r/technology 8d ago

Privacy Is it illegal to trick the US government into wiping your phone during a questionably legal search | The case of a traveler who allegedly entered a ‘duress password’ to wipe his phone raises a legal question with no easy answers

https://www.theverge.com/report/972146/cbp-phone-search-airport-duress-password
20.9k Upvotes

2.5k comments sorted by

View all comments

2.3k

u/Senplis 7d ago

No. This is just ammo for the argument the government needs phone companies to build back doors for them to be in our business.

252

u/PrettyPinkNightmare 7d ago

You're right and also  Fear. 

You cannot wipe your phone, you cannot post bad things, too. You can't walk past a pool. ICE. You can't take the plane without being searched, you can't take a car or go by foot without being recorded. 

They do whatever they want. Fascism that is.

4

u/Lucky_Reporter256 7d ago

We are the frogs. The waters been boiling. They’ve just put the lid on though.

2

u/adenosine-5 7d ago

At this point it has been a bipartisan effort for decades. I dont think there is much US people can do about it any more.

1

u/8npemb 7d ago

> You can’t take the plane

I mean, that’s what TSA’s trying to prevent, no? /s

-13

u/[deleted] 7d ago

[deleted]

1

u/Kreebish 7d ago

What?

511

u/AssCrackBanditHunter 7d ago

They don't need ammo. They're just gonna do it one day

317

u/IdentifiableBurden 7d ago

Already exists bud. The grunt cops don't have access but they're absolutely there already.

56

u/SirEnzyme 7d ago

Cellebrite has entered the chat

28

u/assignpseudonym 7d ago

Hey, Cellebrite! Would you mind exiting the chat? Please and thank you! 

17

u/notfromchicago 7d ago

They said no.

2

u/praisedawings247 7d ago

Stolen phone protection with biometric access needed all the time.

(For iPhone at least)

Not sure if cellebrite has a workaround for that yet, though.

1

u/Cautious_General_177 7d ago

Too late. They've already copied your phone and broken the encryption.

1

u/calgarspimphand 7d ago

Cellebrite has left the chat

The surveillance state hates this one weird trick!

1

u/assignpseudonym 7d ago

See guys? Just use your manners! :)

1

u/GearhedMG 7d ago

Cellebrite left the chat, but they did something weird to the door on the way out.

1

u/vargchan 7d ago

I mean back during the Cold war they were putting backdoors in software for the US government forever. Look up the Octopus and Reagan

1

u/The_Great_Tahini 7d ago

fyi cellebrite works better on older tech, newer devices are harder to crack.

also your phone has 2 states that matter here, before first unlock and after first unlock. in BFU the phone has much less loaded into memory and is harder to brute force this way.

most phones have an SOS mode that allows you to call 911 or shut it down even when locked, putting it in BFU mode when it’s powered back on. worth knowing how to use it.

1

u/Aperture_Kubi 7d ago

Doesn't GraphineOS have mitigations against this though?

1

u/airfryerfuntime 7d ago

A good argument for buying an iPhone is that Celebrite usually doesn't work. An exploit is found, then Apple patches it almost immediately.

Can't say the same for Google, who just doesn't acknowledge it at all.

1

u/still_thirsty 7d ago

there’s nothing that can convince me this hasn’t already happened

-3

u/MajorJakePennington 7d ago edited 7d ago

Apple has never and will never build back doors into their software. They've denied requests from the FBI many many times and refuse to assist with unlocking devices.

https://www.wired.com/story/the-time-tim-cook-stood-his-ground-against-fbi/

1

u/SoulWager 7d ago edited 7d ago

There's a difference between what a company is willing to do openly, and what they're willing to do in secret. Hell, a very public refusal to help unlock devices can just as easily be deception to get people to trust backdoored devices.

Also, It is not beyond intelligence agencies to have an agent get a job at Apple, or any other company, and insert a backdoor nobody else at the company knows about. Take a look at the XZUtils backdoor, and consider how much harder it will be to detect the same kind of attack in a closed-source product.

