Slashdot Mirror


FBI Bought $1M iPhone 5C Hack, But Doesn't Know How It Works (theguardian.com)

An anonymous reader writes: The FBI has no idea how the hack used in unlocking the San Bernardino shooter's iPhone 5C works, but it paid a sum less than $1m for the mechanism, according to a report. Reuters, citing several U.S. government sources, note that the government intelligence agency didn't pay a value over $1.3m for purchasing the hack from professional hackers, as previously reported by many outlets. The technique can also be used as many times as needed without further payments, the report adds. The FBI director, James Comey, said last week that the agency paid more to get into the iPhone 5C than he will make in the remaining seven years and four months he has in his job, suggesting the hack cost more than $1.3m, based on his annual salary.

35 of 77 comments (clear)

  1. Seriously manishs? by 110010001000 · · Score: 1

    This is the second dupe in a few hours. Seriously? Do you get paid twice every Friday?

    1. Re: Seriously manishs? by Namarrgon · · Score: 3, Funny

      This story wasn't cheap, but it can be used as many times as needed without further payments.

      --
      Why would anyone engrave "Elbereth"?
  2. How does it work? by Laser_iCE · · Score: 1

    "I do not recall."

  3. What did yo expect? by Lead+Butthead · · Score: 1

    "Your tax dollars at work."

    --
    ELOI, ELOI, LAMA SABACHTHANI!?
  4. US needs to fund its own hackers. by BoRegardless · · Score: 1

    Given the nature of the millennial shift to electronic everything everywere, IOT, the US had better figure out how to set up its own mega sized hacking teams which aren't limited by USGovt pay grades.

    1. Re:US needs to fund its own hackers. by Imrik · · Score: 1

      If they did that, they'd be required to inform companies of the details of the holes in their security.

  5. Re:Restored from iCloud by Lab+Rat+Jason · · Score: 3, Interesting

    Sure you're being funny, but that actually is a serious concern here: On one hand, is it forensically legitimate if they can't explain how they got the evidence? (and for that matter does the FBI even CARE about keeping it legal anymore), and on the other hand, does the FBI even know if the wool is being pulled over their eyes if they don't know how it works???

    Finally, I seriously doubt they took the phone outside of an FBI facility to perform the hack, which implies that someone was brought in to the FBI facility to perform the hack... do you really think they let that person walk out without explaining how they did it? You're telling me they didn't search the hackers laptop?

    It all sounds a little too implausible for me.

    --
    Which has more power: the hammer, or the anvil?
  6. William Gibson was prescient by mileshigh · · Score: 2

    Reminds me of scenes from Gibson's Neuromancer-era books where people could illicitly buy "ice" to penetrate a particular type of target. Ice for hard targets was pricey but very user-friendly: just a particular shape they dropped onto the target in their VR headset and then watched it eat its way in, all without knowing its workings.

    1. Re:William Gibson was prescient by Tablizer · · Score: 2

      How is that different from many patents? The hard part is often experimenting and testing, NOT the construction itself.

      For example, Thomas Edison tested thousands of materials before he settled on the best one for his new light bulbs. The actual manufacturing of the filament was relatively mundane.

      And as maintenance coders, sometimes we find the solution to a bug is one line of code. Newbie managers then balk at paying so much for changing one line. You then tell them the hard part is finding and knowing which line to change, not changing the line itself.

  7. Re:Restored from iCloud by gtall · · Score: 1

    "I seriously doubt they took the phone outside of an FBI facility to perform the hack, which implies that someone was brought in to the FBI facility to perform the hack"

    So, you failed Logic 101, eh?

  8. He "earned" it by Tablizer · · Score: 1

    director, James Comey, said last week that the agency paid more to get into the iPhone 5C than he will make in the remaining seven years and four months he has in his job, suggesting the hack cost more than $1.3m, based on his annual salary.

    Good, he's shown he's not smart enough to deserve more.

  9. Re:A sucker by QuantumLeaper · · Score: 1

    Bill never said that, nor did PT Barnum, but it was said about Barnum's customers.

  10. Maybe the terrorist told the grup the password by future+assassin · · Score: 1

    and then they both cashed in on it. I bet it was DirkaDirka

    --
    by TheSpoom (715771) Uncaring Linux user here. I have nothing to add to this but please continue. *munches popcorn*
  11. Re:Stop the criminal (DMCA) cover-up by pr0fessor · · Score: 1

    There are over 3000 counties in the US even at $10k each they could make a lot of money off of sheriff departments and state police then rinse and repeat a year from now when an apple update makes it not work anymore.

  12. I bought a burger and it was less than $1m. by fishscene · · Score: 1

    It was delicious. ...sorry, I'm feeling super sarcastic today.

  13. Why should we believe him? by Gravis+Zero · · Score: 4, Informative

    Seriously, the FBI and Comey in particular have flat out lied so many times in the past year that I honestly can't think of a reason why anyone should believe the things they say.

    --
    Anons need not reply. Questions end with a question mark.
  14. Re: Restored from iCloud by Bartles · · Score: 1

    No they didn't. He wasn't diagnosed until 1994. And as far as I know, he never testified under oath.

  15. $1M paid by taxpayers not FBI by schwit1 · · Score: 1

    The FBI should have to get congressional approval(power of the purse) to spend this kind of money when there is no specific line item in the FBI's budget.

    1. Re:$1M paid by taxpayers not FBI by chill · · Score: 1

      If you think something like "cyber forensic tools" isn't a specific line item in the FBI's budget, you're crazy.

      Their total budget for 2015 was just over $8.3 Billion. I'm sure they could find room under their Cyber, Criminal or Intelligence categories to pull $1.3 million from for a tool to hack the phone in a case like this one.

