FBI Makes Official Its Decision to Keep Apple iPhone Hack Secret
bloomberg.com
bloomberg.com
From the bits I've seen of it, the Vulnerabilities Equities Process is a really great bit of government transparency, run by a group of people who understand that the best interests of different parts of the government and the citizens of the country often end up at odds. The process allows for vulnerabilities to be periodically reviewed so that the costs and benefits of not disclosing can be weighed over time, and by an at-least-somewhat independent group.
Just skipping it altogether because "we paid a contractor" completely subverts the process. What's stopping all the TLAs from simply routing all their vulns through a private third party and bypassing the VEP altogether?
The real scary precedent is that they paid that much without obtaining the vulnerability exclusively and the technical aspect behind it. Or maybe it's not a scary precedent (except in tax monies) that they outsourced the vulnerability without obtaining the know-how to reuse it on a whim.
Either way you look at it, it is opaque, regardless of whether it goes through the VEP (and the ERB within) or they use a secret company. Were one way more transparent than the other then we should definitely favor that approach.
Part of it is that the government can have SAIC or their subcontractors do the shady things that the government might actually get taken to task for.
I mean, they've paid black hats for an exploit, and are now protecting their identities.
What if the FBI colluded with a mobster - oh, Bulger. Yeah, nothing new here, just the same old crooks being the same old crooks.
The only way the FBI will be able to use this data in court is if they turn the process over to the defense so they can have the process independently verified. Since the article states that they don't have access to the "technical details" of the hack, they have no way to prove the method doesn't manipulate the data on the device.
There's no claim that they violated any rights searching the phone (which after all belonged to them), but that the process may be unreliable. That means it's still enough for probable cause, or that seems plausible to me. I don't know whether this is right.
Edit: I did some searching, and this seems to be correct. https://en.wikipedia.org/wiki/Taint_(legal)
>The most common of such usage is with reference to evidence, testimony, identification by witnesses, or confessions that have been obtained by law enforcement illegally.
If it's obtained legally, it doesn't count as tainted. http://legal-dictionary.thefreedictionary.com/tainted+eviden... has the same illegal language.
Pretty sure the phone was the property of whomever was named as the dead guy's inheritor in his will. Absent a will it should have gone to the next of kin or probate court or similar. One place the dead guy's property should not go is to the FBI. That's not how property rights work.
I recognize that in practice the FBI will do as they damn well please, but in principle we do have laws for this.
http://gizmodo.com/the-san-bernardino-terrorists-icloud-pass...
> Technically, the iPhone in question (the one the FBI is demanding that Apple unlock) was purchased by the San Bernardino Department of Health. And as security researcher Christopher Soghoian has pointed out on Twitter, the Department tried to reset the phone’s iCloud password remotely in the hours after the attack. The department hoped to gain information from a possible back-up of the phone to iCloud. Instead, it rendered the account useless.
Although the FBI paid more than $1.3 million for the method, Amy Hess, the agency’s executive assistant director for science and technology, said Wednesday that it didn’t purchase the rights to the technical details and therefore doesn’t have the necessary information to submit the method for an Obama administration review known as the Vulnerabilities Equities Process. "The FBI assesses that it cannot submit the method to the VEP," Hess said in a statement. "We do not have enough technical information about any vulnerability that would permit any meaningful review.”
...
The law enforcement agency bought the hacking tool from an entity it hasn’t identified and then used it to access data on an encrypted iPhone
It sounds like the FBI doesn't actually understand the details of how the crack worked and was hand-holded through the process.
tl;dr tainted refers to evidence obtained illegally and is not applicable here.
This just shows typical contempt for the public in general. Why should we be surprised?
It's possible the contractor in question is a gray-hat hacker who really hasn't ever performed the hack on any phones they don't own, which makes everything they've done perfectly legal.
But if I was someone on the FBI side who wanted to "win" this somehow, I could imagine how this might look like a victory. Apple wanted for its phones to look so secure that they will even stand up to the government to protect them. In response, the FBI made Apple's phones look so weak that anyone who has $1M to spend on the black market can get in.
1. https://www.theguardian.com/technology/2015/nov/03/jailbreak...
2. http://www.ibtimes.com/ios-9-jailbreak-reward-zerodium-offer...