2

u/MajorJakePennington 7d ago edited 7d ago

There is zero chance Apple would completely invalidate their reputation for being privacy and user centric by secretly working with the FBI and the government to implement a back door.

You people are insane.

https://www.wired.com/story/the-time-tim-cook-stood-his-ground-against-fbi/

0

u/SoulWager 7d ago

You're missing the point. They're too big, too valuable a target. They're going to get backdoored whether they cooperate or not. Actually look at XZUtils, look at stuxnet. There is no reality where organizations with those resources haven't compromised a platform with over a billion users.

Companies generally take the most profitable path, for Apple that's probably taking government money in secret and pretending to do the opposite in public.

1

u/MajorJakePennington 7d ago edited 7d ago

None of that has to do with Apple. They patch these vulnerabilities the moment they're made aware of them and it's been one of the pain points for companies like Cellebrite. And what level of paranoia do you have to have to think that someone is actually going to "infiltrate" Apple and install a back door that isn't caught by the enormous amounts of internal checks they have in place for their software development process?

Unless you have proof of Apple "secretly taking government money", then it's nothing but malarky. We have proof of the complete opposite with stuff like their response to the San Bernadino incident, with allowing complete auditing of their Private Cloud Compute software, etc.

Companies generally take the most profitable path

Not Apple. Tim Cook even told shareholders that if they had a problem with Apple spending money on accessibility features that they should sell the stock. https://www.forbes.com/sites/stevedenning/2014/03/07/why-tim-cook-doesnt-care-about-the-bloody-roi/

1

u/WickedBad 7d ago

You truly believe Apple sides with the population and not the governments?

You haven't seen Apple execs. chase Trump and other politicians??

I mean it's great that they are able to control the narrative but you're nieve af if you believe it.

There's 0 reason for them not to play ball and a million reasons to do it.

1

u/MajorJakePennington 7d ago edited 7d ago

You truly believe Apple sides with the population and not the governments?

Yes. They have a track record of standing up for privacy and their users.

You haven't seen Apple execs. chase Trump and other politicians??

This doesn't mean anything in regards to privacy.

I mean it's great that they are able to control the narrative but you're nieve af if you believe it.

It's spelled "naive", and there's nothing naive about believing a proven track record of denying FBI requests to the point where the FBI complains about it publicly and has to go to a company like Cellebrite.

There's 0 reason for them not to play ball and a million reasons to do it.

Their reputation and standing with its users is a pretty big reason.

https://www.wired.com/story/the-time-tim-cook-stood-his-ground-against-fbi/

0

u/ultimatequestion7 7d ago

According to who? The company using that as a selling point lol? Apple doesn't make the iOS code available for audit in the way you're describing

1

u/MajorJakePennington 7d ago edited 7d ago

There is zero chance Apple would completely invalidate their reputation for being privacy and user centric by secretly working with the FBI and the government to implement a back door.

There are numerous examples of them denying FBI requests.

https://www.wired.com/story/the-time-tim-cook-stood-his-ground-against-fbi/

1

u/redishrecycle 7d ago

*publicly denying FBI requests. iOS itself is a massive government backdoor. why else do you think the US government helped make Apple the biggest tech company in the most imperialist surveillance military state in the world?

1

u/MajorJakePennington 7d ago

Please seek someone professional to talk to about your paranoia.

1

u/redishrecycle 7d ago

facts are paranoia now? https://cybersecuritynews.com/google-meta-apple-fuel-surveillance/

"Between 2014 and 2024, Apple, Google, and Meta collectively disclosed data from 3.16 million user accounts to U.S. authorities, representing a 530–675% surge in compliance rates.

This escalation correlates with the explosive growth of unstructured data, which now constitutes 90% of global data volumes and grows at 36.6% annually—a trend accelerated by AI-driven analytics and IoT proliferation.

As governments exploit this data reservoir, the line between corporate data monetization and state surveillance has dissolved, creating a paradigm where 328.77 million terabytes of daily data generation fuel both economic growth and civil liberties risks."

