Slashdot Mirror


FBI Paid Professional Hackers One-Time Fee To Crack San Bernardino iPhone

There's another new wrinkle in the never-ending FBI vs Apple saga. The Washington Post is claiming that FBI did not require Cellebrite's assistance in hacking San Bernardino iPhone. Instead, the report claims, the government intelligence organization bought a previously unknown security bug from a group of professional hackers. According to the report, the hacker group provided FBI with at least one zero-day flaw in the iPhone 5c's security, which enabled FBI to circumvent the lockscreen and other security features. The bug hasn't been disclosed. FBI has previously noted that the technique it utilized in breaking into the iPhone 5c does not work with any new iPhone models (iPhone 5s or newer).

149 comments

  1. And Vindicated.... by Lumpy · · Score: 5, Informative

    i was telling people that the FBI was lying and Cellbright did not sell them anything to do this...

    Remember kids, DO NOT TRUST law enforcement. they are not there for your protection.

    --
    Do not look at laser with remaining good eye.
    1. Re:And Vindicated.... by bill_mcgonigle · · Score: 4, Funny

      It's OK, the FBI eventually, after it's caught and cornered, tells the truth.

      --
      My God, it's Full of Source!
      OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
    2. Re:And Vindicated.... by Anonymous Coward · · Score: 4, Insightful

      i was telling people that the FBI was lying and Cellbright did not sell them anything to do this...

      Remember kids, DO NOT TRUST law enforcement. they are not there for your protection.

      Neither are the software providers. Apple, Microsoft, Google, Facebook, Amazon, etc. are not there for your protection.

      TRUST NO ONE.

    3. Re:And Vindicated.... by Joe_Dragon · · Score: 4, Funny

      The truth is out there!

    4. Re:And Vindicated.... by Anonymous Coward · · Score: 0

      The truth is out there!

      Walks away.. quietly whistling the theme to the X-files...

      Smoking a cigarette.

    5. Re:And Vindicated.... by UnknowingFool · · Score: 1, Interesting

      I found the timing suspicious at first. Cellebrite's previous known technique was to copy the entire NAND RAM contents then use the copies to repeatedly try the code. That would take a while even with 10000 number combinations.

      --
      Well, there's spam egg sausage and spam, that's not got much spam in it.
    6. Re:And Vindicated.... by umghhh · · Score: 1

      What is the truth?

    7. Re: And Vindicated.... by Anonymous Coward · · Score: 2, Insightful

      The truth is that our tax dollars fund criminals.

    8. Re:And Vindicated.... by phantomfive · · Score: 1

      I've really been wondering lately whether the FBI has ever done anything good. They must have done something, but I can't think of anything good they've done. Maybe stop some bank robbers in the early 1900s?

      --
      "First they came for the slanderers and i said nothing."
    9. Re:And Vindicated.... by Anonymous Coward · · Score: 0

      NO! They don't.

    10. Re:And Vindicated.... by cellocgw · · Score: 2

      What is the truth?

      Paul Pierce, of course.

      And another person wrote:

      Since they have changed their "post-hack" story at least once,

      So, you're saying they made a post-hac change to the post-hack story? //rimshot

      --
      https://app.box.com/WitthoftResume Code: https://github.com/cellocgw
    11. Re:And Vindicated.... by Anonymous Coward · · Score: 0

      "Never trust advice you didn't pay for." "The only people on your side are the ones you bought."

      And even then. When you're lucky, it's merely capitalism being capitalism and the exploitation isn't malicious, just "good business".

    12. Re:And Vindicated.... by wonkey_monkey · · Score: 3, Insightful

      That would take a while even with 10000 number combinations.

      I hear they have computers that can count up to 10000 now.

      --
      systemd is Roko's Basilisk.
    13. Re:And Vindicated.... by ravenshrike · · Score: 1

      Whistling and smoking a cigarette at the same time? Clearly an alien.

    14. Re:And Vindicated.... by Anonymous Coward · · Score: 0

      Very apt handler. Congrats!

    15. Re:And Vindicated.... by Anonymous Coward · · Score: 0

      Agreed. CAN'T TRUST EM AT ALL.

      It's why anytime some PIG is directing traffic due to a traffic light malfunction, I don't heed his commands and instead try to run him over.

      Don't need no government-mandated SYSTEM telling me HOW and WHEN to go through an intersection.

      It's MY LIBERTY to choose HOW and WHEN, thank you.

      Remember kids: "He who would trade liberty for some temporary security, deserves neither liberty nor security."

    16. Re:And Vindicated.... by EETech1 · · Score: 1

      You can't HANDLE the TRUTH!!!

    17. Re:And Vindicated.... by UnknowingFool · · Score: 1
      Well considering their technique would require
      1. trying 10 codes
      2. de-solder the chip
      3. re-flash the chip
      4. re-solder the chip
      5. repeat step 1

      That would take a long time.

      --
      Well, there's spam egg sausage and spam, that's not got much spam in it.
    18. Re:And Vindicated.... by antdude · · Score: 1

      Trust no one.

      --
      Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
    19. Re:And Vindicated.... by Anonymous Coward · · Score: 0

      Worse than that, the delay after each attempt still kicks in, so you may want to to switch chips after 5-7 attempts, that's 1400-2000 switches for a 4 digit code.

      On the plus side any sane person would connect the print to a socket for the proper chip type and just switch the chip in the socket.
      Way quicker and less likely to damage the print. Un- and resoldering the chip(s) a few times is ok, after few dozen times it becomes a question of when something breaks in an unfixable way. 1000+ times is just insanity.

      And this method requires that all data related to the failed login timer is stored in the main flash.
      SOCs nowadays often have a relatively small onchip Flash/EEProm etc for boot sw, serial & other id / service info.
      Apple's data on their chips remains somewhat - ahem - sparse, so who knows exactly what's in it.
      Also the phone module, GPS module, WIfi module etc may offer the ability to store data...

      If Apple thought this through replacing the flash will not be enough

      Also:
        1) the FBI did not at any tiume claim that CellBrite was the other party, that was random press speculation
        2) CellBrite made no claim to use a particular method or apparently comment at all. Again random press speculation

    20. Re:And Vindicated.... by wonkey_monkey · · Score: 1

      On the plus side any sane person would connect the print to a socket for the proper chip type and just switch the chip in the socket.

