
Why not 7 hours or 7 minutes or immediately?
评论 #17022343 未加载
评论 #17022099 未加载
评论 #17022094 未加载
jlebrechabout 7 years ago
I&#x27;m pretty sure they can just remove the chip and dump the contents.
sliabout 7 years ago
Kind of amazing seeing this story right next to the Google Duplex story.
Animatsabout 7 years ago
Why should it even be enabled if you&#x27;re not logged on?
eulers__numberabout 7 years ago
this is why I will never use google pixel tho I will still be forced to use gmail, search, and Youtube because of its conveniences, hopefully in the future something new that comes out that has mathematical open source decentralized form of censorship-proof algorithms will come out
billabulabout 7 years ago
if the device time is synced from elsewhere maybe one could spoof a ntpd server and provide a time in the past?
评论 #17022616 未加载
评论 #17022892 未加载
gruezabout 7 years ago
How is this relevant when law enforcement can buy a $15k device that unlocks the phone?
评论 #17021821 未加载
评论 #17021846 未加载
atonseabout 7 years ago
Does this mean that companies will now try to exploit the USB&#x2F;Lightning driver to gain access?<p>The cat and mouse game continues.
评论 #17021700 未加载
评论 #17021891 未加载
samfisher83about 7 years ago
You could just pull the flash chip and image it. You would need to figure out how to get the key, but pulling the flash chip and reading it doesn&#x27;t look too hard if you can use a heat gun. If you lived in Shenzhen you could go the market and buy a flash reader.<p>Strange Parts is youtube channel where the guy does this.<p><a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=rHP-OPXK2ig" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=rHP-OPXK2ig</a>
评论 #17021863 未加载
评论 #17021856 未加载
评论 #17021874 未加载
评论 #17021805 未加载
wstuartclabout 7 years ago
...<p>Every 6 days from point of collection: Place phone in caged room. Turn on your cell phone network interceptor device. Set interceptor&#x27;s network time to device collection time. boot phone, await for it to update network time from cell interceptor.<p>...<p>So many edge cases&#x2F;ways to defeat this that need to be handled.
评论 #17022863 未加载
评论 #17022782 未加载
评论 #17022829 未加载
评论 #17023715 未加载
john37386about 7 years ago
I would like to read this article but, the website doesn&#x27;t load. I guess it&#x27;s not optimized to front page HN.<p>May I suggest to loadtest your website or article before posting it?<p><a href="https:&#x2F;&#x2F;ddostest.me&#x2F;load-test&#x2F;" rel="nofollow">https:&#x2F;&#x2F;ddostest.me&#x2F;load-test&#x2F;</a>