5 ms·
> So you should be safe, apart from some kind of rubber-hose cryptanalysis. There are vendors that sell the technology to adversarially access phone data, the
by overfeed 26d ago
> So you should be safe, apart from some kind of rubber-hose cryptanalysis.
There are vendors that sell the technology to adversarially access phone data, the "Before First Unlock" is the safest state a phone can be, but it's not infallible. The safest option is to have a burner or factory-reset phone with nothing on it, even if the hack succeeds.
- ratelimitsteve 26d agoI've worked with Cellebrite, the industry standard in IT forensics for unlocking and imaging phones. It just runs a series of known exploits. PIN lock, data encryption and regular updates will beat it most of the time.
- armadyl 26d ago> I've worked with Cellebrite Any chance you want to do a public service and publish the latest compatibility matrix? Just joking, obviously…
- trollbridge 25d agoWhen I interact with the general public, I get a nice reminder that most people don't do a decent PIN lock, don't have encryption on unless it's the default for that platform, and don't do regular updates. Lots of reasons why (phone is out of space to do an update; not signed in properly to Apple / Google account; kids use their phone so they want an easy to remember PIN on it, etc. etc.)
- wat10000 26d agoBefore First Unlock with recent hardware and an up to date OS is probably sufficiently infallible for an average person. I wouldn't want to rely on it if I was engaged in espionage, but for someone who won't get the NSA pulled into the case, I'd be pretty confident. This leaked Cellebrite support matrix shows that BFU was secure against them for iPhones that were nearly four years old at the time, and I doubt it's become significantly worse since then: https://ia800405.us.archive.org/32/items/inseyets-offline-ufed-version-10.2-user-manual/iOS%2BSupport%2BMatrix%2B7.69.1.pdf https://ia800405.us.archive.org/32/items/inseyets-offline-uf...