However, the situation as I see it is this: The FBI realized they were going to lose their legal battle to compel Apple to unlock the phone in question. They then retracted their suit to avoid a precedent being set against them, and announced "don't worry guys, we got in anyway" to deflect attention from that particular iPhone, which they had argued was where the situation would end in the first place.
Your explanation is certainly possible, I just don't think it's as likely that they would really spend $1m on this phone which in all likelihood has nothing of value on it to begin with.
On the other hand, cases like these may make them consider starting a bug bounty program. and of course, they may already be advertising where it matters (e.g. by calling various hackers, or by using an intermediary to buy hacks) without telling the whole world.
Apple has persisted its appearances in shipping stable, valuable software and hardware the first time quite well. No hiccups allowed here.
Admitting they can't catch every last bug before release would be killing this advantage in public perception they have over competitors like Microsoft.
Why is that? It seems to me that there are a lot of ways to run bug bounties, although I haven't thought through the details of Apple keeping theirs official / unofficial, it seems one could have arguments for having none, both, or either, depending on who you are and what kinds of bugs you are trying to get people to tell you about.
If I owned an apple tree and merchants were willing to give me $5 per piece of fruit, why would I sell the tree to a farmer for $10? That's assuming that I even want the farmer to know how I grew the tree.
Apple is not a government and does not act "in good faith of all - we the people".
In other words - its okay for the GOV to pay a company to extract data from someone's phone (aka "hacking"), it is illegal for a citizen to do so, whether you're paying to crack a phone, or paying to break into someone's house.
The big question that looms in everyone's mind is if the hack can be used against next gen phones.
Seems like for critical things they should have no problem setting up fake companies or handling espionage, etc. What stops them, from, say, paying an employee a large bonus to work for a competitor while feeding back information?
It's definitely true of a $10k exploit which might be readily available on the market, but for something more unique like this they might be more selective with their buyers to protect future profits.
Apple should not be compelled to help the government break into one of its devices. But they can "choose" to help the government break in. Likewise, government should not be compelled to help secure its companies by buying zero-days off the black market for public security. But again they can "choose" to.
The cooperation of corporations and goverments is a symbol of trade and teamwork. The lack of cooperation is a symbol of distrust and hostility.
Yes, it should. Who is working for who here? I can understand someone delegating the initial implementation details of a public service to the state, but to say that the state shouldn't be subject to the demands of the public - well that is just insane.
> ...trade and teamwork. The lack of cooperation is a symbol of distrust and hostility.
Teamwork conveys some idea of equality, which isn't going to work if you're interested in maintaining the idea of "public servant". The state's degree of trust in the public (corporate or individual) is irrelevant, the state doesn't get to selectively perform its duties on such a basis.
They can't even pretend that the technique would never be utilized by "bad guys" outside of the USA government since whatever the technique is, it's already available for purchase.
Every time an american agency finds a vulnerability they are faced with a choice: - Use it, possibly against foreign targets - Share it with american vendors to make the country and its businesses safer
It should be clear that in most cases the value of protecting american interest is vastly more valuable than attacking foreign interests.
It's like Clinton lobbying cruise missiles at Afghanistan, whatever they destroyed was worth a lot less than the missile itself. If for example Apple and Google can be protected that is probably worth a lot more than whatever can be gained by using this offensively.
And note that every time a cyber weapon is used there is a large risk that the entity being attacked can learn how the attack worked and use this back at your interests.
I think the FBI is making the right call here. An exploit that requires physical access to the phone and that sells for a million dollars per use is not a big risk to anyone.
Plausible, actually - and if they wanted a cover story that would cause apple as much collateral damage as possible, they've chosen well - as blowback doesn't matter to the FBI. They're untouchable gods, above the law, above public sentiment.
Without recalling all iPhones prior to the Secure Enclave, I'm not exactly sure how they would 'fix it'.
It is not only common, but NORMAL for hackers to have unknown exploits before the vendor is aware of them. Where do you think 0-days come from? In fact, there is an annual competition to break these devices with previously unknown attacks at CanSecWest.
Example: http://9to5mac.com/2014/11/13/iphone-5s-samsung-galaxy-s5-ne...
Then again, goose!=gander
I would imagine that sort of thing would be very expensive to do correctly, unless you are only talking about feeding badly-timed signals at the asic pins.
Apple does this to an extreme. You can't even see the code to projects you are not on. Oh someone else's code has a bug? Well, you can do symbol search across the entire codebase but you will get the line featuring the symbol, the line above it and the line below it.