      Couldn't they even switch the chip between the board and the flasher electronically?

      --
      systemd is Roko's Basilisk.
    21. Re:And Vindicated.... by Anonymous Coward · · Score: 0

      What is the truth?

      It's like poetry. Most people fucking hate poetry.

    22. Re:And Vindicated.... by UnknowingFool · · Score: 1
      Cellbrite could speed up the process by using some sort of board/interface between the flash chip and iPhone board; however, I don't know if Apple's hardware protection would defeat that setup. It would reduce the steps to:
      1. Try 10 codes
      2. Reset to previous position (maybe a reboot of iOS)
      3. Repeat

      Still a tedious process.

      --
      Well, there's spam egg sausage and spam, that's not got much spam in it.
    23. Re:And Vindicated.... by Lumpy · · Score: 1

      dont have to desolder and resolder the chip.. Desolder existing chip, solder on advanced chip simulator connection. Run phone using the simulator hardware and reset image every attempt. It's not hard at all to have a modern PC completely simulate a chip with some extra hardware. Hell an FPGA could do the job easily.

      --
      Do not look at laser with remaining good eye.
    24. Re:And Vindicated.... by UnknowingFool · · Score: 1

      It would still take a while to go through the combinations. A few weeks. I was suspicious that it took a few days (including time to get the phone to Cellebrite).

      --
      Well, there's spam egg sausage and spam, that's not got much spam in it.
    25. Re:And Vindicated.... by Coren22 · · Score: 1

      Hard to lie when you don't say anything. The FBI using Cellebrite's service was only ever a rumor, they never actually said they used them. I know the Slashdot article indicated it was the way it happened, but other news sources listed the connection as presumed.

      http://www.bbc.com/news/world-...

      If you read the article carefully, an Israeli newspaper said Cellebrite helped the FBI, the FBI did not state that, nor did Cellebrite.

      --
      APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
    26. Re: And Vindicated.... by Anonymous Coward · · Score: 0

      Not even my mother?

  2. Hire a criminal? by Anonymous Coward · · Score: 0

    Sounds legit to me!

    1. Re:Hire a criminal? by Kkloe · · Score: 2

      how is someone selling a bug exploit to someone else illegal?, or are you assuming everyone who calls themselves hackers are doing illegal stuff and have found the exploits illegally?

    2. Re:Hire a criminal? by Iamthecheese · · Score: 1

      He's saying they're lying again. Them money given to the "professional hacking group" was sent to a slush fund and Apple probably updated the individual phone's firmware to allow the crack, something they can do on any other iphone.

      --
      If video games influenced behavior the Pac Man generation would be eating pills and running away from their problems.
    3. Re:Hire a criminal? by Wycliffe · · Score: 1

      how is someone selling a bug exploit to someone else illegal?, or are you assuming everyone who calls themselves hackers are doing illegal stuff and have found the exploits illegally?

      If they are selling it on the open market to the highest bidder without vetting who they are selling it to then yes they are a criminal too.

    4. Re:Hire a criminal? by Frosty+Piss · · Score: 1

      If they are selling it on the open market to the highest bidder without vetting who they are selling it to then yes they are a criminal too.

      How so? What laws are being broken?

      --
      If you want news from today, you have to come back tomorrow.
    5. Re:Hire a criminal? by Anonymous Coward · · Score: 0

      how is someone selling a bug exploit to someone else illegal?

      DMCA?

    6. Re:Hire a criminal? by Wycliffe · · Score: 1

      If they are selling it on the open market to the highest bidder without vetting who they are selling it to then yes they are a criminal too.

      How so? What laws are being broken?

      They've already fought this is court many times. They can get you for aiding a criminal. They use it all the time in the war on drugs. They bust contractors for digging tunnels and installing secret compartments in cars even if the person didn't ever touch the drugs.

    7. Re:Hire a criminal? by whh3 · · Score: 1

      What they did is in violation of the DMCA -- not that I agree with the DMCA, but the law is the law. Malum prohibitum -- they are criminals.

      Will

      --
      remove nospam. to email!
    8. Re:Hire a criminal? by Kkloe · · Score: 1

      There is a law here that says that you can get charged for making someone angry, yes that is a law, in practice someone can report you to the police for walking inside your own home becuase that made them angry, does it mean I am a criminal because I am potentially making someone angry for walking inside my own home?

      same thing here, I can potentially be charged for aiding a criminal but that doesnt mean that I am a criminal before when I did not

    9. Re:Hire a criminal? by Kkloe · · Score: 1

      doesnt i depends on where they sold it?, just becuase the fbi bought it doesnt mean they bought the fix in the us and thus the DMCA would not apply

    10. Re:Hire a criminal? by Kkloe · · Score: 1

      doesnt i depends on where they sold it?, just becuase the fbi bought it doesnt mean they bought the fix in the us and thus the DMCA would not apply, same answer as above

    11. Re:Hire a criminal? by Wycliffe · · Score: 1

      There is a law here that says that you can get charged for making someone angry, yes that is a law, in practice someone can report you to the police for walking inside your own home becuase that made them angry, does it mean I am a criminal because I am potentially making someone angry for walking inside my own home?
        same thing here, I can potentially be charged for aiding a criminal but that doesnt mean that I am a criminal before when I did not

      That's like saying that you bear no responsibility for selling weapons, bomb making material, or nuclear material to ISIS. If you have good reason to suspect that what you're selling is going to be used by a criminal to do a crime then that makes you a criminal or at least an accomplice. Sure there are neutral cases like selling a hunting rifle that later is used in a crime but there are also cases where there's a high probability that the other person is a criminal and you shouldn't participate in the transaction. This goes for engineers too. If you are asked to design a product whose primary purpose is likely to be criminal then you shouldn't participate.

    12. Re:Hire a criminal? by Kkloe · · Score: 1

      So whats the harm of finding bugs in a software\hardware?, why is it criminal?, there are alot of people that do that and then tell the companies for rewards, they could have read about the phone in the news and then later decided to find some vulnerability to sell to the fbi only, is that criminal?

  3. Skeleton Key by Anonymous Coward · · Score: 0

    "Please do not change the lock on your door. I assure you my key with a skeleton on it is not actually a skeleton key. Trust me."

