Sunday, March 16, 2025

iPhones now auto-restart to dam entry to encrypted information after lengthy idle occasions


Apple has added a brand new safety function with the iOS 18.1 replace launched final month to make sure that iPhones robotically reboot after lengthy idle intervals to re-encrypt information and make it more durable to extract.

Whereas the corporate has but to formally verify this new “inactivity reboot” function, regulation enforcement officers had been the primary to find it after observing suspects’ iPhones restarting whereas in police custody, as first reported by 404 Media.

This switches the idle gadgets from an After First Unlock (AFU) state to a Earlier than First Unlock (BFU) state, the place the gadgets are more difficult to interrupt utilizing forensic telephone unlocking instruments.

Moreover, DFU makes extracting saved information more durable, if not inconceivable, since even the working system itself can now not entry it utilizing encryption keys saved in reminiscence.

“Apple added a function known as “inactivity reboot” in iOS 18.1. That is applied in keybagd and the AppleSEPKeyStore kernel extension,” as Hasso-Plattner-Institut researcher Jiska Classen defined.

“It appears to don’t have anything to do with telephone/wi-fi community state. Keystore is used when unlocking the system. So if you happen to do not unlock your iPhone for some time… it should reboot!”

iOS 18.1 inactivity reboot feature

Merely put, on iOS gadgets, all information is encrypted utilizing an encryption key created when the working system is first put in/arrange.

GrapheneOS informed BleepingComputer that when an iPhone is unlocked utilizing a PIN or biometric, like Face ID, the working system masses the encryption keys into reminiscence. After this, when a file must be accessed, it should robotically be decrypted utilizing these encryption keys.

Nonetheless, after an iPhone is rebooted, it goes into an “at relaxation” state, now not storing encryption keys in reminiscence. Thus, there isn’t any option to decrypt the info, making it way more immune to hacking makes an attempt.

If regulation enforcement or malicious actors achieve entry to an already locked system, they will use exploits to bypass the lock display. Since decryption keys are nonetheless loaded into reminiscence, they will entry the entire telephone’s information.

Rebooting the system after an idle interval will robotically wipe the keys from reminiscence and stop regulation enforcement or criminals from accessing your telephone’s information.

An Apple spokesperson was not instantly obtainable for remark when contacted by BleepingComputer earlier.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles