iOS 11.4 Disables Lightning Connector After 7 Days, Limiting Law Enforcement Access

iphonexlockedThe iOS 11.4 update, currently being beta tested, includes a USB Restricted Mode that introduces a week-long expiration date on access to the Lightning port on your iOS devices if your phone hasn't been unlocked, which has implications for law enforcement tools like the GrayKey box.

USB Restricted Mode was outlined this morning by Elcomsoft after testing confirmed that the feature has indeed been enabled. In Elcomsoft's experience, after an iPhone or iPad has been updated to iOS 11.4, if it hasn't been unlocked or connected to a paired computer in the last 7 days using a passcode, the Lightning port is useless for data access and limited to charging.

At this point, it is still unclear whether the USB port is blocked if the device has not been unlocked with a passcode for 7 consecutive days; if the device has not been unlocked at all (password or biometrics); or if the device has not been unlocked or connected to a trusted USB device or computer.

In our test, we were able to confirm the USB lock after the device has been left idle for 7 days. During this period, we have not tried to unlock the device with Touch ID or connect it to a paired USB device. What we do know, however, is that after the 7 days the Lightning port is only good for charging.

With a time limit on the Lightning port, it seems law enforcement officials and bad actors who have physical access to a device will have one week from the time that it was last unlocked to attempt to access it through unlocking tools like the GrayKey, which uses the Lightning port to install software to crack the passcode of an iOS device.

USB Restricted Mode won't prevent tools like the GrayKey box from being used on an iPhone, but it does suggest that the passcode needs to be discovered within a matter of days, severely limiting the amount of time that law enforcement officials have to get into a device.

In developer documentation, Apple says the new mode is meant to bolster security on the iPhone and iPad: "To improve security, for a locked iOS device to communicate with USB accessories you must connect an accessory via Lightning connector to the device while unlocked - or enter your device passcode while connected - at least once a week."

Apple is pairing the new USB Restricted Mode with several other security features that have been introduced through iOS 11 updates. Early iOS 11 updates introduced expiration dates for local backup techniques used to access iOS devices, while iOS 11.3 introduced further limits, cutting down access to just one week.

graykey1

GrayKey iPhone unlocking box, via MalwareBytes

Companies like GrayShift that provide iPhone unlocking tools to law enforcement agencies keep their methods highly secretive to prevent Apple from discovering and patching the exploits being used for access, but USB Restricted Mode and restricted access to local backups introduce clever mitigations that allow Apple to limit these tools even if the specific vulnerabilities haven't yet been addressed.

USB Restricted Mode was actually first introduced in the iOS 11.3 beta, but it didn't make it into the iOS 11.3 release, so its presence in the iOS 11.4 beta does not guarantee that it will be included when iOS 11.4 launches to the public.

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Top Rated Comments

MLVC Avatar
42 months ago
Nice! Now would be even nicer if it was shorter then 7 days. 1 day is fine with me. A couple of hours would be fine with me too.
Score: 116 Votes (Like | Disagree)
thisisnotmyname Avatar
42 months ago
why wait a week? Why not daily?
Score: 38 Votes (Like | Disagree)
IGI2 Avatar
42 months ago
Nice! Now would be even nicer if it was shorter then 7 days. 1 day is fine with me. A couple of hours would be fine with me too.
An opt-in option to enter the passcode (Face ID or Touch ID) every time you connect the iPhone to Mac or PC would be nice as well.
Score: 36 Votes (Like | Disagree)
wolfshades Avatar
42 months ago
Now THAT is a genius solution, especially as it cuts off those who diligently attempt to update/create more bypasses at the advent of each new OS iteration. Well done, Apple!
Score: 35 Votes (Like | Disagree)
Nozuka Avatar
42 months ago
Why are they waiting 7 days?
Score: 31 Votes (Like | Disagree)
StevieD100 Avatar
42 months ago
Please Apple, impliment this but make the delay user configurable with a max and a default of say 7 days.
I'd set mine to 2 hours...
And no, I don't have anything to hide apart from my life.
Then go one step further and allow the device to initiate a security erase in the background if attempts are made to unlock it via USB.
Yes, shades of mission impossible but TBH, I want snooping on my phone to be a 'mission impossible'.
Score: 31 Votes (Like | Disagree)

Top Stories

REC ASA CODE2016 20160601 205816 2745

Elon Musk Reportedly Demanded to Become Apple CEO as Part of Potential Tesla Acquisition [Update: Musk Denies]

Friday July 30, 2021 9:04 am PDT by
Tesla CEO Elon Musk reportedly once demanded that he be made Apple CEO in a brief discussion of a potential acquisition with Apple's current CEO, Tim Cook. The claim comes in a new book titled "Power Play: Tesla, Elon Musk and the Bet of the Century," as reviewed by The Los Angeles Times. According to the book, during a 2016 phone call between Musk and Cook that touched on the possibility of ...
General Apps Messages

