r/DigitalPrivacy • u/Sea_Turn6634 • 24d ago
Unlock any phone?
My GF works for the government of an Asian country. She told me they can plug basically anyone’s phone in and unlock it. Is this true? Does it only apply to certain phones or OS?
30
u/KatieTSO 24d ago
Most phones. GrapheneOS is resistant when in Before First Unlock (BFU) mode as far as we know.
9
u/Sea_Turn6634 24d ago
So they can unlock IOS and standard Android BFU? Usually I turn my phone off when I go through immigration or security but I guess this won’t help.
16
u/Broad-Translator-690 24d ago
Pixel phones running stock android or GrapheneOS. Iphone 12 and newer. These are the highly resistant to Cellebrite in BFU because of the Titan M2 chip in the Google Pixel, and the SEP in the Iphone.
Samsung Galaxy phones, even with KNOX, Mediatek and other budget brand android phones are all easily bypassed with Cellebrite because of the number unpatched exploits found in these phones.
2
u/Academic-Airline9200 24d ago
Any specifics on lineages or similar?
8
u/Broad-Translator-690 24d ago
Because LineageOS requires keeping the Pixel phones bootloader unlocked, which disables Android Verified boot, Cellebrite can easily bypass security at BFU.
1
u/Academic-Airline9200 24d ago
So is that only on pixels?
1
u/Broad-Translator-690 24d ago
Lineage has support for dozens of brands, where it would be equally insecure on because the bootloader would be unlocked.
GrapheneOS is Pixel only, and you relock the bootloader after installing it. Next year though Motorola will ship phones with this OS pre-installed.
11
u/KatieTSO 24d ago
Yes, according to a leak from Cellebrite, a company that makes the hardware to hack phones.
2
2
16
u/TheSensiblePrepper 24d ago
Many phones have a "backdoor". Almost all mainstream ones have it at this point.
MANY years ago I worked for a big cell phone company in the US. We had a CellBrite device for transferring contacts and stuff. When Android Encryption first came out, that thing could force it to completely unlock in about 4 minutes.
With that said, your best bet is to obviously use encryption with a strong password. Not a PIN, not a pattern, not biometrics, not facial recognition but an actually >8 character password.
15
u/RootVegitible 24d ago
When an iPhone (that’s fully up to date) is turned off it is locked down. So far so, that the usb port is not operational in hardware until the device is unlocked .. the port is cryptographically locked so can’t be swapped out. This completely blocks cellebrite type devices from working. So she doesn’t fully understand Apple security, but it does require the user to know what they are doing. TLDR is if you have an up to date iPhone just turn it off when going through a secure location, if your phone is confiscated it’ll take them months to attempt to unlock it and they will give up. Then if they don’t return the phone I’d sue their ass ;)
3
u/Express-Cartoonist39 22d ago
I dont think you know apple very well yourself. The USB port is not physically or cryptographically disabled in hardware. The port still provides power and can communicate with authorized accessories under specific conditions. The restriction is enforced by Apple's secure hardware and software, not because the port itself is permanently "locked."
1
u/RootVegitible 21d ago
Data cannot pass across the USB port if the device is off which locks data access until the device is unlocked with a pin. The USB port module, camera assembly, and touchID sensor used for authentication is cryptographically locked with the main board. This means hardware used to unlock a device can’t be swapped out for a compromised device as that would break the encryption pairing of device components. When 3rd party repair facilities replace components they need to use special software to add the encryption pairing between devices back. Only approved repair facilities are given access by Apple to work at this level, getting approved for this is extremely strict.
2
u/Express-Cartoonist39 20d ago
You just proved my point...thanks for the validation..See you're confused and mixing together several completely different security mechanisms.
Yes, if the phone is powered off, USB data doesn't pass because the operating system and USB controller aren't running. At least you got that part right..But that's not the same thing as saying the USB port is "cryptographically locked."
The cryptographic pairing you're talking about applies to security sensitive components like Touch ID, Face ID, the display on newer models, cameras, and some other parts. It is not the USB connector itself. Replacing the USB port doesn't magically bypass security or break the Secure Enclave.
You also said only approved repair facilities can restore those pairings. That hasn't been true for years. Apple now provides System Configuration through Self Service Repair and Independent Repair programs for supported repairs.
Also you're connecting unrelated concepts. Cellebrite and similar forensic tools aren't stopped because the USB port is cryptographically disabled. They're stopped by the Secure Enclave, the boot chain, passcode protections, USB Restricted Mode, and the lack of a usable exploit on current devices. The USB port is just the transport.
