Fun fact for the UK: "UK police have a new tactic to circumvent strong iPhone encryption: steal the unlocked phone out of the criminal’s hand"
(https://9to5mac.com/2016/12/05/uk-police-have-a-new-tactic-f...)
I remember reading this a few years back. The title says it all. Why bother cracking codes etc when you can get a judge to sign THAT for you? :)
Going through the PDF of the legal document, on page 10, the screenshots have a description of the "Source extraction" (point): "..../private/var/Containers/Shared/AppGroup//telegram-data/account/postbox/db/db_sqlite"
I got so many questions.. I believe Telegram does NOT encrypt group chats. And the default setting is that it does NOT encrypt 1-1 chats. You have to jump the extra hoop (a couple of taps) to start a new and encrypted chat (you cannot encrypt an existing chat).
So.. the chat was not encrypted? So they 'just' managed to bypass iPhone's lock, and dump all the storage, look for messaging SQLITE files, read them. Are we sure they didn't get that data from iCloud (and hiding it - with permission?). Page 11 writes: "Several videos from his iCloud depict him apparently showing off his cash." Could the authorities have gotten an automated backup from iCloud, the guy was using an unencrypted Telegram chat, so basically not much hacking took place?
Side note: big Supernatural fan here - page 10, the second 'blue' message writes "..Poughkeepsie". In the Supernatural universe "Poughkeepsie" is the Winchesters' secret distress signal to each other meaning that something is wrong and they are to drop everything and run.