  4. Evidence by Anonymous Coward · · Score: 0

    How can the evidence have integrity at that rate? I know being of an upright and legal nature is hardly a concern for Big Brother anymore but that's just crazy to me.

    1. Re:Evidence by ChrisMaple · · Score: 4, Insightful

      The story is that the FBI was looking for a contact list: people or organizations to be considered for further investigation. If such a list contained Joe's Pizza, Al's Garage, and 9 people named Mohammed, some of that list is likely to be terrorist related.

      It's a question of looking for likely suspects, and being on the list is by itself not evidence of guilt.

      --
      Contribute to civilization: ari.aynrand.org/donate
    2. Re:Evidence by boristdog · · Score: 2, Insightful

      being on the list is by itself not evidence of guilt.

      You keep telling yourself that when your contact info shows up on a suspected terrorist's phone and you are hauled off for extensive interrogation.

    3. Re:Evidence by Anonymous Coward · · Score: 1

      Have you had Joe's Pizza? It's so good it should be criminal.

    4. Re:Evidence by Anonymous Coward · · Score: 2, Insightful

      If such a list contained Joe's Pizza, Al's Garage, and 9 people named Mohammed, some of that list is likely to be terrorist related.

      Considering how common the name Mohammed is, your statement could read:

      If such a list contained Joe's Pizza, Al's Garage, and 9 people named John, some of that list is likely to be terrorist related.

      and be just as meaningless. Unless you know something about Joe's Pizza that you're not telling the rest of us.

    5. Re:Evidence by phorm · · Score: 1

      And they couldn't get that information from the telecommunications provider?

    6. Re:Evidence by Anonymous Coward · · Score: 1

      To be fair it's actually pretty weird to know 9 separate people named John and even weirder to have only them and a couple small local businesses in you phone contacts.

    7. Re:Evidence by Anonymous Coward · · Score: 0

      Also text messages and other digital content that leaves no user to user traces.

    8. Re:Evidence by dissy · · Score: 1

      How can the evidence have integrity at that rate?

      The story is that the FBI was looking for a contact list

      The contact list as evidence is sound and has a full chain of custody.

      The state department that owns the phone asked the FBI to request the last iCloud backup from Apple, which Apple provided the next day.
      That was at least one if not two weeks before the FBIs request to decrypt the phone.

      In fact the FBI had in their posession the entire iCloud backup (All contacts, SMS and iMessage destinations, all apps installed, all photos and music data, etc)
      From the phone company the FBI had full call records, recorded call contents (thanks AT&T!), plus all SMS destinations and the contents.

      They were also fully aware he didn't even try to wipe his work phone, in fact he left it on his desk at work before doing his killing spree thing. Didn't even try dropping it on the floor or using the microwave trick or anything.

      His personal iPhone however was fully wiped and factory reset, no iCloud backup ever made, and was physically destroyed and recovered in many pieces.

      It would take an FBI agent to not realize where the incriminating evidence was actually stored...

    9. Re:Evidence by TimSSG · · Score: 1
      Not if you are from the 8th Dimension. Tim S.

      To be fair it's actually pretty weird to know 9 separate people named John and even weirder to have only them and a couple small local businesses in you phone contacts.

      .

    10. Re: Evidence by Lije+Baley · · Score: 1

      These kids today don't remember the Lectroid invasion...

      --
      Strange things are afoot at the Circle-K.
    11. Re:Evidence by Anonymous Coward · · Score: 0

      yes, because no obviously deranged mass murderer has ever made a mistake!

    12. Re:Evidence by farble1670 · · Score: 1

      You keep telling yourself that when your contact info shows up on a suspected terrorist's phone and you are hauled off for extensive interrogation.

      Fine with me. I either know nothing which I invite them to verify, or I do know something and I will readily share with them since I'm not a fan of terrorists.

    13. Re:Evidence by Anonymous Coward · · Score: 0

      You keep telling yourself that when your contact info shows up on a suspected terrorist's phone and you are hauled off for extensive interrogation.

      Fine with me. I either know nothing which I invite them to verify, or I do know something and I will readily share with them since I'm not a fan of terrorists.

      You do know that "verification" involves chaining your wrists to your ankles and sitting you on a low stool right? Even if you eventually prove not guilty you become too dangerous to release. Kind of the modern day equivalent of throwing you in a pond to see if you're a witch - if you drown you're innocent.

      The only way to win is not to play.

  5. Find what they were looking for? by Anonymous Coward · · Score: 0

    After all this drama, there better be some new Jennifer Lawrence nudes on that phone.

    1. Re:Find what they were looking for? by __aaclcg7560 · · Score: 1

      It will be something more embarrassing than that: cat videos.

    2. Re:Find what they were looking for? by UnknowingFool · · Score: 5, Informative

      Unlikely. It was Farouk's work phone, and he and his wife had personal phones. Before the attack, he and his wife made sure to destroy their personal phones. They left this one alone so either he forgot about it or there was nothing on it worth destroying. Even Bernandino County officials admitted they suspected the phone had little information on it.

      --
      Well, there's spam egg sausage and spam, that's not got much spam in it.
    3. Re:Find what they were looking for? by Anonymous Coward · · Score: 0

      Even Bernandino County officials are scared their names are on that phone and have to explain multiple times to multiple organizations that they had nothing to do with his activities...

    4. Re:Find what they were looking for? by Anonymous Coward · · Score: 0

      I would like to have them announce if they did or did not find the terrorist "evidence" that "must" have been on the phone that "required" a back door.
      Hey FBI, was it worth it?

  6. Freaking Butthurt Idiots by wkwilley2 · · Score: 1

    In two weeks they'll come out and say that the phone was never cracked at all and that they just wanted to set a precedent.

    Just kidding, why would they lie. /s

    --
    Have you ever fallen asleep at the keybhanusdiog?
  7. proving the point: by Anonymous Coward · · Score: 3, Insightful

    if these guys can do it, and the FBI can now do it, then ANYONE can do it. The chinese, north korea, data theives -

    and the american government wants to force companies to put shit like this in their software on PURPOSE?

    1. Re:proving the point: by Creepy · · Score: 1

      According to the article, they had to craft specific hardware to retrieve the PIN and I'm guessing you need to not only possess the phone, but pull it apart to use this exploit. I had a suspicion that the firmware security in that phone could be exploited with a hardware hack and it turns out that is true. From the sound of it, a remote exploit isn't possible using the method described.

