Oleg Afonin, of the desktop and mobile forensic tools maker Elcomsoft, wrote that the new feature disabled data connectivity of the Lightning connector after an hour since the device was last unlocked or an hour since it was disconnected from a trusted USB accessory.
The USB port could also be disabled manually. The new feature has been widely said to be aimed at companies like GrayShift and Cellebrite which make devices that can discover the passcodes of iPhones.
Focus on the iPhone's security has grown after the FBI had a stoush with Apple in 2016 over gaining access to a device used by a terrorist to kill people in San Bernardino, California, in December 2015.
Afonin said several tests had shown that USB Restricted Mode, once engaged, did not disappear due to reboots or a software restore.
He said there was a good chance that a device would be seized within an hour after being last unlocked as statistics had shown that iPhone users unlocked their phones at least 80 times a day.
According to Apple, users may have to unlock their passcode-protected iOS devices in order to connect them to a PC, Mac or a USB accessory after one hour since the device has been last unlocked or disconnected from a trusted USB accessory or computer.
But Afonin said he had found that iOS would reset the USB Restricted Mode timer if the device was connected to an untrusted USB accessory.
"In other words, once the police officer seizes an iPhone, he or she would need to immediately connect that iPhone to a compatible USB accessory to prevent USB Restricted Mode lock after one hour. Importantly, this only helps if the iPhone has still not entered USB Restricted Mode," he wrote.
He listed the following steps for preventing USB Restricted Mode from being engaged:
- Connect the iPhone to a compatible Lightning accessory (such as the official Lightning to USB 3 Camera Adapter).
- Plug external battery pack to the adapter (to avoid iPhone battery drain).
- Place the entire assembly in a Faraday bag.
"According to our tests, this effectively disables USB Restricted Mode countdown timer, and allows safely transporting the seized device to the lab," Afonin said.
"If you get a message that the device should be unlocked in order to use the accessory (when you connect it), then USB restricted mode has been activated already, and there is nothing you can do about that, sorry."
But he said it was only a matter of time until Apple released an update to prevent these workarounds.
"The ability to postpone USB Restricted Mode by connecting the iPhone to an untrusted USB accessory is probably nothing more than an oversight. We don’t know if this behaviour is here to stay, or if Apple will change it in (the) near future."