THE FBI cracked a San Bernardino terrorist's phone with the help of professional hackers who discovered and brought to the bureau at least one previously unknown software flaw, according to people familiar with the matter.
The new information was then used to create a piece of hardware that helped the FBI to crack the iPhone's four-digit personal identification number without triggering a security feature that would have erased all the data, the individuals said.
The researchers, who typically keep a low profile, specialize in hunting for vulnerabilities in software and then in some cases selling them to the U.S. government. They were paid a one-time flat fee for the solution.
Cracking the four-digit PIN, which the FBI had estimated would take 26 minutes, was not the hard part for the bureau. The challenge from the beginning was disabling a feature on the phone that wipes data stored on the device after 10 incorrect tries at guessing the PIN code. A second feature also steadily increases the time allowed between attempts.
The bureau in this case did not need the services of the Israeli firm Cellebrite, as some earlier reports had suggested, people familiar with the matter said.
The U.S. government now has to weigh whether to disclose the flaws to Apple, a decision that probably will be made by a White House-led group.
The people who helped the U.S. government come from the sometimes shadowy world of hackers and security researchers who profit from finding flaws in companies' software or systems.
Some hackers, known as "white hats," disclose the vulnerabilities to the firms responsible for the software or to the public so they can be fixed and are generally regarded as ethical. Others, called "black hats," use the information to hack networks and steal people's personal information.
The individuals who helped the FBI in the San Bernardino, California, case fall into a third category, often considered ethically murky: researchers who sell flaws to governments, companies that make surveillance tools or groups on the black market.
This last group, dubbed "gray hats," can be controversial since critics say they might be helping governments spy on their own citizens. When selling exploits to governments or on the black market, researchers do not disclose the flaws to the companies responsible for the software, as the exploits' value depends on the software remaining vulnerable.
In the case of the San Bernardino iPhone, the solution found by the hackers has limited shelf life.
FBI Director James B. Comey has said that the solution works only on iPhone 5Cs running the iOS 9 operating system - what he calls a "narrow slice" of phones.
Apple said last week that it would not sue the government to gain access to the San Bernardino solution.
Still, many security and privacy experts have been calling on the government to disclose the vulnerability data to Apple so that the firm can patch it.
If the government shares data on the flaws with Apple, "they're going to fix it and then we're back where we started from," Comey said in a discussion at a privacy conference last week. Nonetheless, he said Monday in Miami, "we're considering whether to make that disclosure or not."
The White House has established a process in which federal officials weigh whether to disclose any security vulnerabilities they find. It could be weeks before the FBI's case is reviewed, officials said.
"When we discover these vulnerabilities, there's a very strong bias towards disclosure," White House cybersecurity coordinator Michael Daniel said in an interview in October 2014, speaking generally and not about the Apple case. "That's for a good reason. If you had to pick the economy and the government that is most dependent on a digital infrastructure, that would be the United States."
But, he added, "we do have an intelligence and national security mission that we have to carry out. That is a factor that we weigh in making our decisions."
The decision-makers, which include senior officials from the Justice Department, FBI, National Security Agency, CIA, State Department and Department of Homeland Security, consider how widely used the software in question is. They also look at the utility of the flaw that has been discovered. Can it be used to track members of a terrorist group, to prevent a cyberattack, to identify a nuclear weapons proliferator? Is there another way to obtain the information?
In the case of the phone used by the San Bernardino terrorist, "you could make the justification on both national security and on law enforcement grounds because of the potential use by terrorists and other national security concerns," said a senior administration official, speaking on the condition of anonymity because of the matter's sensitivity.
A decision also can be made to disclose the flaw - just not right away. An agency might say it needs the vulnerability for only a few months or that its utility will quickly diminish.
"A decision to withhold a vulnerability is not a forever decision," Daniel said in the earlier interview. "We require periodic reviews. So if the conditions change, if what was originally a true [undiscovered flaw] suddenly becomes identified, we can make the decision to disclose it at that point."