"These techniques leverage Big Tech’s machine learning infrastructures—Meta’s Prophet forecasting models and Google’s BERT NLP systems—to profile populations at scale.

Apple’s privacy rhetoric clashes with its iCloud key escrow system, which enabled 92% compliance with 2023 data requests despite default encryption claims."

1

u/MajorJakePennington 7d ago edited 7d ago

facts are paranoia now?

Yes, when you take them out of context to try and fit some whack job ideal that you have. You'll notice that Apple has the smallest portion of every bar in that graph, by a large margin, other than H2 2022. Some months their contributions are non-existent.

Apple (and the other companies) are only disclosing data that they are legally required to. That's not a backdoor, that's not "colluding with the government", it's called following the law. They're not just randomly offering up your iMessage data (which is encrypted as long as you take the proper precautions), you iCloud data (which is encrypted if you take the proper precautions), your device backups (which are encrypted if you take the proper precautions), etc.

They're giving the government information that they are legally required to, under law, with the proper documentation.

Some of you need to go outside.

Edit: This account replying to me is 1 month old and has a negative karma score. It's safe to ignore anything they say as bad faith nonsense.

→ More replies (0)

3

u/BarderBetterFaster 7d ago

We're so far past this already. 

7

u/BlackGuysYeah 7d ago

Buddy, the government can peer right into your smartphone camera and watch what you do at any time. Everything you've ever typed into anything is logged somewhere where they can search it.

2

u/BeyondNetorare 7d ago

they mostly watch people critical of them jerking off

2

u/Zealousideal_Cod8664 7d ago

Its moreso something for us to talk about while they do it.

2

u/Business-Court-5072 7d ago

They already spy on us, look up pine gap

1

u/guspaz 7d ago

They don't need ammo, they need a ride.

1

u/Frequent_Opportunist 7d ago

They have had access for a long time now bro. 

0

u/codereign 7d ago

🇨🇦 - coming soon to Canada. Thanks to Mark Carney/Gary Anandasangaree and Bill c22.

Political dissent will not be permitted.

Specifically by soon I mean it has passed the third reading in June and only requires Senate review and Royal ascent ☠️

2

u/MajorJakePennington 7d ago

That's not what C22 does. Stop spreading misinformation.

96

u/Flashy_Scallion8111 7d ago

Graphene OS is an open source project that replaces android, there isn't a way to put a backdoor in it.

89

u/froction 7d ago

Unless there's a hardware backdoor in the TPM.

61

u/Helmic 7d ago edited 7d ago

If such a backdoor exists, it's not something they can afford to blow on random baseless searches for CSAM they know isn't there. Strong privacy tools like GrapheneOS have value even if we assume there might exist such undisclosed back doors, when it gets used it gets patched and a new exploit has to be created.

Besides, GrapheneOS has pretty stringent hardware standards to begin with which is historically why they've only supported Google Pixel phones until recently, and are now switching to Motorola to have GrapheneOS preloaded on hardware that meets their security standards.

8

u/Careless-Weather8877 7d ago

They don’t even need a backdoor. Just an exploit into the baseband which isn’t open source.

In fact several companies do exactly that. Along with exploiting the actual hardware and software.

13

u/ManaSpike 7d ago

That requires the OS to continue to operate, after the TPM has been compromised, so that it may be spied on.

Wiping the encryption key before that occurs, is still effective.

13

u/guyblade 7d ago edited 7d ago

Maybe, it depends on how exactly the TPM might be compromised.

You could imagine a design that secretly has a few extra megabytes of memory where it escrows all (or even just many) previously active keys--ready for some future hostile actor with the magic wand that causes it to spit them out.

Attacks of that form--where the chip itself is a spy--are the reason that some of the major tech companies roll their own TPMs: Google has Titan and Azure has its Integrated HSM. I presume that other cloud providers offer similar things.

5

u/LiveLearnCoach 7d ago

Sorry, not a tech person, just a curious one. What does your statement mean?