    2. Re:proving the point: by Anonymous Coward · · Score: 0

      According to the article, they had to craft specific hardware to retrieve the PIN and I'm guessing you need to not only possess the phone, but pull it apart to use this exploit. I had a suspicion that the firmware security in that phone could be exploited with a hardware hack and it turns out that is true. From the sound of it, a remote exploit isn't possible using the method described.

      Horseshit! They diddled a few bits of a copy of a firmware upgrade (so it would fail the integrity test), pulled the battery, connected it to a PC running iTunes, and powered up the phone forcing it into DFU mode on boot. No PIN needed.
      But don't take my word for it (trust me, I, Demonoid Penguin, should not be trusted) do your own research - maybe I'm not making this shit up.

      When they tell you it was terribly difficult you can usually bet it was simple. When their lips move you know they are lying.

  8. I know!!! by Lab+Rat+Jason · · Score: 3, Funny

    It was John McAfee! The FBI didn't admit it because they still want to see him eat a shoe!

    --
    Which has more power: the hammer, or the anvil?
    1. Re:I know!!! by Anonymous Coward · · Score: 0

      He's such a loon you could probably offer him 50 cents and he'd eat a shoe.

    2. Re:I know!!! by Anonymous Coward · · Score: 0
  9. FBI can, but you cannot. by Parker+Lewis · · Score: 1

    Do the same (pay a hacker to break a giant's product) and go to jail.

    1. Re:FBI can, but you cannot. by Anonymous Coward · · Score: 0

      There's illegal, and then there's illegal, Obama would be proud.

    2. Re:FBI can, but you cannot. by Anonymous Coward · · Score: 1

      The warrant is what makes it legal. With a warrant the FBI can legally ransack someone's house. Do the same without a warrant and you're called a burglar and you may go to jail.

    3. Re: FBI can, but you cannot. by Anonymous Coward · · Score: 0

      Gets to wondering if the hack broke the terms of the EULA...

    4. Re:FBI can, but you cannot. by Anonymous Coward · · Score: 0

      There's illegal, and then there's illegal, Obama would be proud.

      "Theres classified and then theres classified"... Barack Hussain Obama

    5. Re:FBI can, but you cannot. by Anonymous Coward · · Score: 0

      Yeah, we get get it.

    6. Re: FBI can, but you cannot. by zlives · · Score: 1

      warrant covers all.

  10. no day didn' by turkeydance · · Score: 1

    jes sayin'

  11. Undercover AD? by Anonymous Coward · · Score: 1

    "FBI has previously noted that the technique it utilized in breaking into the iPhone 5c does not work with any new iPhone models (iPhone 5s or newer). "
    GO GET ONE!!! (And we already broke 5s, so don't bother expecting better provacy)

  12. Arn't they? Oh ok. by Viol8 · · Score: 1, Insightful

    So tell us great sage, who should we turn to for help against criminals, Apple?

    1. Re:Arn't they? Oh ok. by wvmarle · · Score: 0, Flamebait

      Get a gun, be your own cop. Shoot first, ask questions later, That's the American way, no?

    2. Re:Arn't they? Oh ok. by Anonymous Coward · · Score: 0

      Only if you've forgotten your lock screen code and want the FBI to unlock it for you...

    3. Re: Arn't they? Oh ok. by Anonymous Coward · · Score: 0

      Shoot first, think never.

    4. Re:Arn't they? Oh ok. by Anonymous Coward · · Score: 0

      So long as you are operating within the confines of the law then yes it is. I Carry both open and concealed as well as have numerous firearms of various types in my home.

    5. Re: Arn't they? Oh ok. by Anonymous Coward · · Score: 1

      Lol somebody mod this funny.

    6. Re:Arn't they? Oh ok. by phantomfive · · Score: 0

      So tell us great sage, who should we turn to for help against criminals,

      You probably have no recourse. If someone breaks into your house, the police aren't even going to take fingerprints, if they even come out at all.
      If you get death threats, the police will tell you they can't protect you. They have no legal obligation to do so.

      --
      "First they came for the slanderers and i said nothing."
    7. Re:Arn't they? Oh ok. by rgbatduke · · Score: 4, Interesting

      This is precisely my experience. Every time I've been broken into and called the police, a bored looking cop comes out, takes a statement, looks at the point of entry and then leaves, never to be heard from again. They only do this much so you can file your insurance, if you are stupid enough to file your insurance (since the insurance company will then just upgrade your risk and raise your rates enough to cover your payout plus an indefinite bleed of additional profit for them for the rest of eternity. No fingerprints. No searching area fences or eBay for your lost goods. No questioning likely suspects. If they are feeling enormously helpful, they may suggest that you get the broken lock fixed as the bad guys might come back and steal some more, and no, they aren't going to stake the joint out to find out.

      Law enforcement is almost non-existent. Police are often called on to "keep the peace" -- to intervene in potentially dangerous situations involving human conflict or risk -- but they don't go out of their way to arrest anybody even then. They do arrest shoplifters, but that is because there is usually hard evidence and the perps are caught in the act. They do arrest anybody who rubs drug usage in their face and spend at least some time arresting the merely unwary. They do a decent job at pulling drunk drivers, when they catch them for obvious driving errors. Outside of that, by far -- far -- my most common interaction with Law Enforcement is getting pulled with a car tag a month out of date. Damn, they are hell on car registration. Makes me feel safe at night, knowing that no scofflaw is able to drive around without properly registered tags, unless of course they are an illegal alien without any driver's license or insurance at all driving a company truck.

      Sigh.

      The two laws that get en

      --
      Even when the experts all agree, they may well be mistaken. --- Bertrand Russell.
    8. Re:Arn't they? Oh ok. by phantomfive · · Score: 1

      The only way I know to get police to act is to have your lawyer contact them. It's really frustrating, actually.

      --
      "First they came for the slanderers and i said nothing."
    9. Re:Arn't they? Oh ok. by Anonymous Coward · · Score: 0

      Only if you've forgotten your lock screen code and want the FBI to unlock it for you...

