Live data from Hacker News

FBI Paid More Than $1M to Hack San Bernardino iPhone

wsj.com

21–30 of 206 posts

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#21
post #7

To me this raises a question about selling security vulnerabilities to state actors in general (in the context of the Facebook vulnerability thread where the standard discussion about value is being hashed out). Specifically, I live in the UK and one of the complaints law enforcement has is that US companies can (and do) totally ignore valid court orders because they don't apply in the US (reddit being an arbitrary c…

https://www.eff.org/deeplinks/2015/06/damn-equities-sell-you...

> Noted eagle eye and EFF Investigative Researcher Dave Maass happened on an interesting item from earlier this week on FedBizOpps, the site for government agencies to post contracting opportunities. The Navy put up a solicitation explaining that the government wants “access to vulnerability intelligence, exploit reports and operational exploit binaries affecting widely used and relied upon commercial software,” including Microsoft, Adobe, Android, Apple, “and all others.” If that weren’t clear enough, the solicitation explains that “the vendor shall provide the government with a proposed list of available vulnerabilities, 0-day or N-day (no older than 6 months old). . . .The government will select from the supplied list and direct development of exploit binaries.”

http://www.zdnet.com/article/nsa-purchased-zero-day-exploits...

> The National Security Agency bought hacking tools from a security firm, based on documents unearthed by a FOI request.

The US is doing it. The GCHQ likely does it too and I bet at least some of this list was built via information purchased from others:

https://www.schneier.com/blog/archives/2014/07/gchq_catalog_...

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#25
post #22

This really seems like a terrible market for a state to be so openly involved in.

So they should be clandestinely involved, instead? They're going to do it anyways, I'd rather know about it.

False dichotomy is false. They didn't have to do this, and by all accounts, received nothing of value for the money.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#26

Earlier quoted context omitted.

> The Federal Bureau of Investigation paid more than $1 million for a hacking tool that opened the iPhone of a terrorist gunman in San Bernardino, Calif., the head of the agency said Thursday. > Speaking at the Aspen Security Forum in London, FBI Director James Comey didn’t cite a precise figure for how much the government paid for the solution to cracking the phone but said it was more than his salary for the seven-…

Well now they have a tool they can use at any time.

On iPhone 5. Until Apple updates the software to fix the vulnerability.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#27

That's it?

a) The amount is nice since I think they apparently approached them after figuring out how to do this. So impossible to think anywhere near that amount of work was actually involved.

b) Establish and prove they can do the job. Will get other work like this and be able to charge more. Really no different than what the local handyman or plumber does in some cases.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#28
post #12

Same article on the FT: http://www.ft.com/cms/s/0/af23e3ea-07f1-11e6-b6d3-746f8e9cdd... James Comey, director of the FBI, said on Thursday that the cost was “worth it”, but added that an accommodation needed to be made with Apple and other technology companies in the future, as paying outside technologists to find ways to access highly-encrypted messages on phones used by terrorist suspects was not “scalable.”

At what scale are they accessing the hardware of terrorists anyways?

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#30
post #12

Same article on the FT: http://www.ft.com/cms/s/0/af23e3ea-07f1-11e6-b6d3-746f8e9cdd... James Comey, director of the FBI, said on Thursday that the cost was “worth it”, but added that an accommodation needed to be made with Apple and other technology companies in the future, as paying outside technologists to find ways to access highly-encrypted messages on phones used by terrorist suspects was not “scalable.”

The only reason it would be 'Worth it' is if they found something of note (something to help prosecution of other criminals or prevent further attacks). Is there any reason to believe that this hack accomplished this?

What else would make it 'worth it'? Or is this just politicking?

Post reply on HN