Skip to content
Phone SeizedThey have your phone?
Menu

Phone SeizedProtect yourselfPasscode strength, updates, and why they matter

Passcode strength, updates, and why they matter

Applies to: England & Wales · Scotland · Northern Ireland · Australia · United States. The law differs materially between jurisdictions this site covers — do not apply this page outside the one named here. Law also varies by state and territory in Australia — this page does not describe every state or territory. Law also varies by state, and by federal circuit, in the United States — this page does not describe every state or circuit.

What you must do, what you can refuse, and what they can do

Every claim below links to the law it comes from, with the wording quoted so you can check it yourself.

Lawful to refuse — but it costs you

Not an offence, but it carries a penalty or an inference.

  • Apple states that iPad, iPhone, Mac and Apple Vision Pro use escalating time delays after each invalid passcode, password or PIN entry, to discourage brute-force attacks.

    Apple Platform Security Guide — "Passcodes and passwords", published 19 Dec 2024, Apple
    On iPad, iPhone, Mac, and Apple Vision Pro , to further discourage brute-force passcode attacks, there are escalating time delays after the entry of an invalid passcode, password, or PIN (depending on the device and the state the device is in), as shown in the table below.

    Read it at support.apple.comquote checked 2026-09-08

  • Apple states it would take more than five and one-half years to try all combinations of a six-character alphanumeric passcode using lowercase letters and numbers.

    Apple Platform Security Guide — "Passcodes and passwords", published 19 Dec 2024, Apple
    In fact, it would take more than five and one-half years to try all combinations of a six-character alphanumeric passcode with lowercase letters and numbers.

    Read it at support.apple.comquote checked 2026-09-08

  • GrapheneOS documents a passphrase option so users who do not want to rely solely on the secure element's throttling can use a diceware password, describing that throttling as very aggressive even for a random six-digit PIN.

    GrapheneOS, "Features" (grapheneos.org/features), as fetched 2026-09-08
    This feature allows users to make use of diceware passwords if they don't want to depend on the security of the secure element which provides very aggressive throttling and offers a high level of security even for a random 6 digit PIN.

    Read it at grapheneos.orgquote checked 2026-09-08

  • Android requires all devices that launched with Android 10 or later to use file-based encryption.

    Android Open Source Project, "File-based encryption" (source.android.com), as fetched 2026-09-08
    All devices launching with Android 10 and higher are required to use file-based encryption.

    Read it at source.android.comquote checked 2026-09-08

  • Apple states that shortly after a device locks, the key for its most-protected data class is discarded, making that class of data inaccessible until the passcode is entered again or the device is unlocked.

    Apple Platform Security Guide — "Data Protection classes", published 19 Dec 2024, Apple
    Shortly after the user locks a device (10 seconds, if the Require Password setting is Immediately), the decrypted class key is discarded, rendering all data in this class inaccessible until the user enters the passcode again or unlocks (logs in to) the device using Optic ID , Face ID , or Touch ID .

    Read it at support.apple.comquote checked 2026-09-08

  • Magnet Forensics reported on 13 Nov 2024 that on iOS 18, once a device has entered a locked state and has not been unlocked within 72 hours, it will reboot.

    Magnet Forensics blog, "Understanding the security impacts of iOS 18's inactivity reboot", 13 Nov 2024
    This means that once a device has entered a locked state and has not been unlocked within 72 hours, it will reboot.

    Read it at magnetforensics.comquote checked 2026-09-08

  • AppleInsider reported on 18 Jul 2024, based on a leaked Cellebrite document, that significant sections of the model/iOS support matrix were listed as 'Coming Soon' or 'in Research' rather than supported.

    AppleInsider, "Cellebrite can't crack iPhones running iOS 17.4 or later", William Gallagher, 18 Jul 2024
    Significant sections of the model/iOS matrix are listed as either "Coming Soon," or "in Research."

    Read it at appleinsider.comquote checked 2026-09-08

Passcode strength and delay, in Apple's own words

Apple documents two separate defences behind a passcode. First, delay: “On iPad, iPhone, Mac, and Apple Vision Pro, to further discourage brute-force passcode attacks, there are escalating time delays after the entry of an invalid passcode, password, or PIN.” Second, length and character set: Apple states “it would take more than five and one-half years to try all combinations of a six-character alphanumeric passcode with lowercase letters and numbers.” That figure is specifically about a six-character alphanumeric passcode — Apple’s own document does not publish an equivalent figure for a numeric-only PIN of any particular length, and this page does not invent one.

The same idea implemented differently: GrapheneOS and Android

GrapheneOS documents a passphrase option built on the same logic: it exists “so users can make use of diceware passwords if they don’t want to depend on the security of the secure element,” which GrapheneOS itself describes as providing “very aggressive throttling and…a high level of security even for a random 6 digit PIN.” Separately, on the storage side rather than the unlock side, Android requires that “all devices launching with Android 10 and higher are required to use file-based encryption” — the mechanism behind the Credential Encrypted/Device Encrypted split described in What a full extraction contains.

What happens if a locked phone sits untouched

Apple states that shortly after a device locks, the key for its most-protected data class is discarded, “rendering all data in this class inaccessible until the user enters the passcode again or unlocks (logs in to) the device.” That is the AFU-to-more-protected shift described in What a full extraction contains. Separately, Magnet Forensics reported on 13 Nov 2024 that on iOS 18, “once a device has entered a locked state and has not been unlocked within 72 hours, it will reboot” — a reported technical observation, not an Apple support-page statement, but the closest dated source for that specific behaviour. A reboot returns a device to the off/BFU state described on the same page.

Why staying updated is not just housekeeping

AppleInsider reported on 18 Jul 2024, based on a leaked Cellebrite document, that “significant sections of the model/iOS matrix are listed as either ‘Coming Soon,’ or ‘in Research’” — meaning a forensic vendor’s own internal tracking, as reported, showed gaps in support for current iPhone models and iOS versions at that point in time. That is a single reported snapshot, not a standing guarantee about any future OS version, and it is reported, not a vendor statement.

Last reviewed 2026-09-08. Next review due 2026-12-08. No lawyer has reviewed this page — see [email protected] if you think something here is wrong.