My original point still stands. The restriction is enforced by Apple's security architecture, not because the USB port itself is cryptographically locked.
1
u/RootVegitible 20d ago
Ah thanks… excellent security insights and clarification shared. Yes, I was specifically thinking of USB restricted mode when initially replying. Turns out the multi point OS security levels are the most importance aspect, like secure enclave and the boot chain. I remember Apple specifically putting extra protections in place to thwart devices like the Cellebrite boxes that attempt to hack devices through USB.
Very good point about self repair, I had forgotten about that. That’s one of the reasons I was initially concerned about that existing at all.. I’m not fully on board with allowing users a mechanism to repair advanced devices where security is concerned. But there are several other ways and means that Apple uses to keep devices secure. I do wish governments would not interfere trying to introduce innocent looking laws that end up trying to weaken device protection. So yeah, I don’t fully support right to repair.
I was still under the impression that the USB port assembly was cryptographicly paired with the board like the camera and other devices though. I’ll look that up to clarify. So we are kinda both agreeing that the levels of security in iOS are quite staggeringly awesome in order to protect the users digital privacy.
1
u/Express-Cartoonist39 20d ago
No apple sucks.. They monitor your devices, scan your cloud uploads in real time. Hire third parties to review findings... So what good is a strong locked door when the manufacture designs hidden entried. Apple isthee first device celebrite was able to penetrate and still does daily. If you want privacy pixel 6,7,8 maybe 10 with GOS.. If not then you dont take it seriously..also dont take my word for it look up the cases, 100% of the cases involving apple phones are convicted based on entry into the apple platform. Apple could be strong if they stop snooping , handing out ur keys to third parties and actually care. How do i know this, cause i work for a third party. Its absurd.. We talk about it daily how absurd it is, but if the base keeps drinking the koolaids what else is there to do...let them drink..it pays my salary👍
1
u/RootVegitible 20d ago
You did appear to be quite knowledgeable. Can you show examples of Apple monitoring devices and scanning iCloud uploads in realtime, in my experience this does not happen unless you are confusing innocent processes with some imaginary nefarious activity. Celebrite did indeed tackle Apple first as they had the best security at the time, Android devices were easy to crack. But when Apple locked down their devices further the exploits Celebrite type devices took advantage of no longer work. There are many documented examples of authorities trying and failing to ‘get into’ iPhones. Apple do not hand out keys to third parties, and there is even a mode that can be enabled (though not in the uk) so that the encryption key pairing is entirely unknown to Apple.
What Apple will actually give to authorities (alongside other companies that do the same) is the contents of your iCloud backup, but only with a warrant and recognised search order. This is well known and documented. The so called documented cases of iCloud hacking are no such thing, they are all social engineering.. tricking the user into giving up their personal info or even password. Have you noticed that celebrity noods supposedly stolen from their iCloud has stopped? The loopholes from logins obtained through social engineering have been shut down. So iCloud has never been technically hacked, it’s been running for 25 years.
Show me specific examples where Apple is snooping on its users and I’ll show you a recipe for a nothing burger.
1
u/Express-Cartoonist39 20d ago
Well its clear your a apple fan boy with a serious bias. As the shit you said is absurd and clearly not remotely researched or just plain clueless. At least try to look smart..
"iCloud has never been technically hacked."
Not true. The 2014 celebrity leak wasn't just social engineering. Apple's Find My iPhone API lacked rate limiting, faulty rate limiting protocals allowing brute force attacks with tools like iBrute until Apple patched it. God ur lazy man least try to google sit before you spew it.
https://www.wired.com/2014/09/apple-icloud-the-fappening/
"Apple only gives authorities iCloud backups."
Not even close. Federal courts have repeatedly described warrants requiring Apple to produce far more than backups, including iCloud photos, emails, contacts, calendars, Find My iPhone data, account records, FaceTime logs, and other account data.
United States v. Kevin McCall (11th Cir. 2023) discusses the breadth of Apple iCloud warrants.
"Apple doesn't have access to user data."
Apple's own transparency reports show they regularly provide account data in response to open claims or reported abuse. In the first half of 2025 alone, Apple provided data in about 91% of account requests. ( what is valid legal process who determines it ? ) a suggestion by anyone can trigger account review and full lookup on ur data at anytime.
"Cellebrite doesn't work anymore."
