It'd work like this: Unlock phone, plug in USB widget; it works.
Or: Plug in USB widget without first unlocking phone; phone shuts down.
I just wonder whether that could be too annoying for Android Auto / Car Play. But to be fair wireless is an option.
The other downside I guess is that a thief would just plug a USB drive in to disable device tracking. But they could just wrap the damn thing in foil so dunno if that should matter.
And by that I mean, using the database itself is simple. But when it exists, then a list of targets for an attacker to emulate also exists.
Those boys at Cellebrite aren't dummies, at all, and they've been doing this stuff for quite a long time. They're a formidable opponent.
We used to use their kit to clone personal data between very different devices back in the dumb phone days. They were the only ones to get it right out of a sea of others that were also evaluated.
When the usual manufacturer-prescribed method for reading contacts said to take some long-winded steps to put the phone into a special mode, Cellebrite's hardware just usually skipped that shit and read the data very directly without any fuss.
Plug it in, push the button, and the Cellebrite box just did the appropriate magic. It then interpreted the data and munged it into a useful form to shove into the next phone.
After that: The recovered personal data was pushed right up into the ass of the next phone with the same lack of consent. It was succinct and brutal in operation.
And: It worked. It was so dead-nuts simple that a cell phone salesperson could run it with ease. I stopped getting phone calls from the field about transfer problems when we started using Cellebrite kit.
Nothing else did this stuff with that measure of resolute nonchalance.
So at this point they've been uniquely hooning with cell phones for decades. It's kind of their schtick.
If we can speculate that something like the the USB-C charge rate negotiation on a given phone can open a pathway into the system, then it can be safe to say that Cellebrite is already using that method to get things done -- and that a person at the border can exploit it even if they're "not a tech person".
Simplifying these kinds of hacks is what they do.
Recognize USB devices by serial numbers, not the manufacturer ID. Even if they could get their hands on the serial number of my car stereo, that's going to be after the same warrant delay this thing protects against.
The lot they tracked you going into? The lot that gets scanned by mobile ALPRs on the regular?
Yeah, so. About that... :-/