4 ms·
They plug the phone into a computer and use software to literally clone it, so everything on the phone. All logs, emails, messages, photos, contacts, deleted fi
by meeb 7mo ago
They plug the phone into a computer and use software to literally clone it, so everything on the phone. All logs, emails, messages, photos, contacts, deleted files if they’re recoverable, passwords, everything.
- CalRobert 7mo agoWould an iphone in lockdown mode have any resistance to this?
- heavyset_go 7mo agoI don't think we have access to all of the functionality of the devices, and all of the devices themselves, that are sold to governments.
- nerdsniper 7mo agoThe latest iPhone model in lockdown mode would be super resistant. Lockdown mode is specifically engineered to protect against Cellebrite / Pegasus-level threats. However, if you’re a noncitizen you might be refused entry, and if you are a citizen you might never see that phone again. The phone will be stored for years until/if Cellebrite finds a vulnerability in that iPhone model, and then it will be searched. Also the government might target your future phones for Pegasus-style remote attacks, so if you present your phone to CBP in lockdown mode, you may want to leave lockdown mode enabled forever. Modern iPhones are very, very hard (impossible) to crack today if they’re locked down properly: strong password, biometrics disabled, and/or lockdown mode.
- srean 7mo agoVery interesting. Are there any technical hindrances that prevent Android being the same ?
- Mkengin 7mo agoI don't think so, I use GrapheneOS and I think I can't even use the USB-C port for anything other than charging (which should be configurable).
- sebastiennight 7mo agoIt is configurable. It can be used to charge (either way), for data transfer, or for remote control. You can set it up with a fixed behavior, or to request permission everytime you plug a data cable.
- nerdsniper 7mo agoSlightly out of my depth, hopefully others weigh in. Getting a very good lockdown mode requires both owning the entire stack (Apps + OS + Silicon) and being willing to sacrifice repairability (swapping chips/cameras/displays/touch controllers is a good way to help hack into a phone), and willingness to spend a lot of money on something that few people would actually pay for. Apple is the only company that's even positioned to take on this challenge. AndroidOS has to work with a bunch of core functionality chips that Google/Samsung don't make. Having a bunch of different code paths/interfaces for a bunch of different SoC's, cellular modems, touch controllers, and cameras is not a winning recipe for security. Both Google and Samsung also use their own SoC's (Google Tensor G5, Samsung Exynos) but Samsung also uses a lot of Qualcomm Snapdragons ... and if you're using someone else's SoC there's no chance in hell of coming up with a proper "Lockdown Mode". Samsung or Google might be able to come up with a fully integrated solution someday, each have invested in parts of this. Beyond SOC's, Samsung has their custom silicon which helps them lock down security for their combo touch/display controller. Samsung has also invested a lot into customizing their Knox Secure Folder solutions (and everything else branded "Knox" as well, which is all mostly industry-leading for Android options). Google has the Pixel with their own Titan M2 security chip, and obviously they own the OS. But it's a lot of work when so much of your engineering is dealing with changes that other companies are making. Google has to keep up with Samsung's hardware changes, because the tail wags the dog there, and Samsung spends a lot of engineering time figuring out how to deal with / customize / fork changes to AndroidOS that Google pushes (while the dog still wags the tail, too). Both have to deal with whatever Qualcomm throws at them for cellular modems, and it required a monumental effort/expense from Apple to only just recently bring up a replacement for Qualcomm's modems.
- srean 7mo agoThanks for replying. Such a comprehensive and well thought comment ought to have been a top standalone comment.
- gzread 7mo agoYes, all Android phones except for GrapheneOS are vulnerable to something, so they'll just copy the flash storage and hand it back to you.
- mikeyouse 7mo agoYes it’s resistant but then they can just deny your entry into the country.
- CalRobert 7mo agoPresumably not if you’re a citizen but then, who knows
- mikeyouse 7mo agoRight this was in the context of Canadians visiting - they can’t deny entry if you’re a US citizen but they can certainly make the entry uncomfortable.
- Lio 7mo agoYou wish, they might just put you in a detension centre for a few weeks and take their own sweet time sending you back. You are in legal limbo before you enter the country.