Cops suspect iOS 18 iPhones are communicating to force reboots
macrumors.com
macrumors.com
Or heck, if the phone thinks the cellular modem isn’t working (like the phone in a faraday cage), some watchdog might just timeout and reboot.
In any case, the idea that they’re randomly networking and intentionally rebooting to thwart this specific law enforcement attack seems pretty unlikely.
Apple‘s stance is to build strong encryption so that they can’t access customers data. What they have refused to do is weaken that encryption so that they could start complying with future requests or sign tampered with firmware that would allow the decryption without user authorization.
1. Your backups are encrypted in transit and at rest. You have a key, Apple also has one.
2. You can optionally ask Apple to get rid of its key to your backup. (https://support.apple.com/en-us/108756)
Basically older iPhones without the modern secure enclave enforced the password attempt lockout period in software so the FBI obtained a court order to force apple to create and sign a new version of iOS that would not enforce the lockout period, which would allow the FBI to guess the password. Apple refused to create this new version of iOS and the FBI eventually retracted their request.
Modern iPhones enforce the lockout period in the secure enclave hardware so this is no longer something Apple could even possibly assist with.
https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_d...
You mean in the sillicon itself? If it's done in the Secure Enclave's firmware then Apple could assist with unlocking.
Off by default, providing a one hour timeout since last phone unlock; or instantly, upon biometric rejection or after holding power-volume-up to reach the power off menu.
Macs are typically enabling an equivalent to this by default as well now, as of the latest macOS update.
> …sign tampered with firmware that would allow the decryption without user authorization.
Apple wrote the firmware for everything. I assume they could write firmware to not need authorization, embedded in a copy of iOS, and sign everything so it could be installed on a phone through DFU.
They have been unwilling to do so. I think they’re right not to. But I suspect it is technically possible.
In the previous case law enforcement retracted the request because they found an alternative..
If the alternative stop working i bet you they will go after Apple in courts again..
You can't prove a negative.
And that document is from last April, 7 months ago, no one really knows how things progressed after that..
Best assumption to make is that all those versions are supported by now..
support for iOS 18 could be available or not, we do not know.. So again i will assume it is supported until the opposite is proved..
But all the latest iPhones in latest iOS versions were only supported in AFU, that apple is handling with this reset feature, or IPR, that require USB being unlocked and is extremely time sensitive as there are already defenses in place..
This still effectively prevents Apple from adding backdoor to be installed on phones the user can no longer access.
Yes and they have also made it such that they can't bypass all that by providing a mechanism to unlock the phone. Hence they don't unlock the phone.
In the US and EU, where it is politically easy. https://support.apple.com/en-us/111754
So sit around in a less secure state for weeks and months and only when externally triggered reboot? That's a stupid feature and makes no sense. If you were to base any partial security measure off of how long a device has been powered up and locked, then just use a timer. Why wait for another phone to wander by?
Though the digital forensics lab claims they were all in airplane mode with one inside a faraday box, so how are they communicating with each other? This suggests incompetence on their part, perhaps not actually putting them in airplane mode or not understanding that bluetooth/wifi can be enabled (and may enable themselves) separately from the cellular radio.
If you download all your songs from Napster - they will work for a month or two without connecting to a network but eventually the lack of a connection will lock the content, it doesn't kno if your still paying, so it makes you sign in.
This is the same but all behind the scenes. Apple phones are constantly communicating with their network or other devices - if that stops, something fishy is going on bc it's not supposed to be able to.
The restart is prolly more for them - that's probably the solution to most of the issues with a phone losing network connection, just restart it. So they built it in.
Sure it does what phones have done forever and makes you sign in with password or full biometrics once at startup buts that's not new either.
At most an iPhone may be able to broadcast a Bluetooth message saying “anybody out there?“. I don’t even know if that’s possible. I’m sure Apple‘s white paper has the answer but I don’t remember it.
The 'Find My' network uses all iPhones/iPads/Macs (unless disabled) to locate said devices and other items over Bluetooth LE.
> The Find My network is an encrypted, anonymous network of hundreds of millions of Apple devices that can help find your stuff, even when it’s offline. Nearby devices securely send the location of your missing device to iCloud, so you can find it in Find My. It’s all anonymous and encrypted to protect everyone’s privacy. — https://support.apple.com/en-au/104978
It’s like an automated ARP response packet that’s automatically transmitted occasionally without needing to hear a request.