      Um, wasn't the phone unlocked to begin with - then some fuckwit in the police locked it. Which conveniently justified the FBI demanding that Apple allow them to be able to unlock any iPony.

      Now the FBI is offering it's unlocking services to police departments..... no power play there. Quick, someone dig up Hoover and buy him a new party dress.

    10. Re:Arn't they? Oh ok. by Lumpy · · Score: 1

      Winchester.

      --
      Do not look at laser with remaining good eye.
    11. Re:Arn't they? Oh ok. by cwsumner · · Score: 1

      The police are there to arrest criminals, but you are responsible for your own safety.

      Call the police when you see criminals that they can arrest, but be prepared to defend yourself until they can get there.

      It's supposed to be a team effort...

      And, "Trust but verify".

  13. Wait for it by Varenthos · · Score: 1

    Give them a little time - assuming the phone has actually been cracked - and they'll come out and say that they found all kinds of terrorism-related material on the phone. Then they'll start telling us that this is why we shouldn't be able to have encryption or privacy and restart the fight to get laws passed banning it, because terrorism and for the children.

    1. Re:Wait for it by zlives · · Score: 1

      the WMD's were on hiding this phone!!! i knew it.

  14. Why did FBI claim they would start helping police? by JoeyRox · · Score: 4, Interesting

    After they "cracked" the San Bernardino phone the FBI publicly came out and said they would use the information they gleaned to start assisting local law enforcement agencies to crack iPhones for their cases as well. I guess that was a bold-face lie, told to make Apple look bad to their security-conscious customers who are concerned that the FBI now has the ability to crack iPhones.

  15. Did they call The Hackers R Us Store? by Bob_Who · · Score: 1

    I really wonder which hackers they hired... someone they are investigating, or just a dark web personal ad from Estonia. The more they say the more idiotic they sound. The FBI sounds as inefficient as the TSA and Congress. A bunch of blowhards with authority that can't get the job done properly because nobody trusts or likes how they operate. Public servants that are always at odds with the public, and never have any good news to report. Nevertheless, never getting the job done is the only job security that exists anymore.

    1. Re:Did they call The Hackers R Us Store? by Anonymous Coward · · Score: 0

      I would imagine it was one of John McAfee's friends/acquaintances -- since he was so being so loud about helping The Bureau out.

    2. Re:Did they call The Hackers R Us Store? by macs4all · · Score: 3, Interesting

      I really wonder which hackers they hired... someone they are investigating, or just a dark web personal ad from Estonia. The more they say the more idiotic they sound. The FBI sounds as inefficient as the TSA and Congress. A bunch of blowhards with authority that can't get the job done properly because nobody trusts or likes how they operate. Public servants that are always at odds with the public, and never have any good news to report. Nevertheless, never getting the job done is the only job security that exists anymore.

      Since they have changed their "post-hack" story at least once, I submit that the FBI either already had the phone hacked (sans Apple's help), OR they never DID get into the phone (more likely); but needed a plausible excuse to sabotage their own legal efforts, since it was pretty clear that the Court case was NOT going to go their way, and they didn't want to set THAT Precedent.

    3. Re:Did they call The Hackers R Us Store? by Anonymous Coward · · Score: 0

      They wanted an out because they did not want a legal precedent set that looked like it was going against them. Simple as that.

    4. Re:Did they call The Hackers R Us Store? by macs4all · · Score: 1

      They wanted an out because they did not want a legal precedent set that looked like it was going against them. Simple as that.

      Do you have your half-duplex switch set correctly? There seems to be an echo in here.

    5. Re:Did they call The Hackers R Us Store? by Bob_Who · · Score: 1

      They wanted an out because they did not want a legal precedent set that looked like it was going against them. Simple as that.

      Do you have your half-duplex switch set correctly? There seems to be an echo in here.

      I think that's how everything sounds to the Feds. It's a cacophony of echos and feedback loops, like a church choir warming up backstage.

  16. The Feinstein effect applied to hacks! by Anonymous Coward · · Score: 0

    A hack for me but not for thee!

  17. Sure, we believe you. by Anonymous Coward · · Score: 0

    FBI has previously noted that the technique it utilized in breaking into the iPhone 5c does not work with any new iPhone models (iPhone 5s or newer).

    I wouldn't believe a single word from these assholes.

    1. Re:Sure, we believe you. by Maritz · · Score: 1

      Yeah. As a general rule of thumb, I would expect reality to be roughly the opposite of what they claim.

      --
      I do not want your cheap brainburning drugs. They are useless for work. And I am a working man today.
    2. Re:Sure, we believe you. by macs4all · · Score: 1

      FBI has previously noted that the technique it utilized in breaking into the iPhone 5c does not work with any new iPhone models (iPhone 5s or newer).

      I wouldn't believe a single word from these assholes.

      I wouldn't either; but it is true that after the 5c, all iPhones have the "Secure Enclave" chip, and thus are MUCH harder to crack. So, it is at least plausible.

  18. NAh it ws a two-fer for the fbi by Anonymous Coward · · Score: 1

    They then arrested the cracker for DMCA violations and got their money back through civil forfeiture. Whilst at the same time being able to claim they reduced computer crime and cut off funding to terrorists and strike a blow against child pornography rings.

  19. Re:Why did FBI claim they would start helping poli by Anonymous Coward · · Score: 1

    They paid a one time fee for an exploit. That exploit could in theory work on any iPhone 5c (unpatched), and there are plenty of those waiting around in evidence lockers.

    If the article stated somewhere that the FBI paid for a one-time crack only, not the exploit itself (which is stupid beyond belief for a government agency) then I'm sorry.

  20. Re:Why did FBI claim they would start helping poli by wvmarle · · Score: 2

    and a potential boon for Apple as all these customers still using last year's model now have to upgrade to this year's models!

  21. You actually did it John, you magnificent bastard. by Anonymous Coward · · Score: 0

    So, McAfee was right. He really could have hacked that iphone the whole damn time... well, not him, but the hackers he hires.

    Actually... are we sure he wasn't the one to hack it?

  22. Re:Why did FBI claim they would start helping poli by Anonymous Coward · · Score: 0

    bold-face lie

    I prefer my lies to be italicized...it blends in better than bold.

  23. Treason? by Anonymous Coward · · Score: 0

    So they know about a 0-day vulnerability and are not protecting their country, citizens, allies? Treason!