      --
      Learning HOW to think is more important than learning WHAT to think.
  16. Re:Restored from iCloud by mrchaotica · · Score: 1

    NDAs do not and cannot be allowed to trump FOIA requests!

    --

    "[Regarding the 'cloud,'] ownership was what made America different than Russia." -- Woz

  17. Re: Restored from iCloud by AK+Marc · · Score: 1

    Yeah, and I was never diagnosed with dyslexia, I just had a qualified person tell me that I should never get tested, because I have all the symptoms and if I were diagnosed with it, I'd end up in special ed with the people who can't dress or feed themselves (hey, it was before the enlightened times).

    And plenty of people claim the symptoms were obvious, despite the cover-up of it while he was serving as president.

    An did you need another link to him being sworn in? Or can we consider that issue covered?

  18. Re:Restored from iCloud by Obfuscant · · Score: 1

    On one hand, is it forensically legitimate if they can't explain how they got the evidence?

    "Your honor, you see, there's these spinning platters covered with magnetic material. Floating about 2 microns above the surface of these platters are some very very tiny magnetic sensors attached to a moving arm. The arm is controlled by a servo ... NRZ ... bit stuffing ... FFT ... JPEG ... CPU ... RAM ... USB ... PostScript ... photosensitive transfer belt ... toner ... fuser ... [three hours later] ... and that's how we recovered the digital photo of the defendant holding the severed head of his victim aloft like a trophy."

    Defense attorney: "I move the evidence be excluded, it was clearly printed on a printer that uses PCL and not PostScript! The witness's description is technically wrong."

    Sure.

    I suspect that if this gets to court, everything from the phone that is actually entered as evidence will have corroboration from other sources.

  19. Feds bad at computers by RightwingNutjob · · Score: 1

    News at 11. Duh.

  20. Re: Restored from iCloud by Plus1Entropy · · Score: 1

    He wasn't diagnosed until 1994.

    That doesn't mean he didn't have it before that.

    --
    Only crack the nuts that crack. You don't put the ones that don't crack in the sack.
  21. NDA and FOIA by Anonymous Coward · · Score: 1

    Actually, material under NDA is specifically exempted from FOIA. Otherwise nobody would ever send proprietary information (like a proposal responding to a Request for Proposals) to the government.

  22. Re: Restored from iCloud by Bartles · · Score: 1

    OK, I'll add the qualifier. He never testified under oath as POTUS.

  23. Re: Restored from iCloud by Bartles · · Score: 1

    Sure. There's nothing that says he wasn't a space alien as well.

  24. Re: Restored from iCloud by Plus1Entropy · · Score: 1

    Nice strawman. Alzheimer's often goes undiagnosed until it enters the later stages and becomes more obvious. That's even true today, with much more awareness, research, and technology to help, let alone 20+ years ago.

    --
    Only crack the nuts that crack. You don't put the ones that don't crack in the sack.
  25. Re: Restored from iCloud by Obfuscant · · Score: 1

    There's nothing that says he wasn't a space alien as well.

    Nice strawman.

    This entire sub-thread is a straw man and irrelevant to start with. Reagan has nothing to do with the iPhone hack or the FBI.

    Alzheimer's often goes undiagnosed

    And space aliens have yet to be identified despite decades of living amongst us. At least that's what the space aliens would claim. And we have a lot more awareness and technology to help us detect them today, let alone 20+ years ago. So, there's nothing to say he wasn't a space alien, either. It's just mud-slinging to make such accusations so long after the fact and without any medical evidence to back it up.

  26. Aiding and abetting the enemy is a Federal Crime by Sir+Holo · · Score: 1

    FTA:

    FBI Guy says, "The FBI confirmed that it would not tell Apple about the security flaw exploited in the hack, partly because the law enforcement agency does not know how it works." [And they won't tell either, so whatever they do with it is their own business. Wah.]

    Thanks for keeping us all safe by violating Federal Law!

  27. Re: A sucker by LiENUS · · Score: 1

    I've read aloud the Gettysburg Address. If you were quoting it would you attribute it to me? or Abraham Lincoln?

  28. Re:Restored from iCloud by rtb61 · · Score: 1

    The FBI are trapped, either they were stupid in their investment in failing to pay for open access to the method to ensure legal requirements when evidence is presented as being gained by this method or they are lying. The reason for the lie, they would be criminally negligent for failing to inform citizens seeking to ensure security and generate revenue by that provision of security, of the methods by which that security is broken. This also extends to individuals citizens should their phone be illegally hacked by this method. I doubt they are that stupid, so the lie, which is hugely legally problematic for them and will remain so, is the only logical conclusion. It also does not matter if they know it or not, they know someone does and they are failing to ensure the security of citizens device by obtaining that known secret and are still being criminally negligent.

    --
    Chaos - everything, everywhere, everywhen
  29. Re: A sucker by Imrik · · Score: 1

    Depends on my objective in quoting it.

  30. Wait, what?! by wwalker · · Score: 1

    Something doesn't quite add up in this story. So, the FBI has this black box that they don't know what it does and how it works. All they know is that you put an iPhone into it, and it produces supposedly decrypted data from the said iPhone? How can they verify that it actually does a complete and accurate job? That it doesn't introduce some random files, or hides some information? Either FBI is lying again, or they bought something that's completely useless, as I don't see how any judge would accept the results of what this black box produced as legitimate. Especially considering the box was made in a foreign country (Israel?).

  31. Lol by peanutbar2323 · · Score: 1

    They know how it works.. They're doing it to mine now