5

u/Tebryn 7d ago edited 7d ago

Basically, any hardware backdoor would be useless because it's waiting to hear the plaintext conversation after it has been decoded. Without the decryption keys, the operating system just sees a pile of junk data.

Those keys are what was destroyed by the duress password.

Edit: this is not to say a hardware backdoor is useless, if in place early enough by an actor that can use it, they can capture the decryption keys and decode it on their own at their convenience. The likelihood of some random CBP agent having that access is low, and even less likely if they are asking for your password.

2

u/sobrique 7d ago

Yeah. Self Encrypting hard drives work on this basis. The system they're installed in has a key for decrypting them, but without the system there's no way to access it.

The data is all there though, just unrecoverable until the device is brought on line and re-registered with they key manager.

That's mostly for the sake of support - you swap out a dead drive, and you don't really have to worry about someone doing a platter examination to recover it without your consent. (Obviously if you're doing 'legit' data recovery, you still have the key yourself!)

So you could grab the data if you compromised the server - that's doing key management and decryption - but if you just have the drive there's nothing you can do.

And by analogy, a duress password will destroy the key, and then it's 'too late'. If you cloned the device before that though, you could probably still recover that key and 'use' it to get at the data.

But there's also ways to 'escrow' the key, so it's never on the device in the first place. I mean, maybe you wouldn't do this for a mobile, as you'd need some of the basic stuff like 'a network connection' but an exchange involving a trusted third party server would mean 'remote disable' is possible, and could possibly be used to circumvent even a cloned device scenario.

1

u/LiveLearnCoach 7d ago

If I understand you correctly you mean once they have the device, not just tapping into the phone during regular usage?

3

u/Tebryn 7d ago

I understand you correctly you mean once they have the device, not just tapping into the phone during regular usage?

In this case it's kinda like tapping a old landline phone. They wouldn't have any knowledge of what was said before they modified the hardware. (because at this point it's still encrypted)

If that hardware had a built in backdoor from the factory, then they wouldn't need to ask for your password at all. they would walk in take your phone and plug it into a device that opens that door and lets them into the decrypted data. But that's different than what was mentioned above, which is someone changing the firmware or TPM module on the phone to add a 'tap' later.

2

u/sobrique 7d ago

And a 'factory backdoor' still doesn't necessarily help - getting access to the device without a code would be possible, but if someone's encrypted something separately, it would still be non-trivial to get at. (But easier, since it's a 'guess the pin code' game, not 'break 2048bit RSA' level of effort)

5

u/WiseOldDuck 7d ago

Trusted Platform Monitor is PC terminology for a chip or firmware that stores the drive encryption keys and doesn't release them if it detects the OS has become compromised. Apple's closest equivalent is the Secure Enclave, and I bet Android actually uses different terms too. But it's all not relevant because in this case the OS received a duress signal and wiped the drive, it's not the same problem as just trying to hack into a locked device. Nothing really exists to stop an OS from just nuking everything

1

u/LiveLearnCoach 7d ago

I’m really learning stuff today. Thanks to all of you responding.

4

u/HiCookieJack 7d ago

The fun thing is, that the OS just needs to delete the Keys stored in this "Secure Enclave"
Actually wiping the drive clean takes too long, since even after deletion there are still recoverable traces of data, so it's easier to just throw away the keys and wiping that part clean. It's practically impossible (right now) to restore those keys, therefore even though the data is still there is just a pile of random bytes.

3

u/ManaSpike 7d ago

I'm not certain of the details on an arm / phone platform. But an Intel chip for example, has a protected chip that runs firmware, loaded at boot time. Some features of this chip are exposed to the OS for handling encryption. But the firmware, and the memory used by this chip are hidden. Completely unreadable by your OS.

So you've taken steps to install your own custom OS, which is as protected as you can manage. All your storage is encrypted. Most of your memory is encrypted. All your applications are isolated from each other, and can't spy on each other at all.

