> Funny to call it reporting when it's more of an editorial by the renowned security researcher Bruce Schneier.
I respect Bruce and he's done a ton of great work, but I obviously disagree with him on this point. I do not believe governments (especially ones engaged in clandestine surveillance operations) have an obligation to share security vulnerabilities with companies. But neither do those companies have an obligation to create vulnerabilities for the governments to exploit (on the contrary; the companies have an obligation to find and fix the holes in their products).
> It doesn't matter that the vulnerability "has always been there" if nobody knew about it.
There's no guarantee that nobody knew about it, and that's the problem. Information asymmetry is a bitch, but the safest assumption is that someone else did indeed know about it, and then told the FBI. If someone was willing to tell the FBI, it's a safe bet the security community knows about this exploit.
Also, if I was the FBI I would intentionally try to obfuscate my capabilities as much as I can. I would want people to think I can hack every iPhone at any time, even if I can't.