4 ms·
They don't need your pin, they can just hack the phone take all your data anyway. ICE has a contract with Cellebrite
by autoexec 8d ago
They don't need your pin, they can just hack the phone take all your data anyway. ICE has a contract with Cellebrite
- puppycodes 8d agoNot really. Cellebrite isn't magic. If you have an up to date OS and a strong password not pin, encryption functions as it should. The best thing to do is simply have a travel phone.
- autoexec 8d agoIt's not magic, but that doesn't mean it doesn't work most of the time. From https://cellebrite.com/en/blog/the-access-gap-is-closed-what-cellebrite-can-unlock-in-2026/ https://cellebrite.com/en/blog/the-access-gap-is-closed-what... : Here’s what that looks like in practice in 2026: iOS: Cellebrite supports access to the latest iPhone models and iOS versions, including both after-first-unlock (AFU) and before-first-unlock (BFU) states. Recent updates have introduced new AFU access methods for previously unsupported iOS device configurations, expanding the range of devices that can be accessed without requiring a prior unlock event. Android: The latest releases restored and expanded full file system (FFS) extraction across a broad range of newer Android models, which is an area where the competitive landscape had seen fluctuation. Coverage now spans Samsung, Google Pixel and other major Android manufacturers at their current OS versions.
- puppycodes 5d ago"Access" is not what you think it means. This is marketing hype directly from their site. I have first hand experience using their extractors and its not as robust as they make it sound. They extract metadata outside of the encrypted volumes. It all depends on what your worried about. Actual hardware 0-days are highly coveted, extremely expensive, military classified tools that TSA does not have access too and never will. Edit: CBP not TSA (thanks good callout)
- righthand 5d agoMinor nitpick this wouldnt be TSA but CBP; both are anti-American organizations under DHS.
- iAMkenough 7d agoImaged encrypted volumes can be decrypted later. We're building massive amounts of compute with government bonds these days.
- puppycodes 5d agoThis is true for literally everything encrypted. Security is always a function of time and effort. The name of the game is being not worth the effort.
- iAMkenough 5d agoWhen the effort becomes trivial, so does the justification for it. Doesn’t cost them any of their own money.
- puppycodes 5d agoOnce again its not as simple as oh its easy now. It's highly dependent on how much time has passed, who you are, what your worried about... etc... making it out like everyone is on the same plane makes the threat assessment worthless.
- matheusmoreira 7d agoRight now it seems GrapheneOS is the only OS capable of resisting Cellebrite.
- puppycodes 5d agoThats not at all accurate. When you say "resisting" you are glossing over really important distinctions. The lastest versions of iOS are perfectly capable of being locked down in a such a way that they are not able to be penetrated by Cellebrite. The info extracted is the nuance your missing here. Cellebrite doesnt break encryption, it brute forces weak PINs and passwords and collects metadata thats outside of the protected volume. Your online activity likely exposes much much more about you than the data extracted by Cellebrite. These distinctions matter as its really easy to misunderstand and sensitionalize their tools.