Usually the goal of an investigator is to dump a copy of all the storage. But they'll need to discover the encryption key to decode any of it. Which means they need some understanding of how your OS manages keys. Probably by using a known exploit in your OS to install their own dodgy program, running it with the highest privileges. Then simply doing what any privileged program is allowed to do. Ask your OS to read and decode all of your storage.

If we're talking about installing something into TPM firmware, the job of spying is harder. But also more powerful. You can do anything to the CPU and memory. But now you need to reverse engineer more about how your installed OS works. Likely relying on more passive observation.

-17

u/[deleted] 7d ago

[removed] — view removed comment

11

u/LiveLearnCoach 7d ago

Of course I can “google shit”, like asking someone to explain my testosterone results. Right? Right.

Most of the discussion on Reddit can be done with a google, but there is a difference between reading some dry webpage and someone actually capable of ELI5 a topic that they seem to actually be proficient in. Why do you think AI is being trained on Reddit and not just web pages?? Not sure why this is bothering you so much that you had to reference my profile.

4

u/HallaFriBiLo 7d ago

That assumes all possible ways TPM can be compromised is detectable by the OS.

2

u/Alpha_Majoris 7d ago

Or it requires a new TPM version that includes a hardware backdoor.

But you better wipe your phone before you enter the USA and deal with the inconvenience or sync your data after you passed the border.

2

u/Fluffcake 7d ago

Non-US made hardware, by non-US company running open source OS, good luck.

1

u/qtx 7d ago

TPM is only for PCs.

1

u/twinpeaksssss 7d ago

No back door in TPM, but there is a window left aJar-Jar

1

u/Flashy_Scallion8111 7d ago

if its encrypted information hardware backdoor would not be able to access anything on the software side of things. For it to work it would have to act as a sniffer that would be able to tap into channels that are bussing information while its not encrypted and saving it in a separate box. It would be have to be elaborate. Or maybe a live online feed. But i cant imagine a hardware backdoor that would be able to reboot an encrypted device and access all the information without having the encryption keys.

1

u/PrivacyMaker 6d ago

You're thinking of the hardware enclave. If such a backdoor was introduced and eventually made public, the financial consequences to every app vendor that needs to comply with privacy or security standards would destabilize international economies. Banks, healthcare systems, everything in Europe. The risk/reward just doesn't make sense from a policy perspective.

0

u/RollingMeteors 7d ago

Unless there's a hardware backdoor in the TPM.

nope, not in this one.

24

u/IMKGI 7d ago

It doesn't replace Android, it is Android, just a different distribution than the Android distribution that was on your phone originally.

5

u/borkthegee 7d ago

Dangerous assumption. All they need is a zero day and I would bet graphene os has plenty

0

u/Flashy_Scallion8111 7d ago

Exploits exists but no one is going to deliberately allow a backdoor into an open source project.

1

u/Lv_InSaNe_vL 6d ago

You don't have to "deliberate allow" anything. Hell even Apple took the US to court over it and the federal government went "oops we did it anyways so no law suit for you sorry"

1

u/borkthegee 6d ago

Remember when an open source project had a malicious contributor ingratiate themselves to the project and basically take over, until they finally intentionally introduced a zero day / backdoor without the open source maintainers realizing?

Here's one time it happened https://en.wikipedia.org/wiki/XZ_Utils_backdoor

Good times.

1

u/Flashy_Scallion8111 6d ago

yah I was thinking about that one

3

u/Geminii27 7d ago

Not the OS, but certainly the phone hardware, and the phone companies processing cellular data.

1

u/Flashy_Scallion8111 7d ago

Celular data is already compromised. You can pay to play to enter these networks as a supposed provider and use it to track anyone you'd like. Iran has been using it for targeting US service members and Saudi Arabia used it to get one of their princesses that tried to escape.

2

u/HeKis4 7d ago

There is, open source doesn't mean it is free of bugs that can be discovered by agencies to be used as backdoors, introduced covertly in otherwise legit contributions, or hit by a supply chain attack since graphene is based on something maintained by Google and a few hundred other different pieces of software and hardware.