TBH I think it's very unlikely, but it's entirely possible they could add a flag to those beacon messages suggesting other iOS devices reboot.
On the other hand, I can easily see it being an honest bug where being off a cellular network corrupts the beacon message somehow, and reading the corrupt messages triggers iOS to reboot.
Who knows
"HEY Bob, you're in the pokey, reboot so your filesystem is umounted!"
A network deprived phone might not realize, yet a friendly nearby may.
I doubt this is so, but it would be a fun game.
And if it reboots on the cops Apple probably considers that a plus.
> the idea that they’re randomly networking and intentionally rebooting to thwart this specific law enforcement attack seems pretty unlikely.
So there is partial evidence for it at least.
Where? If you want that to be partial evidence, you have to parse that sentence as:
(they’re randomly networking and intentionally rebooting) to thwart this specific law enforcement attack
which means
(they’re randomly networking to thwart this specific law enforcement attack) AND (they’re intentionally rebooting to thwart this specific law enforcement attack)
All you show is that they’re randomly networking, not that it’s for thwarting even any law enforcement attacks, so I don’t think what you say is partial evidence.
Having a few lines of code to dictate what happens once a phone has been identified as any of the above is pretty simple stuff.
I think this restart is for Apple - an easy attempt to restore the devices network connection (and the data stream from it) and has little or nothing to do with law enforcement originally but now Apple will say that's the whole entire reason this exists bc privacy.
Anyways, it was absolutely relevant info to the article and considering it and more - it's obvious that Apple could have done this, or something like it, to thwart cops but is very unlikely.
Two birds, one stone..
Its all happening over RF, its not like they can implement this so a signal opens a inter-dimensional portal and comes back out making it undetectable on the RF spectrum.
[1]https://appleinsider.com/articles/24/11/07/iphones-stored-fo...
> The officials hypothesize that an iPhone running iOS 18 can send signals that make nearby units reboot if the device has been kept disconnected from cellular networks.
Either the officials are storing multiple devices in 1 cage, don't understand Faraday cages, or are arguing in bad faith.
> In October of 2024, multiple users of iPhone 16 Pro and iPhone 16 Pro Max units reported that their devices kept restarting themselves for no apparent reason. This is a known issue that occurred during normal use and one that Apple fixed with the iOS 18.1 update.
> This timeframe would also align with the creation of the alleged law enforcement document. Specifically, the document says that three iPhones with iOS 18.0 were brought into a forensics lab on October 3, after which they rebooted themselves.
Ah ignorance or bad faith after all.
It's not ENTIRELY far fetched, but it is very unlikely.
[1] https://www.wired.com/story/ultrasonic-signals-wild-west-of-...
To verify the original claim that it could happen over BLE, you don't need a faraday case to verify or prove this. The faraday cage just allows you to cut down on the data/signals to analyze.
well they do silently communicate for the "find my" network. I don't see why that couldnt result in a reboot somehow
Because Find My is a reverse-engineered protocol that can be abused to broadcast false information to nearby devices? Trusting Find My to know when it's time for a reboot sounds like an amazing Flipper Zero feature but a not-so-great experience for iPhone owners.
The find my network is just an example of local p2p functionality that is largely opaque to users.
iOS devices communicate thru a separate ultra-wideband mesh network used for "Find My" and more recently the AirTags.
If it's in the hands of a legit owner, they just need to type the iCloud password and they're back in. If it was stolen or confiscated, it just became a very expensive brick unless they can coerce the owner to log in somehow.
Also, it would be easy for cops to create a spoofed celular network to keep those phones with reception.
It look like it is based on how long since phone was last unlocked, i would say 1 week is even a big long in this case.. Just a couple of days should be more then enough.
https://chaos.social/@jiska/113447894119816217
That would make sense since thieves know that they have to get an iPhone offline to prevent Find My tracking and remote locking.
People often point out the law enforcement case for breaking into phones but conveniently forget that the very same security holes used by law enforcement are used to make stealing phones more profitable and by other nation-states to spy, commit corporate espionage, etc.
Apple doesn't save your physical SIM PIN, so it would mean leaving your phone untouched for a while would automatically make it unreachable, since you need to enter the SIM PIN after a reboot.
