Affiliate Disclosure
If you buy through our links, we may get a commission. Read our ethics policy.

iPhone unlocking tool GrayKey sees increased use across all levels of law enforcement

Last updated

With the help of the iPhone-cracking GrayKey, local police departments and government agencies alike are gaining the ability to crack the security in the iPhone in ever-greater numbers, a new report says.

Back in early 2016, Apple famously refused to assist the FBI in unlocking an iPhone 5c belonging to Syed Rizwan Farook, one of the shooters in that year's San Bernardino attack. The FBI later got into the device on their own, setting off an entire round of disputes between the company and federal law enforcement.

Both federal law enforcement and local police departments have begun using GrayKey, a relatively inexpensive encryption bypass tool, and other tools like it, according to an investigative piece published by Motherboard.

Vice found, using public records requests, that the State Department has purchased GrayKey technology, as have the Indiana and Maryland State Police. The Secret Service and Drug Enforcement Agency are planning to, and the Indianapolis and Miami-Dade police departments either have bought the equipment or have sought it.

The same site had reported last month that the Indiana State Police had contracted to use GrayKey. Beyond Indiana, Vice does not say in the piece exactly how many state and local police departments are using GrayKey.

The device can unlock an iPhone in a matter of hours for a four-digit passcode, but six-digit passcodes, now the standard, can take as long as three days, according to an analysis by MalwareBytes.

GrayKey is manufactured by a startup company called Grayshift, with Braden Thomas, a former Apple security engineer, among its principals. Thomas has his name on at least five Apple patents.

The GrayKey device has been described as "a pocket-sized device with questionable security," available in $15,000 and $30,000 editions.

The piece also notes that despite the FBI using GrayKey, FBI Director Christopher Wray has said publicly that "we face an enormous and increasing number of cases that rely on electronic evidence. We also face a situation where we're increasingly unable to access that evidence, despite lawful authority to do so," according to comments published by the website Lawfare, and cited by Vice.



47 Comments

Cesar Battistini Maziero 410 comments · 8 Years

Apple should eliminate the codes and stick with just Touch ID and Face ID

SpamSandwich 32917 comments · 19 Years

Apple should eliminate the codes and stick with just Touch ID and Face ID

Neither of those things protect the phone (or iPad) owner from being forced to unlock their device, either by unethical law enforcement or a criminal who may temporarily have control over both the device and the owner.

sfolax 49 comments · 6 Years

Good job. Can't wait for DED to tell us his thoughts on this.

gatorguy 24627 comments · 13 Years

Apple should eliminate the codes and stick with just Touch ID and Face ID
Neither of those things protect the phone (or iPad) owner from being forced to unlock their device, either by unethical law enforcement or a criminal who may temporarily have control over both the device and the owner.

...nor from a legal court order that demands the owner use image or fingerprint to unlock his/her device. Yes you can be forced/compelled to unlock your device secured by Touch or Face ID. You cannot be legally compelled (in the US) to reveal what's in your mind so a pass-code can be more secure than any bio-metric locking method on a consumer device if you're bound and determined that no one sees what on your phone.

sflocal 6138 comments · 16 Years

Apple should eliminate the codes and stick with just Touch ID and Face ID

No consumer device will ever be 100% secure.  Let's agree on that.  The deterrent for many will in the difficulty of breaking into an iPhone.

Apple balances on a thin line in making the iPhone as secure as possible to everyone and making it easily accessible to the owner.  If my iPhone gets lost or stolen, I can be fairly confident that my data is secure.  However, if I'm in a position where my phone is confiscated by a government agency, then I would be naive to believe it's secure from a government that has the ability to throw a ton of resources, money, and manpower at breaking into my phone.

One thing I'm confident of is that Apple will continue to harden iPhone security, but then the iPhone cracking industry will continue as well.  Cat and Mouse.