Android iMessage Competitor Puts Pressure on Apple

Friday July 30, 2021 3:15 am PDT by
Google and the three major U.S. carriers, including Verizon, AT&T, and T-Mobile, will all support a new communications protocol on Android smartphones starting in 2022, a move that puts pressure on Apple to adopt a new cross-platform messaging standard and may present a challenge to iMessage. Verizon recently announced that it is planning to adopt Messages by Google as its default messaging...
Apple watch series 5 new case material made of titanium 091019

Titanium Apple Watch Series 6 Models Currently Widely Unavailable

Sunday August 1, 2021 6:21 am PDT by
Models of the Apple Watch Series 6 with titanium cases part of the "Apple Watch Edition" collection is currently widely unavailable for pick-up in several of Apple's retail stores in the United States and is unavailable entirely for delivery in major markets. Noted by Bloomberg's Mark Gurman in the latest edition of his "Power On" newsletter, titanium models of the Apple Watch Series 6,...
ifixit iphone12 mini

Apple to Make Space for Larger Batteries in iPhones, iPads, and MacBooks By Adopting Slimmer Peripheral Chips

Monday August 2, 2021 2:12 am PDT by
For future iPhones, iPads, and MacBooks, Apple plans to use smaller internal components in an effort to increase the size of the device's battery, according to DigiTimes. Image Credit: iFixit Specifically, Apple plans to "significantly increase the adoption" of IPDs or integrated passive devices for the peripheral chips in its products. These news chips will be slimmer in size and allow for...
Flat 2021 MacBook Pro Mockup Feature

Unreleased Apple Macs and Apple Watches Listed in Eurasian Database Ahead of Fall Product Launches

Monday August 2, 2021 9:34 am PDT by
Apple is preparing for a slew of fall product launches according to new filings that showed up today in the Eurasian Economic Commission database. There are listings for new Mac and Apple Watch models, all of which have previously unknown model identifiers that indicate that they're upcoming devices. There are six new Apple Watch identifiers, including A2473, A2474, A2475, A2476, A2477, and...
a15 chip

iPhone 13 and Redesigned MacBook Pro Chip Production Hit With Gas Contamination

Friday July 30, 2021 5:44 am PDT by
The most important TSMC factory that manufactures Apple's chips destined for next-generation iPhone and Mac models has been hit by a gas contamination, according to Nikkei Asia. The factory, known as "Fab 18," is TSMC's most advanced chipmaking facility. TSMC is Apple's sole chip supplier, making all of the processors used in every Apple device with a custom silicon chip. Industry...
iPhone 13 Wi Fi 6E feature update

Wi-Fi 6E Explained: What It Could Mean for iPhone 13 and Beyond

Monday August 2, 2021 8:00 am PDT by
The iPhone 13 is widely expected to come with Wi-Fi 6E capabilities, and while it may seem rather nuanced to the average consumer, with only improved speeds and being "up to date" in the realm of Wi-Fi technology, it's actually a fairly significant improvement, laying the groundwork for much of what we know the future holds. To truly understand Wi-Fi 6E, MacRumors sat down for an exclusive...
youtube premium lite

YouTube Tests Cheaper 'Premium Lite' Subscription for Ad-Free Viewing

Monday August 2, 2021 3:22 am PDT by
YouTube is piloting a new cheaper subscription tier in Europe called "Premium Lite," which offers ad-free viewing minus YouTube Premium's other features. First spotted by a user on ResetEra and subsequently confirmed by Google, the "Lite" plan means users who aren't interested in offline downloads or background playback can still enjoy YouTube videos on web and mobile app without being...
iPhone 13 Always On Feature

iPhone 13 to Bring Over a Major Feature From the Apple Watch

Wednesday July 28, 2021 2:21 am PDT by
Apple's upcoming iPhone 13 lineup will feature an always-on display akin to the Apple Watch Series 5 and Series 6, according to recent reports. In his weekly Power On newsletter, Bloomberg journalist Mark Gurman, who often reveals accurate insights into Apple's plans, said that the iPhone 13 may feature an Apple Watch-inspired always-on mode. The Apple Watch Series 5 and Apple Watch...
COVID19 Digital Wallet Apple Wallet

Australian Government Now Offering COVID-19 Digital Vaccination Certificates for Apple Wallet

Monday August 2, 2021 12:04 am PDT by
The Australian government has introduced support for adding COVID-19 vaccination digital certificates to Apple Wallet via the Express Plus Medicare app on iOS. Image credit: Tap Down Under As spotted by Tap Down Under, users who have received two doses of either the AstraZeneca or Pfizer vaccine now have access to the digital certificate through their Medicare online account or via the Medica...