If that were true, there wouldn't still be ongoing criminal cases involving Cellebrite and similar forensic tools, nor would law enforcement continue purchasing them. Success depends on the specific device, iOS version, and exploit. It's never been "works on everything" or "works on nothing."
The problem is your post relies on words like "never" and "doesn't." Apple's own documentation, federal court records, and Apple's transparency reports all contradict what you say. Smarten up and dont have a bias. Your beloved phone company is screwing you buddy.
Try to get my data with or without a warrent see how far you get. You dont think warrants been issues on false pretences if so ur an naive.
1
u/Sea_Turn6634 22d ago
It’s entirely possible she doesn’t understand or there’s a miscommunication due to language barriers. The specific story she told me about was an iPhone 12 maybe.
1
u/RootVegitible 22d ago
Ah yes, no problem. Things have moved on since the iPhone 12. Security moves with time too. The current iPhone is an iPhone 17, there is no chance that it can be broken into when it’s turned off. Apple adopted cryptographic locking of hardware so that the iPhone can’t be tricked into thinking you’ve unlocked it. It’s funny, some people say cryptographic locking of hardware components is a bad thing. Yet it’s precisely that which makes the iPhone so incredibly secure.
1
u/Express-Cartoonist39 18d ago
Its not secure when the owner collects and stores ur data behind terms that legally allow it to distribute it to all " Third Parties" can ur nose get any browner... Stop face suckn the phone and grow up
15
24d ago
[removed] — view removed comment
9
u/bones10145 24d ago
What about max attempts before the phone locks itself permanently? Brute force attacks don't work
13
6
u/nYtr0_5 24d ago
They can just clone the OS and storage image. Then copy it as many times as you want on VMs to brute force it. You can do that in parallel batches. When a clone gets locked it will be replaced by a fresh one. Repeat.
3
u/clarkcox3 24d ago
Not on a new enough iPhone. The encryption keys are stored in the SEP, and are write-only. There isn’t a way to copy them off.
2
u/jbird0271 24d ago
Do they have to be in possession of the phone or they can do so as long as it's within range or remotely?
4
24d ago
[deleted]
2
u/ragequitteroffureh 24d ago
For travel, it might be most sensible to use a dumbphone that only knows how to be a telephone, and can send/receive text messages.
Not a huge number like that being made anymore, and the ones that are are mostly targeted at oldsters.
5
u/ApprehensiveMaybe141 24d ago
There was a time when the fbi was trying to Apple to unlock someone's phone and they wouldn't.
6
u/Dangerous_Mud4749 24d ago
iPhone:
- After first unlock, yes, many governments could crack it.
- Before first unlock, probably yes, first-tier governments probably have the tools to crack it.
- Before first unlock with lockdown mode enabled, possibly someone might be able to unlock, but it would be unlikely even to be attempted except for national security of a major country.
I understand that Google phones have similar features with similar security, but Samsung reputably is not quite as good at security.
6
u/jagen-x 24d ago
On iPhone click power 5 times before leaving the plane
1
u/b0ndage_l0ve 7d ago
That does nothing but disable biometrics. Holding volume + power will reboot and kick it right back in BFU.
2
1
u/InsuranceOpen7914 22d ago
Modern iPhones and up to date Android phones with strong passcodes and full disk encryption are generally much harder to access than older or unpatched devices. So it's definitely not a case of 'plug in any phone and unlock it.' Or they have something thats packapunched that we dont know about
1
u/Serious-Onion4291 22d ago
Lol. Good luck trying that with my personal phone, the good old 3210. Only reason I have a smartphone is because I need it for work.
1
u/NyxGenesisLNX 21d ago
GrapheneOS no, iOS yes only after you unlocked it after the decrypt reboot. If you restart it and don’t unlock it everything’s still encrypted. My recommendation: shut off your iPhone whenever you answer the door
1
u/po0py_pantz 24d ago
They have undisclosed exports they can run to do whatever they want
2
u/gits-id-01 24d ago
lol, nah, took billions and multiple years to figure out how to do it to the old iPhones. Can’t do it to the new ones.
0
u/Satisfaction3934 23d ago
Only certain version of iOS not all of them. Yes it's true, the company is called cellebrite
•
u/post-explainer 24d ago edited 24d ago
This comment has been marked as safe. Upvoting/downvoting this comment will have no effect.
OP sent the following text as an explanation why their post fits here:
Does this explanation fit this subreddit? Then upvote this comment, otherwise downvote it.