If your phone hasn’t connected to a cellular network in weeks and is locked in a stationary box 23.9 hours a day or more, then I’m not sure I would be surprised if it becomes automatically unreachable in this way eventually — it’s becoming unreachable any time it reboots for an overnight iOS update already, right? so an inactivity reboot isn’t going to have a worse impact than that already does.
(Note that physical SIMs were discontinued in late 2022 models, but it allows you to set an eSIM PIN with the same effect.)
I would guess that most people with only one SIM go with eSIM if they phone supports it.
You can put a PIN on an eSIM, but is there really much point? My understanding is that the main point of a SIM PIN is so that someone cannot transfer your physical SIM to another phone.
Without a PIN someone could steal your phone and even if they could not get past the phone lock they could just move the physical SIM to their phone and thus take over your phone number. They don't even need to steal your phone--they just need access to it for a few seconds to remove the SIM.
That's not the case with eSIM.
You might want a PIN to keep others from making/receiving calls if they have access to your unlocked phone, but because SIMs permanently lock after 3 failed unlock attempts (with no timeout--a mistake today, another a year from now, and another two years after that and it locks) that's probably asking for trouble.
If Apple doesn't make this an official feature, or worse: fixes this issue for the convenience of law enforcement, we need to read that as Apple selling out our privacy to the government.
So they obviously have direct backdoor for the big ones like cia, and they let some wiggle room for 'security' companies that sell 0day exploit to local cops. If they didn't do, there would be lobbies until inevitably they too get their backdoor, which would look bad for apple. It would kill the myth of iphone privacy, any cop could leak about it.
I suspect this is either a bug or a feature that won't really prevent cops from accessing suspect's iphones, they will be annoyed until their 'unlock tool' get updated.
Don't count on Apple to actually fight any government to protect their customer privacy. If they did so, they would never have set up an alternate icloud on CCP controlled server for their Chinese customer, they Would have gone out of Chinese market.
"Forgotten" debugging registers enabled Triangulation exploit against iPhones: https://www.itnews.com.au/news/forgotten-debugging-registers...
"While all of the vulnerabilities were zero-day bugs when patched, one attracted particular attention, because it turned out to be an undocumented hardware vulnerability.
Larin described the bug as “insane”, saying it’s a hardware feature in Apple’s A12 to A16 Bionic system-on-chip (SoC).
The feature, he said, allows attackers to “bypass the hardware-based kernel memory protection” in target iPhones, if they write data to “unknown memory-mapped input-output (MIMO) hardware registers” that Apple’s firmware doesn’t use.
Larin said the research team found six undocumented MIMO addresses used by the Triangulation exploit, which “basically, bypass all hardware-based kernel memory protections”.
He said they appear to be ARM/Apple CoreSight debug registers for GPUs, since they’re nearby identified MIMO registers.
In a statement, Larin said that "due to the closed nature of the iOS ecosystem, the discovery process was both challenging and time-consuming.”
Fwd: Fwd: READ THIS!!! You won't believe what the iPhone does when off network and around other iPhones!!!
> It is believed that the iPhone devices with iOS 18.0 brought into the lab, if conditions were available, communicated with the other iPhone devices that were powered on in the vault in AFU. That communication sent a signal to devices to reboot after so much time had transpired since device activity or being off network.
The hypothesis doesn't make any sense because the phone doesn't need to communicate with other phones to decide to restart/lock based on lack of network signal.
> Matthew Green, a cryptographer and Johns Hopkins professor told 404 Media that the law enforcement officials' hypothesis about iOS 18 devices is "deeply suspect," but he was impressed with the concept.
Just about sums it up.
I know mobile networks keep lists of stolen devices, but they can't be used at all? Like all possible recovery modes demand authentication?
Newer phones for, I want to say maybe the last 5 years, yeah.
If it's turned off and you don't have the code to boot it, you can't access any kind of bootloader or recovery mode, it just shows a screen with an obfuscated email that is required to unlock it or something similar.
Gone are the days of just being able to do a factory reset.
Obviously, the logic board is locked to the owner's Apple account, but so is the display, battery, camera, and selfie camera. Basically the only thing you can reuse is the metal frame of the phone.
Phones are still stolen (since the cost of theft is $0) but stolen phones are worth closer to $5 than $1000.