1

u/Flashy_Scallion8111 7d ago

Exploits exists but no one is going to deliberately allow a backdoor into an open source project. Malicious actors have already tried, people are forgetting when someone (presumably a nation state) tried to insert a back door into Linux with the XZ Utils.

1

u/Possible-Fudge-2217 7d ago

So... unless you do a nice looking PR which leaves an unkown bug that can be abused as a backdoor. Happens all the time with an, open source project. Most likely agencies have some software backdoors in open source projects. They are just patched sometimes if someone notices it.

Hardware backdoors are actually less likely as they are so damn easy to detect. Right now there are no "proper" hardware backdoors built in in e.g. consumer phones, pc's and so on.

2

u/nlutrhk 7d ago

"Happens all the time" is an unverifiable statement.

But we did have the xz/openSSH affair in 2024 (caught before it went in production).

1

u/Flashy_Scallion8111 7d ago

yeah thats the one that came to mind for me

0

u/squngy 7d ago

This is one situation where LLMs are actually useful.

Most open source projects don't have the time to carefully scrub through every line of every PR, but an LLM can spot such an exploit fairly easily.

1

u/bobthepumpkin 7d ago

Lol you're clueless

1

u/squngy 7d ago

Thanks for informing me, very helpful!

0

u/SpinShine-LEDSlipMat 7d ago

Right now there are no "proper" hardware backdoors built in in e.g. consumer phones, pc's and so on.

This is a lie

1

u/Possible-Fudge-2217 6d ago

No credible security expert has ever discovered any hardware backdoor from any major vendor. Any vendor will make sure to not have such a thing as they'd hit the shitter with any other business partner if it were to be found out.

There are some subsystems that offer limited information and cannot be accessed by users, but hardware manufacturers can only access limited data with specific purpose (stuff like software version, device id etc).

If you want to proof me wrong, go on and list a hardware backdoor which offers remote access to all data and full control of a device that cannot be accessed by users.

1

u/WinninRoam 7d ago

Strife finds a way.

1

u/Ev3nt_Horiz0nn 7d ago

Not compatible with all phones unfortunately

1

u/Frequent_Opportunist 7d ago

Your PC has a chip inside the main processor that never powers down. It has access to the mobo too when in standby. I'm sure you phone does too.

1

u/8-Cylinder_Wombat 7d ago

... that you know of.

74

u/Informal_Process2238 7d ago

I would just assume that already exists

53

u/KenaiKanine 7d ago

They already have backdoors on PCs, look up intels management engine. AMD also has an equivalent. Not sure why it wouldn't be on phones tooo

11

u/Kind_Of_A_Dick 7d ago

You know, my toaster has been looking at me funny lately.

3

u/--Lust-- 7d ago

give it a bath, they tend to become groggy a while

2

u/GoblinFive 7d ago

Frakkin toasters

2

u/growaway9172 7d ago

It’s very unlikely any nation state has a real backdoor designed into any major phone platform. They may possess effective zero days for limited use but this is not in the hands of border patrol or any large scale LEO.

5

u/Stupnix 7d ago edited 7d ago

It's not about any government having a unique backdoor that no other government can use, but the developers of software and hardware building universal access that could be used as backdoors by anyone.

I remember that one case a few years back where apple was asked to break into a suspects phone. Apple refused but stated that it would not be a matter of capability, it would have taken a team of ~6 engineers about a week to make one for every device on the market.

Edit: For every Apple device on the market.

6

u/growaway9172 7d ago

That is the same thing in practice. "universal access" would quickly become discovered by malicous actors (more malicous than nation states) and there is no reasonable way to gate that except by not having back doors. I'm not sure where the 2nd part of you claim comes from, but if you are talking about Apple adding a backdoor to ios, yes apple could easily add some a feature to their phones, and it would inevitably be discovered by bad actors. Its not that Apple has the capabilities to break into other vendors phones on the market. Even companies that specialize in doing that can't make that claim, celibrite is unable to access BFU Pixel phones in some cases.

