Cops Can Bypass iPhone's Automatic Reboot to Get into Locked Phones
- ID
- 30986
- Status
- summarized
- Published
- 01 Oct 2026, 10:38 PM
- Fetched
- 02 Oct 2026, 6:51 AM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://www.404media.co/cops-can-bypass-iphone-automatic-inactivity-reboot-graykey/
- Source URL
- https://hnrss.org/best
Summary
- Score
- 4.0
- Created
- 02 Oct 2026, 6:52 AM
- Tags
- Audience
- developers
What happened
404 Media reports that Magnet Forensics, the company behind the GrayKey iPhone unlocking tool sold to law enforcement, claims in a leaked promotional video to have defeated Apple's iOS 'inactivity reboot' — the feature Apple quietly added around November 2024 that reboots an iPhone after 72 hours without an unlock. The claimed workaround is a new device called GrayKey Preserve plus an 'Evidence Preservation Mode' feature for existing GrayKey units, which reportedly freezes iPhones in a state that keeps them accessible to forensic extraction. The claims come from a vendor marketing video obtained by 404 Media, not independent technical verification, and the article itself sits behind a paid membership wall.
Why it matters
For most builders this changes nothing you can act on: it is a vendor claim in a leaked promo video about a physical-access forensic tool, not a CVE, an API change, or a remote attack. The one decision worth making is whether any part of your threat model rests on 'the phone is locked, therefore the data is out of reach' — if your team issues iPhones to field staff, handles seized-device evidence, or writes privacy copy implying locked devices are safe, that assumption is now explicitly contested by the vendor's own marketing. If you store user secrets only in app-sandbox storage on iOS, this is not a reason to re-architect; the text gives no mechanism, no iOS version, no device list, and no independent test result.
Discussion angle
Apple's 72-hour inactivity reboot was a deliberate anti-forensics feature, and a commercial vendor is now advertising a bypass to police buyers. Ask the room: should defenders treat 'seized device' as part of their threat model at all, and does it matter that this is a vendor claim in a leaked video rather than a reproducible technical write-up?