Live data from Hacker News

FBI Paid More Than $1M to Hack San Bernardino iPhone

wsj.com

41–50 of 206 posts

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#41
post #7

To me this raises a question about selling security vulnerabilities to state actors in general (in the context of the Facebook vulnerability thread where the standard discussion about value is being hashed out). Specifically, I live in the UK and one of the complaints law enforcement has is that US companies can (and do) totally ignore valid court orders because they don't apply in the US (reddit being an arbitrary c…

> Specifically, I live in the UK and one of the complaints law enforcement has is that US companies can (and do) totally ignore valid court orders because they don't apply in the US (reddit being an arbitrary concrete example).

A US company (or individual) should absolutely ignore court orders from a non-US court; such courts have no jurisdiction. A "valid" court order necessarily must come from a court with jurisdiction.

Similarly, I'd expect a UK company to ignore US court orders.

(And in both cases, I'd ideally hope the court knows better than to take the case in the first place or to issue such an order.)

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#42
post #12

Same article on the FT: http://www.ft.com/cms/s/0/af23e3ea-07f1-11e6-b6d3-746f8e9cdd... James Comey, director of the FBI, said on Thursday that the cost was “worth it”, but added that an accommodation needed to be made with Apple and other technology companies in the future, as paying outside technologists to find ways to access highly-encrypted messages on phones used by terrorist suspects was not “scalable.”

I see two ways to interpret what he said, and I'm kind of appalled at both interpretations:

(1) "We can't afford to pay someone every time we need to bypass security, therefore we need the ability to force third parties to do this work for free": um, OK.

-or-

(2) "Bypassing security takes too much time and effort, therefore we need a backdoor": even more horrifying, even though he's repeatedly denied that this is the endgame.

Edit: typo

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#43
post #12

Same article on the FT: http://www.ft.com/cms/s/0/af23e3ea-07f1-11e6-b6d3-746f8e9cdd... James Comey, director of the FBI, said on Thursday that the cost was “worth it”, but added that an accommodation needed to be made with Apple and other technology companies in the future, as paying outside technologists to find ways to access highly-encrypted messages on phones used by terrorist suspects was not “scalable.”

> was not “scalable.” This is the same James Comey that said they just were just asking Apple for access to just that one phone.

“The relief we seek is limited and its value increasingly obsolete because the technology continues to evolve. We simply want the chance, with a search warrant, to try to guess the terrorist’s passcode without the phone essentially self-destructing and without it taking a decade to guess correctly. That’s it.

“We don’t want to break anyone’s encryption or set a master key loose on the land,” Comey continued. “I hope thoughtful people will take the time to understand that. Maybe the phone holds the clue to finding more terrorists. Maybe it doesn’t. But we can’t look the survivors in the eye, or ourselves in the mirror, if we don’t follow this lead. “

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#44
post #12

Same article on the FT: http://www.ft.com/cms/s/0/af23e3ea-07f1-11e6-b6d3-746f8e9cdd... James Comey, director of the FBI, said on Thursday that the cost was “worth it”, but added that an accommodation needed to be made with Apple and other technology companies in the future, as paying outside technologists to find ways to access highly-encrypted messages on phones used by terrorist suspects was not “scalable.”

> was not “scalable.” This is the same James Comey that said they just were just asking Apple for access to just that one phone.

Just think of how many lives were saved by the data they got off that phone. Oh wait...

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#46

Earlier quoted context omitted.

Don't they have a tool to get into other iPhone's now? $1,000,000 doesn't seem too bad.

Not necessarily, they might not own the tool, just paid for someone to use it on the phone.

The subtitle quote indicates that the tool was bought outright.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#47
post #12

Same article on the FT: http://www.ft.com/cms/s/0/af23e3ea-07f1-11e6-b6d3-746f8e9cdd... James Comey, director of the FBI, said on Thursday that the cost was “worth it”, but added that an accommodation needed to be made with Apple and other technology companies in the future, as paying outside technologists to find ways to access highly-encrypted messages on phones used by terrorist suspects was not “scalable.”

The only reason it would be 'Worth it' is if they found something of note (something to help prosecution of other criminals or prevent further attacks). Is there any reason to believe that this hack accomplished this? What else would make it 'worth it'? Or is this just politicking?

I doubt it was worth it. It wasn't even the terrorist's phone. It was owned by their employer. The terrorists destroyed their personal phones prior to attack.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#49
post #20

Is that a lot or a little?

It's about par. Some security firms will charge $1M/year and over. Corporate enterprises involved in intelligence gathering for the government (i.e. ATnT, Apple, Google, Microsoft, basically any "free" and paid tech service) can make a lot of money depending on how many accounts they pass off to the FBI,NSA, etc... If you're using any service in the US and the "West", even the "free speech" stuff like ytcombinator, reddit, they'll pass of information and can charge for it.

edit: Apple's encryption fight, for example, is a bit of a wash. It's basically to lure in more users which they can charge more for. The more value the user has for their privacy, the more companies can charge for access.

They are all corporate enterprises, and their responsibility is to profit for their shareholders. When the government offers a legal profitable offer, they have a responsibility to take it. If they are found not to take it, and a group or party finds out and can prove it was a profitable venture, they can attack the company with the courts.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#50
post #32

Earlier quoted context omitted.

The only reason it would be 'Worth it' is if they found something of note (something to help prosecution of other criminals or prevent further attacks). Is there any reason to believe that this hack accomplished this? What else would make it 'worth it'? Or is this just politicking?

It's just politicking, its "worth it" because they get to flex their muscle and show the world that they don't need apple's cooperation to get what they want.

And because they didn't get to see their precious All Wits Act request struck down setting a precedent against them. A few million to be able to keep invoking the AWA would definitely be "worth it" in their eyes.
Post reply on HN