Report: Apple's iOS 12 now blocks iPhone-hacking tool favored by police

Your iPhone just got a better lock.
By Jack Morse  on 
Report: Apple's iOS 12 now blocks iPhone-hacking tool favored by police
Shut down. Credit: VICKY LETA / MASHABLE

Your iPhone just got a little more secure — assuming you've updated to iOS 12, that is.

Following reports earlier this summer that Apple planned to release a software update that would combat the phone-hacking device, sometimes used by police, known as GrayKey, Forbes has confirmed that the Cupertino-based company has done just that. While it's not a 100 perfect lockout to the cops, the update goes a long way toward further protecting iPhone owners from invasive government snooping.

But first, some background. The GrayKey device, a physical machine manufactured by the Atlanta-based Grayshift, was able to get around iPhone PINs to unlock phones seized by police. Somehow, the device could bypass Apple's prohibition of multiple password guesses. This allowed the GrayKey to enter codes in rapid succession until the phone unlocked.

According to Apple Insider, researchers estimated that it took the device around 11 hours to unlock a phone with a six-digit passcode. A four-digit code could be hacked in this way in as little as six and a half minutes.

Two different versions of the machine sell for $15,000 and $30,000, with the latter reportedly good for unlimited unlocks.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

Or, at least it used to be. Forbes notes that "[multiple] sources familiar with the GrayKey tech" confirmed that "the device can no longer break the passcodes of any iPhone running iOS 12 or above."

There is, however, an important caveat: The GrayKey can still access some data on the phone. Specifically (again, according to Forbes), "police using the tool can only draw out unencrypted files and some metadata, such as file sizes and folder structures."

And while that's not perfect, it's better than the unfettered access a full unlock would previously get them.

Nicholas Weaver, a senior staff researcher at the International Computer Science Institute, wrote that it "[sounds] like Apple patched whatever secure-enclave exploit that GrayKey used to do the on-chip brute force attack."

Although, to be clear, this appears to be speculation on his part.

Either way, this news is cause for celebration among privacy advocates. It also, of course, is cause for consternation among law enforcement.

But with Apple CEO Tim Cook taking a strong stance on user privacy as recently as this morning, we should expect to see addition attempts by Apple to lock down iPhones. And, of course, more attempts by both Grayshift and police to defeat them.

Mashable Image
Jack Morse

Professionally paranoid. Covering privacy, security, and all things cryptocurrency and blockchain from San Francisco.


Recommended For You
Apple Watch Series 9 vs. SE: A smartwatch skeptic tested both for 13 days
Apple Watch Series 9 vs. SE

How to blur your home on Google Street View (and why you should)
A home blurred on Google Street view

'I was kinda trapped': Watch a Cybertruck try to eat a guy's finger
a Tesla Cybertruck with its frunk trunk or "frunk" standing open

Apple Watch feature becomes first digital health tech to receive this FDA approval
Apple Watch

Rabbit R1, Humane Ai pin guts exposed in new teardown video
Humane Ai pin and woman holding Rabbit R1

Trending on Mashable
NYT Connections today: See hints and answers for May 3
A phone displaying the New York Times game 'Connections.'

'Wordle' today: Here's the answer hints for May 3
a phone displaying Wordle

T-Mobile, AT&T, Sprint, Verizon slapped with $200M fine — here’s what they illegally did with your data
User holding iPhone

NYT's The Mini crossword answers for May 3
Closeup view of crossword puzzle clues

The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!