38C3 Lightningtalks

iOS Inactivity Reboot
29.12.2024 , Bühne HUFF
Sprache: English

When your phone is stolen, a simple reboot significantly improves the security of your data! Curious about how this protection works and how Apple automated reboots in iOS 18?


Apple silently introduced a feature called "Inactivity Reboot" in iOS 18. This inactivity reboot restarts an iPhone if it was not unlocked for three days, similar to auto-reboot on GrapheneOS. A reboot puts a phone into "before first unlock" state, meaning that disk encryption secures the data. This makes data extraction with forensic tooling more challenging, posing a significant barrier for thieves, but also complicating processes of law enforcement.

In this talk, you'll learn how inactivity reboot is implemented on iOS and what it protects.

Jiska Classen is a wireless and mobile security researcher at Hasso Plattner Institute. The intersection of these topics means that she digs into iOS internals, reverse engineers wireless firmware, and analyzes proprietary protocols. Her practical work on public Bluetooth security analysis tooling uncovered remote code execution and cryptographic flaws in billions of mobile devices. She also likes to work on obscure and upcoming wireless technologies, for example, she recently uncovered vulnerabilities in Ultra-wideband distance measurement and reverse engineered Apple's AirTag communication protocol.

She has previously spoken at Black Hat USA, DEF CON, RECon, hardwear.io, Chaos Communication Congress, Chaos Communication Camp, Gulasch Programmier Nacht, MRMCDs, Easterhegg, Troopers, Pass the Salt, NotPinkCon, gave various lectures and trainings, and published at prestigious academic venues.

Diese(r) Vortragende hält außerdem: