Live data from Hacker News

FBI Paid More Than $1M to Hack San Bernardino iPhone

wsj.com

71–80 of 206 posts

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#72
post #62
post #43

Earlier quoted context omitted.

“The relief we seek is limited and its value increasingly obsolete because the technology continues to evolve. We simply want the chance, with a search warrant, to try to guess the terrorist’s passcode without the phone essentially self-destructing and without it taking a decade to guess correctly. That’s it. “We don’t want to break anyone’s encryption or set a master key loose on the land,” Comey continued. “I hope…

That's a lot of double-speak. They know that removing the timeout so they can try thousands of passwords per second opens up a huge security hole. What he's saying is "we want it both ways". We don't want to take away security for users, we just want to make it easier for someone who's not the owner of the phone to get into it.

The government owned the iPhone in question.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#73
post #7

To me this raises a question about selling security vulnerabilities to state actors in general (in the context of the Facebook vulnerability thread where the standard discussion about value is being hashed out). Specifically, I live in the UK and one of the complaints law enforcement has is that US companies can (and do) totally ignore valid court orders because they don't apply in the US (reddit being an arbitrary c…

Uh, state actors (including GCHQ) already are some of the primary buyers of vulnerabilities.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#75
I'm trying to see what's around the corner for this argument.

Sure they can go to congress and push for increased funding or whatever for their top cases. Which gives congress a tangible budget number that could be "saved" by passing a law, but politics/congress doesn't really work this way - spending money benefits the administrating critters, the FBI, and the contractors doing the work.

Furthermore, $1M is essentially a small amount and obviously "worth it" for the major sensational events that they'd use to push through backdoors. So it seems they're actually giving up ground by having to move the argument to the urgency for backdoors in cases that aren't worth $1M.

I can see the argument playing for fiscal-primacy authoritarians who would take this as an example of government waste, but they'd already support government backdoors and I don't see this riling them up enough to be worth it.

It seems like a dead-end for propaganda purposes. What am I missing?

Maybe they're just trying to salt the earth so that their technical success in this case does not hinder them arguing for backdoors next time?

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#76
post #69

What evidence is there that the phone was actually hacked? Wouldn't saying "ah never mind we hacked it" be a convenient way out of a precedent-setting court case the FBI was losing?

Except the other cases haven't been dropped, and this case was perhaps the one most sympathetic to the government (terror).

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#77
post #38

Earlier quoted context omitted.

False dichotomy is false. They didn't have to do this, and by all accounts, received nothing of value for the money.

> by all accounts, received nothing of value for the money How can you know that?

I can't KNOW it, which is why I said, "By all accounts".

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#78
Given that they found no relevant information on his work phone, exactly as experts and reasonable amateurs and common men predicted, how was it "worth it" as he claims? Is it that wasting huge sums of taxpayer money while attacking civil rights and attempting to instantiate a police surveillance state with no privacy is simply "worth it" no matter what, even if pointless?

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#79

Earlier quoted context omitted.

False dichotomy is false. They didn't have to do this, and by all accounts, received nothing of value for the money.

Don't they have a tool to get into other iPhone's now? $1,000,000 doesn't seem too bad.

There is no indication that it wasn't what had been claimed they could always do, and that's physically clone NAND gates. Remember, the FBI wasn't after data in the first place, they were after a legal precedent.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#80

Earlier quoted context omitted.

> was not “scalable.” This is the same James Comey that said they just were just asking Apple for access to just that one phone.

Well, heads of US security apparatuses haven't seemed to be capable of anything beyond immediate contradiction lately

To me they seem to be a step behind. Maybe they're just too old.
Post reply on HN