Live data from Hacker News

FBI Paid More Than $1M to Hack San Bernardino iPhone

wsj.com

1–10 of 206 posts

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#4
post #2

Paywalled for me here in the UK. I assume the title sums up the article? Since I can't read the article, from anyone that can, how did they come to that figure? Is that just the cost of the exploit or..? Cheers

> The Federal Bureau of Investigation paid more than $1 million for a hacking tool that opened the iPhone of a terrorist gunman in San Bernardino, Calif., the head of the agency said Thursday.

> Speaking at the Aspen Security Forum in London, FBI Director James Comey didn’t cite a precise figure for how much the government paid for the solution to cracking the phone but said it was more than his salary for the seven-plus years remaining in his term at the FBI.

> His annual salary is about $180,000 a year, so that comes to $1.26 million or more.

> “[We] paid a lot’’ for the hacking tool, Mr. Comey said. “But it was worth it.’’

I wonder how exactly it's worth it, given that nothing of interest of relevance was found on the device.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#7
To me this raises a question about selling security vulnerabilities to state actors in general (in the context of the Facebook vulnerability thread where the standard discussion about value is being hashed out).

Specifically, I live in the UK and one of the complaints law enforcement has is that US companies can (and do) totally ignore valid court orders because they don't apply in the US (reddit being an arbitrary concrete example).

So, what would be the impact of GCHQ setting up a scheme where you can sell vulnerabilities to them (assuming they do the legwork to make it legal)? Would it violate some kind of trade agreement? I assume at minimum it would harm diplomatic relations given the pressure the big companies would exert on the US to push back.

Re: FBI Paid More Than $1M to Hack San Bernardino iPhone

#10
post #7

To me this raises a question about selling security vulnerabilities to state actors in general (in the context of the Facebook vulnerability thread where the standard discussion about value is being hashed out). Specifically, I live in the UK and one of the complaints law enforcement has is that US companies can (and do) totally ignore valid court orders because they don't apply in the US (reddit being an arbitrary c…

https://en.wikipedia.org/wiki/Treason
Post reply on HN