Live data from Hacker News

FBI Paid More Than $1M to Hack San Bernardino iPhone

wsj.com

141–150 of 206 posts

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#141
post #18
post #12

Same article on the FT: http://www.ft.com/cms/s/0/af23e3ea-07f1-11e6-b6d3-746f8e9cdd... James Comey, director of the FBI, said on Thursday that the cost was “worth it”, but added that an accommodation needed to be made with Apple and other technology companies in the future, as paying outside technologists to find ways to access highly-encrypted messages on phones used by terrorist suspects was not “scalable.”

>paying outside technologists to find ways to access highly-encrypted messages on phones used by terrorist suspects was not “scalable.” Good! I don't want it to be "scalable". That means they want to expand the data that they are collecting to include more a more phones. There is no need to do that!

Yeah. I thought the whole point of court ordered warrants was to NOT be scalable, cause, you know, due process or whatever.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#142

Earlier quoted context omitted.

Indeed. Americans need to wake up to the fact that these spooks simply cannot be trusted. The very concept of trust is alien to their culture. Would be nice of we could count on congress to provide adequate oversight.

It's amazing to me too that the very concept of an "unwarrantable" space is simply impossible to conceive.

Considering all communication is subject to eavesdropping the space they are wanting to access borders on the realm of private thoughts. And some day soon it just may exist in that realm.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#144

Earlier quoted context omitted.

The thing is, companies like Google, Facebook and Apple are kinda companies of great britain or at least Ireland. They have bases in Ireland for tax purposes and to comply with certain data retention laws. That aside, it is not really too much to ask that a company that does business in England abide by English law.

I'd certainly agree that a company with a legal nexus in a given country must obey that country's laws (or leave). But "does business in England" and "has a legal nexus in England" are two different things, depending on your definition of "does business". For instance, if I sell a service online, and someone from England buys it, that might count as "does business in England" but it doesn't make either me or the serv…

Yeah, but at the same time... If they want to reap the tax benefits of basing themselves out of a country, I would argue that they should be subject to that country's rule.

Really, calling themselves an "Irish" company seems like tax evasion to me, if it's in name only, with none of the negative ramifications.

Edit: speaking with regard to Apple, though other companies are in the same boat.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#145

Given that they found no relevant information on his work phone, exactly as experts and reasonable amateurs and common men predicted, how was it "worth it" as he claims? Is it that wasting huge sums of taxpayer money while attacking civil rights and attempting to instantiate a police surveillance state with no privacy is simply "worth it" no matter what, even if pointless?

It was worth it because they didn't know that beforehand. Now the FBI are sure that the attackers weren't in contact with other ISIS members. The FBI thinks that information is worth the $1.2M+ they paid. How could they possibly have known that without unlocking the phone?

Metadata?

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#146

Earlier quoted context omitted.

> Specifically, I live in the UK and one of the complaints law enforcement has is that US companies can (and do) totally ignore valid court orders because they don't apply in the US (reddit being an arbitrary concrete example). A US company (or individual) should absolutely ignore court orders from a non-US court; such courts have no jurisdiction. A "valid" court order necessarily must come from a court with jurisdic…

The thing is, companies like Google, Facebook and Apple are kinda companies of great britain or at least Ireland. They have bases in Ireland for tax purposes and to comply with certain data retention laws. That aside, it is not really too much to ask that a company that does business in England abide by English law.

> The thing is, companies like Google, Facebook and Apple are kinda companies of great britain or at least Ireland.

It's useful to read the terms of service:

All Google interactions are with the US entity: https://www.google.com/intl/en/policies/terms/ identify

    The Services are provided by Google Inc. (“Google”), located at 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States.
Facebook actually segregates US/Canada users from users of other countries: https://www.facebook.com/legal/terms

    If you are a resident of or have your principal place of business in the US or Canada, this Statement is an agreement between you and Facebook, Inc.  Otherwise, this Statement is an agreement between you and Facebook Ireland Limited.  References to “us,” “we,” and “our” mean either Facebook, Inc. or Facebook Ireland Limited, as appropriate.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#147
post #2

Paywalled for me here in the UK. I assume the title sums up the article? Since I can't read the article, from anyone that can, how did they come to that figure? Is that just the cost of the exploit or..? Cheers

> The Federal Bureau of Investigation paid more than $1 million for a hacking tool that opened the iPhone of a terrorist gunman in San Bernardino, Calif., the head of the agency said Thursday. > Speaking at the Aspen Security Forum in London, FBI Director James Comey didn’t cite a precise figure for how much the government paid for the solution to cracking the phone but said it was more than his salary for the seven-…

Given that this is FBI procurement, I'm guessing they bought an "Enterprise license" with full support and the opportunity to use the application on any phone that fits the spec just in case because additional procurements would take a long time. Typing this sarcastic comments made me realize that they may have bought this tool for all open cases with this device which actually might've been fairly cost effective, but a bit scarier.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#148
post #35
post #12

Same article on the FT: http://www.ft.com/cms/s/0/af23e3ea-07f1-11e6-b6d3-746f8e9cdd... James Comey, director of the FBI, said on Thursday that the cost was “worth it”, but added that an accommodation needed to be made with Apple and other technology companies in the future, as paying outside technologists to find ways to access highly-encrypted messages on phones used by terrorist suspects was not “scalable.”

It was worth it to get out of a court case they were obviously losing that would establish precedent.

Since they have other similar cases with more friendly judges to the FBI desires.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#149
post #20

Is that a lot or a little?

It's about par. Some security firms will charge $1M/year and over. Corporate enterprises involved in intelligence gathering for the government (i.e. ATnT, Apple, Google, Microsoft, basically any "free" and paid tech service) can make a lot of money depending on how many accounts they pass off to the FBI,NSA, etc... If you're using any service in the US and the "West", even the "free speech" stuff like ytcombinator, r…

That's bullshit.

Management has wide-ranging freedom to define what they see as the best course of action and nothing short of fraud is actionable in a court: https://en.wikipedia.org/wiki/Business_judgment_rule.

In this case, the obvious defense would be that for a company such as Apple, the fees they charge the government for access are completely meaningless, compared to the damage the brand could suffer if they're found violating their user's privacy.

At 25$ each as mentioned above, these fees probably don't even cover the costs of having a lawyer take a quick look at it.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#150
post #52

Earlier quoted context omitted.

Making it not scalable is the point. It places a monetary restriction so that they have to pick and choose what devices they think are worth hacking and which ones are not. This is the balance between citizen's rights and government power. Otherwise we just collect everyone's data on everything all the time and have access to everything.

Why would you expect them to be responsible with money that isn't theirs? Your argument would work for an individual, and to a lesser extent a corporation (where money spent comes out of profit and would be balanced against benefit), but the government plays with your money - not their own. If they want to get into a hundred phones, they'll just ask congress for an appropriation for $100m. And since the government is…

They don't have unlimited money. If they can bring it down to $1000 per phone to crack, they still can't crack millions of phones without wondering why their budget is allocated this way.
Post reply on HN