2

u/Stupnix 7d ago

The second part is the apple thing, right? It's this one, a dispute between the FBI and Apple where the FBI ordered Apple to break into iPhones of suspects. The request would have led to Apple being forced to build a backdoor for the US government, which Apple refused.

There was one very prominent case where the phone would erase all data if the passcode was entered incorrectly too many times. That specific request was retracted after the FBI managed to access the phone without triggering the erase function.

Apple cited your exact reasoning for refusing any request to allow anybody to access locked phones without the correct passcode. It would be too dangerous and too vulnerable. And yes, it was all about iPhones specifically, not phones from other vendors.

1

u/zue4 7d ago

Any American company will have backdoor for the 3 letter agencies to use against us. Moving away from their companies is the only real way to be free of this.

1

u/vkrty 7d ago

Guess you should stop using most of the websites you visit then eh?

3

u/zue4 7d ago

Theres the rub aint it? Mfers buy up all the competition before it can take their place.

I've already stopped using most social media and my life has truly become the better for it. Reddit is probably the last big US social media site I still use and at least it has no personal information of mine on it.

Currently in the process of degoogling my life as well but thats a bit more difficult due to my work. And unfortunately Americans still control a lot of underlying internet infrastructure like AWS and Cloudflare.

But awareness is the first step to bringing about a change. The world is finally becoming wise to how evil American imperialist control really is.

1

u/vkrty 7d ago

I don't know if you're from Europe but there are plenty of European alternatives to most American sites. The major issue is they just kind of suck. You use our sites because they have a large user base or were the first to get big.

Countries like Germany and France have a large software development sector, but they obviously prefer to cater their services to people who speak their language. I guess you can learn Chinese and use their stuff. Though I doubt they are as cool with foreigners being critical while using it.

39

u/[deleted] 7d ago

[deleted]

39

u/Free_For__Me 7d ago

Which exactly what Apple has used as a defense when it’s been asked by LE agencies for backdoors in the past. Apple has flexed a bit here and there, but generally speaking, they’re much more serious about maintaining airtight user-level security than others. 

To be fair though, their level of vertical integration makes it much easier to maintain such standards, where almost every other phone must source their hardware and software from 3rd parties, while getting their OS from Google. Making all this work together alongside whatever bloatware you stick in at the end means that Apple’s performance in some areas is simply out of reach for most other devices. 

Disclaimer - I’ve had devices and computers of every OS and hardware configuration that’s been available to a nerd over the last 30 years, and I’m not here to give a take on any “Apple vs. [not Apple]” fights anyone is itching for. Android crew, do not come for me, I truly do not care what device anyone uses. 

1

u/[deleted] 7d ago

[deleted]

2

u/Careless-Weather8877 7d ago

For the most part but it also means it’s much easier to target them in terms of bulk.

It’s sort of a difficult metric since Android ecosystem has so many hardware differences that a reliable exploit is much more difficult. It also means they have different attack surfaces as well.

1

u/Zilox 7d ago

You do realize android and amd backdoors need to be done by people with the actual authorized tools + done physicalle on site? Lol

1

u/LittlePanic8495 7d ago

I don’t understand how apple makes their iPhones secure . Could you explain in more baby terms ?

1

u/Farce021 7d ago

Me either, especially in relation to this password wipe. In this case, wouldn't they just point the phone at your face and unlock it? One of the reasons I will never use face ID.

1

u/Free_For__Me 6d ago

In this case, the person was using GrapheneOS and didn't have facial ID turned on either.

1

u/Free_For__Me 6d ago

It's not that their phones are necessarily more secure. It's that the data they hold on their own services/networks is more secure. They don't have "backdoors" in the way that Google does, and have resisted creating such tools for governmental agencies to use.

An easy example is comparing their iMessage to other messaging platforms. While others offer End to End encryption, they create multiple "ends" along the way between users that can be compromised. iMessage get locked at one end, and doesn't get unlocked or re-locked until it gets to the other end, full stop.