  24. Re:Why did FBI claim they would start helping poli by UnknowingFool · · Score: 1

    And the information they'll provide is: "Here use these guys. Don't tell anyone who you paid."

    --
    Well, there's spam egg sausage and spam, that's not got much spam in it.
  25. Ethics kick in on this one. by TheHawke · · Score: 3, Interesting

    You know the director will be dragged in on the carpet by congress on the ethics of using hackers at this level.

    If they paid them using gov't funds, lets hope they kept track of the funds used.

    --
    First rule of holes; When in one, stop digging.
    1. Re: Ethics kick in on this one. by Anonymous Coward · · Score: 0

      You know better. The hackers didn't get paid. These hackers were probably facing jail time for something unrelated and the FBI threw them a bone. Hack this for us and we forget what you did happend. Classic matrix scenario. Neo had a huge hacker file. I'd bet it was him.

    2. Re: Ethics kick in on this one. by Anonymous Coward · · Score: 0

      You know better. The hackers didn't get paid. These hackers were probably facing jail time for something unrelated and the FBI threw them a bone. Hack this for us and we forget what you did happend.

      As if the FBI could put a gun to some hacker's head and demand that they discover a previously unknown flaw that allows them to accomplish a highly specific task. Doubtful.

      More likely, they bought the hack on the black market or otherwise quietly and this wasn't the first time they have done so.

    3. Re:Ethics kick in on this one. by Anonymous Coward · · Score: 0

      What are we going to call this one? 2 F4$t 2 fUr!0u$?

    4. Re: Ethics kick in on this one. by TheHawke · · Score: 1

      They were paid on this one as "consultants" and that comes under the auspices of the GAO and the bean-counters that reside there. Everyone in big government is held accountable, ranging from the d-bag EPA rep up in Alaska to the Oval Office desk-polisher. Keep your receipts and anything over a certain amount requires additional approval!

      --
      First rule of holes; When in one, stop digging.
  26. Do they have a warrant? by MrKaos · · Score: 1

    Because encryption alone won't stop the state, who will find a way to get in somehow. Especially considering they have access to all the other data products a telecommunications device like a phone produces, without needing one.

    --
    My ism, it's full of beliefs.
  27. Re:Why did FBI claim they would start helping poli by Anonymous Coward · · Score: 0

    Not at all. This whole thing was one big security circus. Apple got tons of free press and saved it's face, FBI got what it wanted - a precedent. An local police has a new best friend.

    Only one who got fucked in this deal is you, dear tax payer.

  28. Re:Why did FBI claim they would start helping poli by macs4all · · Score: 1

    They paid a one time fee for an exploit. That exploit could in theory work on any iPhone 5c (unpatched), and there are plenty of those waiting around in evidence lockers.

    If the article stated somewhere that the FBI paid for a one-time crack only, not the exploit itself (which is stupid beyond belief for a government agency) then I'm sorry.

    Actually, that was one of Apple's less-successful models in terms of sales numbers. So, I would imagine that, while there are undoubtedly some in evidence rooms, they are not as prevalent as some of the other models.

  29. Re:Why did FBI claim they would start helping poli by macs4all · · Score: 2

    and a potential boon for Apple as all these customers still using last year's model now have to upgrade to this year's models!

    The 5c was three revisions ago at this point. Do try to keep up.

  30. Re:Why did FBI claim they would start helping poli by macs4all · · Score: 2

    Not at all. This whole thing was one big security circus. Apple got tons of free press and saved it's face, FBI got what it wanted - a precedent. An local police has a new best friend.

    Only one who got fucked in this deal is you, dear tax payer.

    You're so full of shit it's running out of your ears.

    Apple got as much negative press as positive. Maybe more. There are a BUNCH of people that still think that Apple is marketing to Terrists. THAT kind of publicity really DOESN'T fall under the adage of "Any publicity is good publicity."

    Also, the FBI got NO legal precedent. They FOLDED, right before they were going to court for that, probably because the Amicus Curiae Briefs and even some really high-up Government Officials in the Intelligence Sector in support of Apple were piling up as high as the sky, and the FBI was AFRAID of the "Precedent" they WERE going to set...

  31. Useful information? by ikirudennis · · Score: 2

    My question is: Have they said whether they found useful information on the phone? (Not that I necessarily trust them to answer that truthfully at this stage.)

  32. Re:Why did FBI claim they would start helping poli by Anonymous Coward · · Score: 0

    A lot of people don't give a shit about this kind of minutiae.

  33. A valid question by Anonymous Coward · · Score: 0

    If the 5C were hacked, what, if any, information did they obtain from the phone. People assumed and led to believe that Cellurite provided the exploit, now we hear that is not the case at all.

    So, was the phone's security actually breached or not? And, given the similarity between the 5C and 5S, it should enable Apple to compare differences in the HW and SW to identify the possible vulnerable areas. That is, of course, assuming that a breech did occur and the exploit only works on the 5C.

  34. What did they find? by Anonymous Coward · · Score: 0

    Notice the FBI hasn't said what, if anything, it found on the phone. They are probably keeping tight-lipped because they found nothing, and don't want to be known as the organization who raised a giant stink over nothing.

  35. Re:Why did FBI claim they would start helping poli by budgenator · · Score: 1

    As likely as not a bald-faced lie to make Apple look good. They can probably hack into any Iphone now, but made a big show about a legal case against Apple and now to buy an exploit into an almost obsolete phone as a distraction. People especially bad actors will stay with Apple thinking they are secure.

    --
    Apocalypse Cancelled, Sorry, No Ticket Refunds
  36. Remember: It can be as simple as cutting the power by SB5407 · · Score: 1

    Keep in mind that the exploit could be as simple as brute forcing the PIN and cutting the power after each unsuccessful attempt: http://blog.mdsec.co.uk/2015/0...

    At the machine's rate of one PIN every 40 seconds, that's only about 111 hours to brute force a 4 digit PIN.

  37. Pretty sure they did illegal activities... by Anonymous Coward · · Score: 0

    while completing that task too.

  38. Re: Why did FBI claim they would start helping pol by Type44Q · · Score: 1

    Do try to keep up.

    And the benefit in doing that would be...?