The Washington Post
Wed Apr 13 2016
Some hackers, known as "white hats," disclose the vulnerabilities to the firms responsible for the software or to the public so they can be fixed and are generally regarded as ethical. - File Photo
2TM: Consultations on PTPTN loans, admission to IPTA at MOHE booth
Consultations on PTPTN loans and admission to IPTA are among services provided at the Higher Education Ministry booth.
Kampung Tanjung Kala residents affected by flooded bridge every time it rains heavily
Almost 200 residents from 60 homes in Kampung Tanjung Kala have ended up stuck when their 200-metre (m) long concrete bridge flooded.
COP29 climate summit draft proposes rich countries pay $250 billion per year
The draft finance deal criticised by both developed and developing nations.
Bomb squad sent to London's Gatwick Airport after terminal evacuation
This was following the discovery of a suspected prohibited item in luggage.
Kelantan urges caution amidst northeast monsoon rains
Kelantan has reminded the public in the state to refrain from outdoor activities with the arrival of the Northeast Monsoon season.
Former New Zealand PM Jacinda Ardern receives UN leadership award
Former New Zealand prime minister Jacinda Ardern was given a global leadership award by the United Nations Foundation.
ICC'S arrest warrants for Netanyahu, Gallant an apt decision - PM
The decision of the ICC to issue arrest warrants against Benjamin Netanyahu and Yoav Gallant is apt, said Datuk Seri Anwar Ibrahim.
KTMB provides two additional ETS trains for Christmas, school holidays
KTMB will provide two additional ETS trains for the KL Sentral-Padang Besar route and return trips in conjunction with the holidays.
BNM'S international reserves rise to USD118 bil as at Nov 15, 2024
Malaysia's international reserves rose to US$118.0 billion as at Nov 15, 2024, up from US$117.6 billion on Oct 30, 2024.
Findings by dark energy researchers back Einstein's conception of gravity
The findings announced are part of a years-long study of the history of the cosmos focusing upon dark energy.
NRES responds to Rimbawatch press release on COP29
The Ministry of Natural Resources and Environmental Sustainability (NRES) wishes to offer the following clarifications to the issues raised.
Online Safety Bill and Anti-Cyberbullying Laws must carefully balance rights and protections
The Online Safety Advocacy Group (OSAG) stands united with people in Malaysia in the fight against serious online harms.
Malaysia's inflation at 1.9 pct in Oct 2024 - DOSM
Malaysia's inflation rate for October 2024 has increased to 1.9 per cent, up from 1.8 per cent in September this year.
Saudi Arabia showcases Vision 2030 goals at Airshow China 2024
For the first time, Saudi Arabia is participating in the China International Aviation & Aerospace Exhibition held recently in Zhuhai.
King Charles' coronation cost GBP 71mil, govt accounts show
The coronation of Britain's King Charles cost taxpayers GBP72 million (US$90 million), official accounts have revealed.
Couple and associate charged with trafficking 51.9 kg of meth
A married couple and a man were charged in the Magistrate's Court here today with trafficking 51.974 kilogrammes of Methamphetamine.
PDRM to consult AGC in completing Teoh Beng Hock investigation
The police may seek new testimony from existing witnesses for additional insights into the investigation of Teoh Beng Hock's death.
Thai court rejects petition over ex-PM Thaksin's political influence
Thailand's Constitutional Court rejects a petition seeking to stop Thaksin Shinawatra from interfering in the running the Pheu Thai party.
Abidin takes oath of office as Sungai Bakap assemblyman
The State Assemblyman for Sungai Bakap, Abidin Ismail, was sworn in today at the State Assembly building, Lebuh Light.
UPNM cadet officer charged with injuring junior, stomping on him with spike boots
A cadet officer at UPNM pleaded not guilty to a charge of injuring his junior by stomping on the victim's stomach with spike boots.