• MegaUltraChicken@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    2 days ago

    Basically, the tools that LE uses to unlock devices uses exploits that require the device to be in what’s called an AFU (after first unlock) state. The data on the device is encrypted prior to that first unlock after you boot. If the device is in a BFU state (before first unlock) Cellebrite/Greykey (by far the primary tools used in this space) basically hit a wall.

    • sem@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 days ago

      Elsewhere in the thread they explain because decryption takes time, they don’t cycle it every time you lock your phone by default. Not sure if there’s more to it.

      • twice_hatch@midwest.social
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 days ago

        The time needed for key derivation aka key stretching may be a factor, but also in the BFU state I think apps don’t run and you don’t get notifications, since most of the files are still locked