  39. Re:Why did FBI claim they would start helping poli by Anonymous Coward · · Score: 0

    A shill? They asked for a one time use decrypter, to access a phone. They got one, specially designed for the one phone. Now, it still cannot be used as evidence, or a ploy for investigation. They, meaning the FBI, got what they paid for. Now they will have to find someone smart enough in the fbi, to do the same, Just because they have the phone open now, does not mean its fbi good evidence, what has the phone done since then? updated, Its not good evidence then. Something has been added to the phone, what? Bad evidence. But, it shows that apple is rotten to the core with ego. we are so good, blah, blah, blah. but someone took two weeks and came in with proof it can be done? What is everyone else missing then? security.

  40. Re:Why did FBI claim they would start helping poli by R3d+M3rcury · · Score: 1

    So...about a year-and-a-half, then.

  41. Re:Why did FBI claim they would start helping poli by Agent0013 · · Score: 1

    But it also needed some custom hardware created to make use of the exploit. So unless they are going to build hardware for all the police departments out there, or have them send the phones off to the FBI, it isn't going to do much good.

    --

    -- ssoorrrryy,, dduupplleexx sswwiittcchh oonn.. -Quote found on actual fortune cookie.
  42. Re:Why did FBI claim they would start helping poli by Agent0013 · · Score: 1

    The lying they did and folding at the last minute should count as precedent anyway. The next judge should say to the FBI, "you lied to the court last time about a large number of things. dismissed with prejudice!".

    --

    -- ssoorrrryy,, dduupplleexx sswwiittcchh oonn.. -Quote found on actual fortune cookie.
  43. Re:Why did FBI claim they would start helping poli by macs4all · · Score: 1

    So...about a year-and-a-half, then.

    Nope, sorry.

    The iPhone 5C was released in September, 2013.

    The iPhone SE (which is the closest thing to an heir-apparent to the 5C, and is also the most-recent model) was shipped in the U.S. and several other countries starting on March 31, 2016.

    By my estimation, that is around 2 1/2 years. And in that time, there has been the 5s, the 6 and the 6s in between the 5C and the SE. So that actually sounds like FOUR revisions, not even counting concurrent variants, like the 6 plus and the 6s plus.

  44. Re:Why did FBI claim they would start helping poli by macs4all · · Score: 1

    The lying they did and folding at the last minute should count as precedent anyway. The next judge should say to the FBI, "you lied to the court last time about a large number of things. dismissed with prejudice!".

    We can but hope!

  45. Re:Why did FBI claim they would start helping poli by Anonymous Coward · · Score: 0

    No problem with sending iphones etc - secure evidence transport between law enforcement agencies happens all the time.

  46. Apple itself by farble1670 · · Score: 1

    Apple has no interest in running afoul of the US government. What they are concerned about is letting the public know that they cooperated. Do they really care if the FBI gains access to this phone? Of course not. I'd have to guess that Mr. Cook is opposed to terrorism and would like it stopped.

    My guess is that this was a shady, unofficial back-alley deal between Apple and the FBI. "Here's how you do it. Here's some hardware to help. You never saw us. We don't exist."

  47. Professional hackers? Like the NSA? by sabbede · · Score: 1

    The agency they should have turned to for help in the first place?

  48. this is for real give it a try by Anonymous Coward · · Score: 0

    HACK ATM AND BECOME RICH TODAY
    How to hack an ATM MACHINE or BANK ACCOUNT
    You can hack and break into a bank's security ATM Machine without carrying guns or any weapon. How is this possible? First of all we have to learn about the manual hacking of ATM MACHINES and BANKING ACCOUNTS HOW THE ATM MACHINE WORKS. If you have been to the bank you find out that the money in the ATM MACHINE is being filled right inside the house where the machine is built with enough security.to hack this machine We have develop the special blank ATM Card which you can use in any ATM Machine around the world. this card is been programmed and can withdraw 2000 USD within 24 hours in any currency your country make use of. The card will make the security camera malfunction at that particular time until you are done with the transaction you can never be trace. getting the card you will forward the company your address details so we can proceed to send the card to you once you agree to the terms and conditions. you can contact us on email now atmmachinehackes@gmail.com

  49. How about chain of evidence? by Anonymous Coward · · Score: 0

    Is there any reason a judge or jury should trust evidence gathered using hired guns whose ethics are questionable at best?

  50. And yet by Anonymous Coward · · Score: 1

    And yet, they're clearly spread thin and underfunded in a lot of places. The same places defeat community policing measures. Because taxes. And the public is outraged, just outraged, that things are then relegated to minimal police response due to this reality. Reminds me of the nursing profession. Snake head? Meet snake tail!

  51. Coren22 = An online liar humiliated by Anonymous Coward · · Score: 0

    See subject: Don't talk about lying Coren22 considering how easily I shot you to pieces for it here https://news.slashdot.org/comm...

    * HOW CORRECT & HONEST WERE YOU COREN22?

    (Prepare for a massive lie from him folks - anyone here can read that link and see how the little scumbag Coren22 operates, lies galore WHICH I & OTHERS DISPROVED!)

    Going to say I am "abusing" you you little FUCK? You have it coming for the crap you spewed about me & my work you little do nothing nobody (show you've done better).

    You've been trolling me for a week now too (last Friday especially & now again today which YOUR POST HISTORY SHOWS).

    APK

    P.S.=> You have GOT to be the biggest damn weasel I've ever SEEN online & I've been out here since 1985 online... apk

    1. Re:Coren22 = An online liar humiliated by Coren22 · · Score: 1

      What lying would that be? That I don't consider a single person reviewing your code to be enough to be considered safe? That is the truth, and is true of many people. You are the developer, it is your job to engender trust in users by having code reviews done by many people, it isn't my job to blindly trust that your software won't turn my computer into a zombie.

      Also, replying to ACs now and trying to claim that they are me? Grow up little one.

      EAT YOUR WORDS Coren22 by ac (your bridge bs gave you away & I remember EVERYTHING...)

      HAHAHAHHA, you mean YOUR bridge bullshit. You are the one who claimed you were using bridges to anonymize yourself. You are the one with a lack of basic knowledge of networking that thought a bridge would do things that it plainly cannot do.

      https://en.wikipedia.org/wiki/...

      Learn about technology before trying to claim you are an expert it in. I didn't claim you were using a bridge, you did.

