Live data from Hacker News

FBI Paid More Than $1M to Hack San Bernardino iPhone

wsj.com

51–60 of 206 posts

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#51
post #7

To me this raises a question about selling security vulnerabilities to state actors in general (in the context of the Facebook vulnerability thread where the standard discussion about value is being hashed out). Specifically, I live in the UK and one of the complaints law enforcement has is that US companies can (and do) totally ignore valid court orders because they don't apply in the US (reddit being an arbitrary c…

> Specifically, I live in the UK and one of the complaints law enforcement has is that US companies can (and do) totally ignore valid court orders because they don't apply in the US (reddit being an arbitrary concrete example). A US company (or individual) should absolutely ignore court orders from a non-US court; such courts have no jurisdiction. A "valid" court order necessarily must come from a court with jurisdic…

Actually, the court would issue such an order _because_ it knows better: without it, you basically have little leverage when you try to enforce the same in the foreign country in a court that actually _has_ jurisdiction.

Here's an example where a French court issued a court order to a US firm:

https://en.wikipedia.org/wiki/LICRA_v._Yahoo!

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#52
post #12

Same article on the FT: http://www.ft.com/cms/s/0/af23e3ea-07f1-11e6-b6d3-746f8e9cdd... James Comey, director of the FBI, said on Thursday that the cost was “worth it”, but added that an accommodation needed to be made with Apple and other technology companies in the future, as paying outside technologists to find ways to access highly-encrypted messages on phones used by terrorist suspects was not “scalable.”

Making it not scalable is the point. It places a monetary restriction so that they have to pick and choose what devices they think are worth hacking and which ones are not. This is the balance between citizen's rights and government power.

Otherwise we just collect everyone's data on everything all the time and have access to everything.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#53
post #38

Earlier quoted context omitted.

False dichotomy is false. They didn't have to do this, and by all accounts, received nothing of value for the money.

> by all accounts, received nothing of value for the money How can you know that?

come on do all internet comments have to be perfect? how about "by all public accounts to date".

I'd have though that extra context wasn't necessary.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#54

Earlier quoted context omitted.

False dichotomy is false. They didn't have to do this, and by all accounts, received nothing of value for the money.

Don't they have a tool to get into other iPhone's now? $1,000,000 doesn't seem too bad.

AFAIK, the exploit only works on older iphones. It'll quickly lose value going forward.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#55

Were they going to pay Apple if they had somehow forced them to do the deed?

Example: http://www.cbsnews.com/news/verizon-att-get-most-bucks-from-... >AT&T, for example, imposes a $325 "activation fee" for each wiretap and $10 a day to maintain it. Smaller carriers Cricket and U.S. Cellular charge only about $250 per wiretap. But snoop on a Verizon customer? That costs the government $775 for the first month and $500 each month after that, according to industry disclosures made last year to C…

So the only argument the FBI hears is how much? Disgusting.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#56
post #29
post #8

McAfee offered to do it free of charge. Should have took him up on that, rather than wast $1M.

McAfee's offer was a PR stunt. He admitted it a week later.

And he made a series of public statements which made it clear he had no understanding whatsoever of the technical issues involved.

First, he claimed that he would use "social engineering" to access the phone's data.

Later, he claimed that he could do it easily by clearing the area of flash memory containing the phone's password, apparently unaware of the fact that the password was used as a key to encrypt data.

Source: http://arstechnica.com/security/2016/03/john-mcafee-better-p...

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#57
post #42
post #12

Same article on the FT: http://www.ft.com/cms/s/0/af23e3ea-07f1-11e6-b6d3-746f8e9cdd... James Comey, director of the FBI, said on Thursday that the cost was “worth it”, but added that an accommodation needed to be made with Apple and other technology companies in the future, as paying outside technologists to find ways to access highly-encrypted messages on phones used by terrorist suspects was not “scalable.”

I see two ways to interpret what he said, and I'm kind of appalled at both interpretations: (1) "We can't afford to pay someone every time we need to bypass security, therefore we need the ability to force third parties to do this work for free": um, OK. -or- (2) "Bypassing security takes too much time and effort, therefore we need a backdoor": even more horrifying, even though he's repeatedly denied that this is the…

He doesn't want a "backdoor" just special treatment time and again.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#58

Earlier quoted context omitted.

False dichotomy is false. They didn't have to do this, and by all accounts, received nothing of value for the money.

Don't they have a tool to get into other iPhone's now? $1,000,000 doesn't seem too bad.

You can't put a price on national security. Never mind, they just did and they got to define national security as well.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#60
I find it interesting that this entire issue is the same as the nuclear issue was in the cold war.

Government Technocrats: We need bigger and more powerful warheads to protect us from the Soviets.

General Public: OK we'll learn Duck and Cover.

Sensible Few: Is risking the destruction of everything we're trying to protect worth it?

Government Technocrats: We can't look our children in the eye ... yadda yadda yadda.

Post reply on HN