iOS 12 introduces USB restrictions that effectively put an end to law enforcement access to iPhones and iPads using devices like the GrayKey box, but Grayshift, the company that makes the box, may have already developed a workaround.
VICE‘s Motherboard shared an email from a forensic expert who planned to meet with Grayshift, which said the company had “gone to great lengths” to futureproof its technology and that USB Restricted Mode had been “already defeated.”
Grayshift’s GrayKey iPhone unlocking box, via MalwareBytes
“Grayshift has gone to great lengths to future proof their technology and stated that they have already defeated this security feature in the beta build. Additionally, the GrayKey has built in future capabilities that will begin to be leveraged as time goes on,” a June email from a forensic expert who planned to meet with Grayshift, and seen by Motherboard, reads, although it is unclear from the email itself how much of this may be marketing bluff. “They seem very confident in their staying power for the future right now,” the email adds.
A second source that spoke to Motherboard said Grayshift addressed the topic of USB Restricted Mode in a webinar several weeks ago.
Coming in iOS 12, USB Restricted Mode prevents USB accessories from connecting to an iPhone or iPad if it’s been more than an hour since the device was last unlocked.
The setting is enabled by default and it will not allow USB-based accessories like the GrayKey box to connect to an iOS device until a passcode is entered, effectively disabling the current techniques law enforcement officials across the United States are using to access locked iPhones.
Motherboard‘s sources did not share details on how Grayshift plans to avoid the new USB restrictions, so it’s not clear if the GrayKey box will continue to function or if Grayshift has another iPhone access solution in the works.
Despite Grayshift’s potential workaround, law enforcement officials are concerned about the changes Apple is implementing, and are said to be frustrated with the attention the GrayKey box has received in the media. “Some vendors are frustrated with GrayKey,” one researcher told Motherboard. “They feel the media hype brought too much attention to the attack vector.”
Apple yesterday confirmed its plans to implement new USB access restrictions in iOS 12 and clarified that it is aiming to defend customers against hackers, not frustrate law enforcement officials.
“At Apple, we put the customer at the center of everything we design. We’re constantly strengthening the security protections in every Apple product to help customers defend against hackers, identity thieves and intrusions into their personal data. We have the greatest respect for law enforcement, and we don’t design our security improvements to frustrate their efforts to do their jobs,” Apple said in a statement to MacRumors.
Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.
Discuss this article in our forums