      --
      APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
  52. Bridged modems & router firewalls stupid... ap by Anonymous Coward · · Score: 0

    See subject & a quote of myself giving it away since you're too stupid to figure it out:

    "I used BRIDGED router firewalls to my cable modem http://slashdot.org/comments.p... might as well tell you since you're TOO dumb to figure it out" - BY ME, here https://news.slashdot.org/comm...

    I gave you a clue in a Led Zeppelin lyric "have you seen the bridge" but your OUTISM defective brain didn't pick up on it & took it LITERALLY!

    57++ antivirus programs also back my code is safe. What do YOU have vs. that much? Not much. You're a lying troll Coren22, losing badly vs. myself & facts I use.

    APK

    P.S.=> Coren22, look - IF you want to continue looking stupid & coming off as a damn liar (or illiterate) vs. myself? That's YOUR business... apk

  53. Re:Bridged modems & router firewalls stupid... by Coren22 · · Score: 1

    Holy hell, are you a moron?

    You use a bridge connection to the internet?? That is like begging to be hacked, and inviting the trouble!

    You claim you are a "security expert" and you run a bridged connection, which is the exact opposite of security, as it means you are turning off the firewall?

    Wow, just wow, I think I have now lost any possible respect I could have had for you, you know nothing about security, and have now proven it.

    --
    APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
  54. Bridged modem = dummy (firewall router takes over) by Anonymous Coward · · Score: 0

    See subject: A firewalling NAT stateful packet inspecting router is the 'brain' then, & layered security Coren22 (it protects me FAR better than cable or DSL modems do for sure) - that's not turning off a firewall. It turns on a BETTER one.

    THAT, along w/ other "defense-in-depth"/"layered-security" methods do the rest (in case one of my layers fails).

    * It also lets you do a HELL of a lot more too which judging by what I've shown others I do here blowing by any barriers put in my way too? Well, proof's in the pudding... moving target safety in fact. Thus, my system can't be "zeroed in on" typically to BE directly attacked in other words.

    This time, since I realize you have a brain damaged inability to read, I actually feel BAD showing everyone how stupid you are, now eating your words.

    APK

    P.S.=> I use & do a LOT more ontop of that too http://www.bing.com/search?q=%... that works & even got me PAID for it no less - unexpectedly... apk

  55. Re:Bridged modem = dummy (firewall router takes ov by Coren22 · · Score: 1

    Keep walking it back, you are the one who claimed you bridged your router, not I.

    Yeah, the brain damage is strong in this one, does it come with an inability to admit when you were wrong?

    https://slashdot.org/comments....

    I used BRIDGED router firewalls to my cable modem

    So, keep it up, this is great entertainment for me.

    --
    APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
  56. Notice you're not questioning it by Anonymous Coward · · Score: 0

    See subject: It's not worse security as you said - it's better (especially in router level blocklists - good routers have ones that take FAR more entries than std. cable or DSL modems do) https://slashdot.org/comments....

    * By the way, on "brain damage": WHO is the assburgers dolt here? Not I, lol... you are.

    APK

    P.S.=> Coren22, look - I know you're "butthurt" over your BLUNDERS & LIES I cut to shreds vs. myself on here -> https://news.slashdot.org/comm... since you troll nearly all of my posts, lol!

    However, when I attempted to give you a clue on 'bridge'? You didn't even UNDERSTAND what I meant taking it all out of context yet NEVER stating what to do (which is what I do in that 1st link above).

    Now, in the 1st link above, you do (& you can't stand it vs. "yours truly" + you certainly haven't written guides for security I have a decade++ ago (far longer actually, 2 decades ago) that I was paid for in security & I develop a program that works for more security & speed you NEVER will (You don't have the skills))... apk

    1. Re:Notice you're not questioning it by Coren22 · · Score: 1

      Keep walking it back. You can't say anything to change what you claimed, all the proof is here in this thread that you know nothing about network security. You keep posting more and more digging the hole deeper and deeper.

      http://slashdot.org/comments.p...
      You can keep bringing it up, but it doesn't change anything. You are the one claiming that you are using a bridge to get by the Slashdot posting limits, as it that is even possible. You are now trying to claim that bridging your connection is the same thing you were talking about then, and that it is better security than a firewalled connection. Next you change the story again, it is now a bridged cable modem hooked to a router! So, how does that bridge help you post on Slashdot while normal ACs have serious posting limits that you so easily bypass? How is a bridged connection the exact same thing as a bridge to a router, and adds to your proxying of your connection?

      https://slashdot.org/comments....
      I have consistently refuted all your points, yet you keep bringing them up, without changing a damn thing. Here is where I go through your whole DNS vs hosts shit posting and explain why it is a terrible way to do it.

      https://slashdot.org/comments....
      Here you are saying you would stop the shitposting, but you couldn't resist, could you?

      I have the popcorn cooking, this shit is entertaining. I love tearing apart your comments, it is great entertainment for me, as you can't actually fight your way out of a wet paper bag, and you make the same arguments over and over like they are somehow novel or correct the more they are said. Oh, and then you claim to have won the argument, because you say so.

      --
      APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
  57. Coren22's 'refutation' quoted (lol) by Anonymous Coward · · Score: 0

    secretary at MalwareBytes took a look at his source code and said it looked all good - by Coren22

    My code's verified by Mr. Steven Burn of Malwarebytes

    "I've seen the code, and yes, it is safe." FROM http://forum.hosts-file.net/viewtopic.php?f=5&t=4290

    NOT a secretary!

    I don't give away work to be stolen OR misused like GOOGLE CHROME http://it.slashdot.org/story/15/10/20/1254225/efast-malware-hijacks-browser-with-chrome-clone

    won't demonstrate security of his product be exposing the source - by Coren22 (1625475)

    57 antivirus results show otherwise https://www.virustotal.com/en/file/e01211ca36aa02e923f20adee0a3c4f5d5187dc65bdf1c997b3da3c2b0745425/analysis/1433430542/

    MalwareBytes' employee hosts & recommends it -> http://hosts-file.net/?s=Download

    * EAT YOUR WORDS Coren22 (you've done better? No - You don't possess the skills)

    APK

    P.S.=> I'll let others judge "who refuted whom", lol.. apk