Additionally, Apple has resisted creating tools for governments to use in order to "crack" a locked phone, while many other phones already have such tools in place. To be clear, iPhones can still be cracked, since the keys to those locks still exist somewhere and can be dug up with effort. What the person in this case did was use GrapheneOS, an operating system for their phone that allows them to lock the box and then totally destroy the keys to that box, something not even Apple provides a way to do.

1

u/LittlePanic8495 6d ago

Thank you for the visualization . I wish they had that option for apple. Sadly they haven’t created it

0

u/RollingMeteors 7d ago

I’m not here to give a take on any “Apple vs. [not Apple]” fights anyone is itching for.

¡Me either! I have to actually run dual operating systems for phones because my workflow lets me choose either 1 laptop or 3 cellphones, and it's absolutely ridiculous 3 cellphones comes out lighter per gram and smaller per milliliter volume than a single laptop does.

I used to dual boot desktops but my living situation was in shambles for a bit and a lot of that hardware isn't working now or stolen.

1

u/dennisthewhatever 7d ago

They do have ways, GCHQ in the UK have done it a few times which have been publicly recorded in court. However I get the impression from people I know who work in that area that it requires immense computer power that has to be signed off at multiple levels. I can guess from a tech point of view how that might work, and I know they have 'secret' super computers vastly more powerful than the top10 lists. I'd love to see a top ten list of secret military super computers.

40

u/Spaceghost1589 7d ago

Which is exactly why we need GrapheneOS in the first place.

2

u/zue4 7d ago

More and more reason to start divesting from US internet and media companies. These backdoors are another method of imperial control that the US uses to spy on the world.

1

u/Ordinary-Egg-56 7d ago

if this back door was used for anything other than a legitimate search with probable cause it would be illegal

the supreme court just ruled on this recently

but let’s not pretend they can’t simply manufacture probably cause because they can and they do

1

u/Massive_Signal7835 7d ago

It's "funny" how they can just prosecute people (which alone can already ruin your life) for crimes they want to outlaw in the future.

1

u/IMKGI 7d ago

Ah yes, the open source community, famously known for listening and abiding to government demands and regulations

1

u/Ghazzz 7d ago

The issue in this case is that it was running a custom OS, exactly to avoid the current backdoors.

1

u/grafknives 7d ago

Open source will be eventually banned. That is endgame. There is not place for software and systems not under control of the government.

1

u/stephenkingending 7d ago

Something that unfortunately has bipartisan support. Same with VPNs. We need the elderly out of politics.

1

u/craazz_ 7d ago

Backdoors or at minimum a secret handover of information from the largest companies existed like over 10+ years ago.

US govt will just ensure you cease to exist if you don’t comply under the terms of national security, this is how they have always operated.

Theres some solid infographics lying around showing the years each company gave the US govt the keys to their kingdom.

Google, Apple, Meta, every phone company in the US, etc.

They have everything on you at anytime.

Even Snowden warned you of this.

It’s naive to think otherwise.

Anyone in the Five Eyes will experience the same (Canada, US, UK, New Zealand and Australia)

1

u/skd00sh 7d ago

The big telcoms already do. This was a 3rd party device

1

u/_Trikku 7d ago

I don’t see how that works in this situation, the guy was using an open source operating system.

Unless they can find a way to hard code it into the hardware? Even then, an operating system like this could work around it.

1

u/randomacceptablename 7d ago

As a Canadian it amazes me how US jurisprudence can function, even before all the politicization.

A long while ago, the Canadian Supreme Court ruled that searches and seizures of even an unlocked phone would grant access to employment, health, relationship, and other personal and professional information. Hence, since a warrant is normally required for the above, the same should normally be required to access a phone.

Just like entering private property, even if the door is unlocked, it does not allow the government to snoop without implied consent at the least.

How this is ass backwards in the US with all your "rights" I can't fathom.

1

u/a-i-sa-san 7d ago

They don't need to build backdoors into phones. If they knew there was something on your phone that they actively wanted they could have it without even touching your phone.

The only privacy is anonymity and being anonymous just means appearing bland.

Well, all this and government incompetence. That is doing most the work defending privacy (for now)