I have read that there are services offered by specialized criminals to unlock stolen iPhones. These basically amount to phishing schemes where they trick the owner into entering their apple ID and password on a site under their control.
They can then factory reset the iPhone, but they also get to mine the phone/account for crypto, banking details, identity theft, etc.
Potentially the value of a stolen iPhone can be more than the aftermarket price, since draining a bank account has unbounded gain.
Low level thieves are getting $300-$600 for stolen phones.
https://abc7ny.com/amp/crime-spree-phones-stolen-nyc-migrant...
Why do you think iFixit and collaborators are so opposed to serialization of iPhone parts?
They say this while ignoring the generally low crime rates of those compared to peers. For example, Chicago has an almost 20% lower property crime rate than Peoria, IL. Fort Worth, TX has 52% higher property crime rate than New York City. Carmel, Indiana, an affluent suburb with a public high school ranked #354 in the country and 6th in Indiana, only manages to have a 28% better property crime rate than NYC.
(And driving a car around is a lot more statistically dangerous to your life than walking around a big city. I'd rather have my phone stolen than be t-boned by a drunk driver)
Look for “5G NOTAM” if you are someone who thinks this is bunk. Specifically, some radio altimeters (which are needed for some IMC approaches) can be interfered with by the adjacent 5G frequency bands due to not being built with a tight enough filter.
Hence the whole US aircraft fleet was upgraded (by the end of September 2023) so that band could be used for 5G there and it’s no longer a problem.
As I understand it, cellular modems wouldn’t transmit on a frequency if they can’t see a base station (tower) first on that channel, so I expect before the problem was fixed, the temporary solution was just to disable that band at the base stations.
If there was any actual known or suspected risk of electromagnetic compatibility issues with any consumer devices, there would be very strict laws about it (it might become a Federal offence not to have your phone in airplane mode, for example - but obviously it’s not)
Either way, it's about interference with aircraft systems from cellular infrastructure/devices. Certainly, if a tower talking on 5G can interfere with a radio altimeter, a bunch of cellphones onboard could do the same thing or even amplify the effect.
> it might become a Federal offence not to have your phone in airplane mode, for example - but obviously it’s not
Violating directions from the flight crew can be a federal offense. There is a chain of authority from the FAA to the airlines and to the PIC. The airline and PIC delegate part of that authority to the rest of the crew. Unless you are very aware of every regulation and particular company policy, I highly recommend that you don't test this.
That being said, I have heard of a weird automation someone made where it would open an app as soon as they went to the Home Screen. It took some thinking for them to deactivate it because the shortcut was really fast to activate.
You can also ask Siri to reboot or turn off your phone, Siri will ask you to confirm you want to do the action, but it doesn't take too long to do. Just in case you don't want to reach for your phone for what ever reason.
Some keys can still be read, and depending on the exploit they use a lot of data could be extracted. BFU + good passcode is always the way to go.
"Before first unlock", for those like me who weren't familiar with this particular acronym.
Iphones have 2 states when it comes to encryption:
Before First Unlock (BFU) - everything is encrypted. The most difficult state to hack.
After First Unlock (AFU) - data isn’t fully encrypted. Maybe it's for performance reasons. In this state exploits exist which police can use to get data.
Your suggestion of getting to the 'slide to power off' screen does NOT hardlock the phone (it does not put it in BFU).
It just means it requires a passcode. However, since it is in AFU mode, data can be exfiltrated with the right tools.
You should definitely power it down to be secure.
Indefinite contempt of court seems like "force" to me.
https://arstechnica.com/tech-policy/2017/05/jail-looms-large...
I don't think Google is in this same category at all. Didn't they just recently give nest door unlock codes to LEO without even asking for a warrant?
Apple and Google are on different planets when it comes to user privacy.
Did they? I don't remember seeing anything about that.
Apple “helping criminals“ is a gold mine.
I can’t read the full article, but I’d be surprised if the cops didn’t manage to claim how this is somehow related to fentanyl in there somewhere.
The purpose of this is to counter a thief putting your phone into aeroplane mode to prevent you remote locking or erasing the device.
I wonder if that's all this is. Probably a memory leak somewhere or some other bug.
It would be sensible if both these features put the phone into a pre-first-auth mode.
https://support.apple.com/en-us/121161#a181 (last item)
There are fewer groups with so much power who see themselves as downtrodden. I could name others, but that'd be going off-topic.
