TechCrunch News 2024年11月15日
New Apple security feature reboots iPhones after 3 days, researchers confirm
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

苹果iOS 18系统引入了一项名为“非活动重启”的新安全功能,若iPhone在72小时内未解锁,则会自动重启。此功能旨在增强iPhone安全性,即使设备被盗,也难以通过旧版取证工具解锁并提取数据。这项功能将iPhone置于更安全的状态,将用户的加密密钥锁定在安全隔区芯片中,有效防止数据泄露。虽然此功能给执法部门提取数据带来挑战,但专业人员仍可在协调行动下获取数据。此外,文章还介绍了iPhone的两种状态“首次解锁前”和“首次解锁后”,以及相关安全机制。

🍎 **iOS 18新增“非活动重启”功能:**如果iPhone在72小时内未被解锁,系统会自动重启,旨在提升设备安全性,防止数据泄露。

🔒 **增强iPhone安全状态:**重启后,用户的加密密钥被锁定在安全隔区芯片中,即使长时间被盗也难以被旧版取证工具破解。

🕵️ **对执法部门造成挑战:**该功能增加了执法部门获取犯罪嫌疑人设备数据的难度,但专业人员仍可在协调行动下获取数据。

🔄 **iPhone两种状态:**“首次解锁前”(BFU)和“首次解锁后”(AFU),前者数据加密程度高,后者部分数据未加密,更容易被提取。

🛡️ **苹果持续增强安全:**多年来,苹果不断加强iOS系统安全,曾引发执法部门反对,但苹果坚持保护用户隐私。

Apple’s new iPhone software comes with a novel security feature that reboots the phone if it’s not unlocked for 72 hours, according to security researchers.

Last week, 404 Media reported that law enforcement officers and forensic experts were concerned that some iPhones were rebooting themselves under mysterious circumstances, which made it harder for them to get access to the devices and extract data. Citing security researchers, 404 Media later reported that iOS 18 had a new “inactivity reboot” feature that forced the devices to restart. 

Now we know exactly how long it takes for this feature to kick in.

On Wednesday, Jiska Classen, a researcher at the Hasso Plattner Institute and one of the first security experts to spot this new feature, published a video demonstrating the “inactivity reboot” feature. The video shows that an iPhone left alone without being unlocked reboots itself after 72 hours.

Magnet Forensics, a company that provides digital forensic products including the iPhone and Android data extraction tool Graykey, also confirmed that the timer for the feature is 72 hours.  

“Inactivity reboot” effectively puts iPhones in a more secure state by locking the user’s encryption keys in the iPhone’s secure enclave chip. 

“Even if thieves leave your iPhone powered on for a long time, they won’t be able to unlock it with cheaper, outdated forensic tooling,” Classen wrote on X. “While inactivity reboot makes it more challenging for law enforcement to get data from devices of criminals, this won’t lock them out completely. Three days is still plenty of time when coordinating steps with professional analysts.”

Do you work for a mobile forensics company or law enforcement? We’d love to hear from you. From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

iPhones have two different states that can affect the ability of law enforcement, forensic experts, or hackers, to unlock them by brute-forcing the user’s passcode, or extracting data by exploiting security flaws in the iPhone software. These two states are “Before First Unlock,” or BFU, and “After First Unlock,” or AFU.

When the iPhone is in BFU state, the user’s data on their iPhone is fully encrypted and near-impossible to access, unless the person trying to get in knows the user’s passcode. In AFU state, on the other hand, certain data is unencrypted and may be easier to extract by some device forensic tools — even if the phone is locked. 

An iPhone security researcher who goes by Tihmstar told TechCrunch that the iPhones in those two states are also referred to as “hot” or “cold” devices. 

Tihmstar said that many forensic companies focus on “hot” devices in an AFU state, because at some point the user entered their correct passcode, which is stored in the memory of the iPhone’s secure enclave. By contrast, “cold” devices are far more difficult to compromise because its memory cannot be easily extracted once the phone restarts.

For years, Apple has added new security features that law enforcement have opposed and spoken out against, arguing that they are making their job harder. In 2016, the FBI took Apple to court in an effort to force the company to build a backdoor to unlock the iPhone of a mass-shooter. Eventually, the Australian startup Azimuth Security helped the FBI hack into the phone. 

Apple did not respond to a request for comment. 

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

iOS 18 iPhone安全 非活动重启 数据安全 执法
相关文章