Phone SeizedProtect yourselfLock state, Lockdown Mode, and GrapheneOS: what each actually changes
Lock state, Lockdown Mode, and GrapheneOS: what each actually changes
What you must do, what you can refuse, and what they can do
Every claim below links to the law it comes from, with the wording quoted so you can check it yourself.
Lawful to refuse — but it costs you
Not an offence, but it carries a penalty or an inference.
Apple states that its most-protected data class becomes inaccessible shortly after lock until the passcode is entered again, or the device is unlocked using Optic ID, Face ID, or Touch ID.
Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
“Shortly after the user locks a device (10 seconds, if the Require Password setting is Immediately), the decrypted class key is discarded, rendering all data in this class inaccessible until the user enters the passcode again or unlocks (logs in to) the device using Optic ID , Face ID , or Touch ID .”
Read it at support.apple.comquote checked 2026-09-08
Apple documents a default Data Protection class that applies to third-party app data not otherwise assigned to a class of its own.
Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
“This is the default class for all third-party app data not otherwise assigned to a Data Protection class.”
Read it at support.apple.comquote checked 2026-09-08
Android's file-based encryption documentation states that Credential Encrypted storage, the default storage location for app data, is only available after the user has unlocked the device.
Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
“Credential Encrypted (CE) storage, which is the default storage location and only available after the user has unlocked the device.”
Read it at source.android.comquote checked 2026-09-08
Apple states that Lockdown Mode requires a device to be unlocked before it can connect to an accessory or another computer.
Apple, "About Lockdown Mode" (support.apple.com/en-gb/105120), as fetched 2026-09-08
“Device connections: to connect your iPhone or iPad to an accessory or another computer, the device needs to be unlocked.”
Read it at support.apple.comquote checked 2026-09-08
GrapheneOS documents an auto-reboot timer set to 18 hours by default, adjustable between 10 minutes and 72 hours, or able to be turned off.
GrapheneOS, "Features" (grapheneos.org/features), as fetched 2026-09-08
“The timer is set to 18 hours by default, but can be set to values between 10 minutes and 72 hours, or turned off.”
Read it at grapheneos.orgquote checked 2026-09-08
GrapheneOS documents a duress PIN or password feature that irreversibly wipes the device, including any installed eSIMs, when entered at the lockscreen or any other credential prompt.
GrapheneOS, "Features" (grapheneos.org/features), as fetched 2026-09-08
“GrapheneOS provides users with the ability to set a duress PIN/Password that will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested (on the lockscreen, along with any such prompt in the OS).”
Read it at grapheneos.orgquote checked 2026-09-08
GrapheneOS documents that its default USB-C setting when the device is locked is charging-only, which it states significantly reduces attack surface.
GrapheneOS, "Features" (grapheneos.org/features), as fetched 2026-09-08
“The default is Charging-only when locked , which significantly reduces attack surface when the device is locked.”
Read it at grapheneos.orgquote checked 2026-09-08
A security-research analysis published 16 Mar 2025 reported that GrapheneOS's additional hardening was effective against full-file-system extraction in the after-first-unlock state, unlike the standard Google build of Android, and had been so since 2022.
Osservatorio Nessuno, "A deep dive into Cellebrite Android support, as of February 2025", 16 Mar 2025
“While it seems that for the standard Google ROM there are working exploits available to perform the FFS extraction in AFU state, on the contrary GrapheneOS additional hardening and protections are effective, and have been so since 2022.”
Read it at osservatorionessuno.orgquote checked 2026-09-08
Apple's own law enforcement guidelines state that for iOS 8.0 and later, Apple is unable to perform an iOS device data extraction because the data typically sought is encrypted and Apple does not hold the encryption key.
Apple, "Legal Process Guidelines — Government & Law Enforcement within the United States", published October 2025, Apple
“For all devices running iOS 8.0 and later versions, Apple is unable to perform an iOS device data extraction as the data typically sought by law enforcement is encrypted, and Apple does not possess the encryption key.”
Read it at apple.comquote checked 2026-09-08
BFU and AFU, in the vendors' own documentation
The off/BFU, AFU and unlocked states defined in What a full extraction contains are not this site’s invention — they follow directly from how Apple and Android document their own encryption. Apple states that shortly after lock, the key for its most-protected data class is discarded, and the same document lists the ways to get it back: “until the user enters the passcode again or unlocks (logs in to) the device using Optic ID, Face ID, or Touch ID.” Apple separately documents a default class, applied to third-party app data not otherwise assigned to a class of its own, that is a different class from the one discarded at lock. Android’s file-based encryption documentation draws the same kind of line: Credential Encrypted storage, the default location for app data, “is only available after the user has unlocked the device.”
Lockdown Mode's effect on accessory connections
Apple states that Lockdown Mode restricts device connections: “to connect your iPhone or iPad to an accessory or another computer, the device needs to be unlocked.” That is a stated restriction on cable or dongle-based connections specifically — not a claim about what happens over Wi-Fi, cellular, or cloud sync, which are separate paths covered on Cloud and carrier.
What GrapheneOS adds on top of the Android base
GrapheneOS documents three features layered on top of standard Android file-based encryption. An auto-reboot timer: “The timer is set to 18 hours by default, but can be set to values between 10 minutes and 72 hours, or turned off” — each reboot returns the device to off/BFU. A duress PIN or password that “will irreversibly wipe the device (along with any installed eSIMs) once entered anywhere where the device credentials are requested.” And a USB-C default of “Charging-only when locked, which significantly reduces attack surface when the device is locked” — a data-connection restriction in the same spirit as Lockdown Mode’s accessory rule above, on a different operating system.
What was reported about GrapheneOS's resistance to one vendor's tools
A security-research analysis published 16 Mar 2025 reported that “while it seems that for the standard Google ROM there are working exploits available to perform the FFS extraction in AFU state, on the contrary GrapheneOS additional hardening and protections are effective, and have been so since 2022.” That is one researcher’s reported assessment of one vendor’s tooling as of the date given — not a permanent guarantee, and not this site’s own technical claim.
Apple's own position on passcode-locked devices
Apple’s own law enforcement guidelines state: “For all devices running iOS 8.0 and later versions, Apple is unable to perform an iOS device data extraction as the data typically sought by law enforcement is encrypted, and Apple does not possess the encryption key.” That is Apple describing what its own devices do, in a document written for law enforcement, not a third-party claim about Apple.
Last reviewed 2026-09-08. Next review due 2026-12-08. No lawyer has reviewed this page — see [email protected] if you think something here is wrong.