Imagine the future when neurolink is going to be fully developed and the court would be able to authorise drilling into your skull to forcefully connect you to a computer to read your thoughts. Well, that's not much different.
https://www.reddit.com/r/androidapps/comments/1cscmu8/app_th...
My Xiaomi phone had a feature where it would boot the phone shortly before any alarms would go off, so you could shut it down before bed and barely drain the battery in the mean time. Still required manual shutdowns, though.
1) Keep the alarm data in an insecure location so that app can work before login. (A read only cache is fine)
2) Let me _choose_ if some other apps can live in the insecure storage partition too. E.G. Google Voice comes to mind along with any basic carrier integration stuff you'd rather just have even on a fully locked phone. (Why GV in unlocked? It interacts with the insecure phone network anyway, so that's not exactly holding much back. Maybe make message history harder to get to with a still locked device.)
Set it sufficiently low, and it's a pretty good option to ensure keys are evicted and if you use a SIM pin, it's even better.
Sadly GrapheneOS is only available on recent Pixel devices. I know I'm probably the only one that still cares about these features, but I won't buy a phone that requires me to hot-glue a USB dock to it just to get 3.5mm and microSD if I can simply buy a Sony instead :/
That's why I've been sticking with moto phones. I'd switch to pixel tomorrow if they made one with an audio jack and a micro sd slot.
Locking and disabling biometrics are good ways to add a quick layer of protection, but rebooting makes it incredibly difficult for exploit kits and other hacking tools to dump the contents of a phone's storage.
I'm thinking this may just be a bug (how often does a real world iPhone get zero available networks of any kind? Probably not enough for that use case to be tested thoroughly for days) but with how hard law enforcement is panicking about this, maybe it should be a feature. If they care this much, I don't think their expensive hacking subscription they've bought is working anymore, so it's probably working around some pretty bad vulnerabilities in iOS.
Am I the last person who regularly experinces dead zones, or does this sound crazy?
There's no need to lock the phone just because I'm on the highway at this one spot on the way out of town.
I’m guessing that supply chain is pretty locked down. Sure, a journalist might have obtained one at some point but it won’t be able to phone home and download the latest exploits.
School districts and the like have them, it's not at all locked down. Independent "researchers" can obtain them (and have.)
I read the article about school districts obtaining Cellebrite devices, but I don't think that really refutes what I'm saying. If it was that easy, why wouldn't we see more in-depth analysis of the exploits that UFEDs use?
Other than the Moxie Marlinspike post, I haven't heard of anything recently. Would love to learn more about this topic.
You can stop reading there. iOS 18 doesn't add freaking telepathy to phones. Whether it's a bug or a new feature Apple added that reboots phones under certain circumstances, it's not "iPhones communicating to force reboots".
I'm glad HN doesn't allow emoji, but I do wish I could add :facepalm: or :eye-roll: here.
Edit: I noticed it's "box" and not "cage" but I think the same what-if applies here.
They provide enough attenuation to keep phones off the cellular network and prevent GNSS from working, but not enough to prevent communication with nearby devices via Bluetooth or wifi.
A Faraday cage is an attenuator, which multiplicatively decreases signal strength by some constant (at least within a similar frequency band, which Bluetooth and 5G can be considered to be).
Unless the forensic lab has additional special shielding from cell towers, the received strength of both a reasonably close cell tower and a nearby Bluetooth transmitter would be pretty similar, so they'd both be attenuated similarly.
And while I don't expect stock iPhones to do anything like what's being suggested in the article, I could see custom software activating a "panic mode" based on observations that plausibly suggest a device being in such an environment.
I can say from experience that it is not.
> A Faraday cage is an attenuator, which multiplicatively decreases signal strength by some constant
It's not constant at all. The level of attenuation varies greatly based on frequency. For the Ramsey STE3000 I have here, it varies by 40dB or more at the frequencies at which I've tested it. The enclosure good for around -100dB at 700MHz, but only -60dB or so at 2.4GHz.
> (at least within a similar frequency band, which Bluetooth and 5G can be considered to be).
Even if you exclude mmWave and consider only the sub-6 bands, AT&T for example has LTE and 5G bands from 700MHz to 3700MHz. They're not similar at all. Worlds of difference in terms of propagation characteristics.
> the received strength of both a reasonably close cell tower and a nearby Bluetooth transmitter would be pretty similar
No, they wouldn't.
On my Pixel 8 Pro right now I'm seeing -93dBm from a tower about half a mile down the road (700MHz LTE), and -40dBm from the BLE radio in the HVAC controller on the wall of this room, about 8 or 10 feet away. That's a 53dB difference.
If I put my phone in the box, it attenuates the LTE downlink from down the street to well below the thermal noise floor. It cannot do the same for BLE; my phone can still talk to the HVAC controller from inside.
That's surprising, you'd think those boxes would be better at blocking signals since that's what they're designed to do.
But how is a device in a faraday box receiving this signal and rebooting? And why do they need a signal when they could just use their own clocks and determine that it's been X days or weeks since last going online and reboot?
Doesn’t need to. Being in a Faraday box is a reasonable trigger for a single reboot. That said, the most incredulous part of this story is that iPhones can detect when they’re in a Faraday cage.
Lack of motion? The information the other phones provide are proximity (it’s unusual for people to pile their phones together), that the radios still work and possibly a timeline, e.g. if the other phone says “I’ve been in a suspicious state for two days,” the first phone can change its priors.
I'm even more confident that Apple hasn't spent the research hours required to do that reliably, then incorporate the electronics and software needed into off-the-shelf phones, all to protect criminals from having their phones hacked under very specific conditions. That seems like a huge money sink.
In a zero-signal environment? With other iPhones in very close proximity?
You can even measure your false positive rate by timing to first successful unlock. If it happens more than once, turn down the sensitivity on the feature (or turn it off completely).
(Were I designing this feature, I’d let phones in this state poll the other phones on how long they’ve been in it.)
It automatically reboots after the device hasn't been unlocked within the selected duration, not after certain uptime has been reached
Law enforcement seems to be reading the behavior into the iPhone, which is understandable. They’ve see it before.
The real concern is how law enforcement seems to create these bright lines between “legitimate” and “illegitimate” security.
Shutting down when an attack is suspected is a reasonable security feature.
My guess (and this is just a complete random guess), its a bug not a feature, prob to do with Find My, all the phones are prob airplane mode and they are all trying to talk to each other (and to the mothership) regarding Find My and are crashing out.
If this is brilliant I'm Einstein
What's odd to me in this article is it doesn't seem like faraday bags are being used. I'd assume concerns over this type of thing are greater than ever now.
Cellebrite doesn't have BFU unlocks for any recent iPhone, allegedly.
Could easily just be a memory leak that is accumulating until the OS crashes.
That would be my assumption since they are storing them in labs while trying to crack them under non-normal conditions, so it could easily be a memory leak that doesn't happen under normal conditions. Either that or its the software they use to mess with the encryption causing issues.
If you are not looking at a phone all day, you may not have noticed that the power was out to them over some weekend.
Maybe iPhones just reboot sometimes too.
However, I do think 12 hour "Phone hasn't been unlocked, reboot it" seems logical security feature to add.
I don't have an iPhone, but it's not exactly alien for me to be in a situation where I've gone more than a couple of hours without touching my phone but while it is doing something important: recording where I am. (And, yes, I have fallback options, but they aren't nearly as good.)
If you're going to put in an auto reboot either make it long enough nobody will trip it while the phone is legitimately recording something or make it configurable.
You’re in for a bad time refusing to unlock at most borders.
News: Apple implemented auto-reboot as a security feature fending off cops
Eg: iPhone keeps location and time of found devices via Find My, the cache grows as it's not connected to the network. Eventually restarts...
Maybe the isolated phone has a feature where it reboots after being unable to find a peer?
Makes no sense.
This is absolutely some kind of non-technical user superstition style claim born from a little bit of paranoia that Apple hates cops because they don’t roll over easy (though they do follow subpoenas they are technically capable of following).
This is only happening on phones that are currently locked, but which were previously unlocked since the last reboot.
A reboot of a phone is hardly the end of the word, and it's trivial and obvious to simply have the trigger conditions be slightly less simple and stupid. Like require some user activity. Require the pin again or some other reassurance.
What happens if one is in a place with no connectivity? What indeed? Nothing much. That's what happens.
The article is kind of confusing about this.