Privacy Advocates Cite NSA Hack as Vindication of Apple's Fight With FBI - MacRumors
Skip to Content

Privacy Advocates Cite NSA Hack as Vindication of Apple's Fight With FBI

Seal_of_the_United_States_National_Security_AgencyPrivacy advocates have claimed the breach of hacking tools and exploits apparently stolen from the National Security Agency has vindicated Apple's stance in its dispute with the FBI earlier this year.

Last week, reports emerged that a hacker group called the "Shadow Brokers" had allegedly stolen a cache of the NSA's top espionage tools and offered to sell them to the highest bidder.

The malware was linked to the "Equation Group", a secretive team of cyber spies widely believed to be associated with the NSA and its state partners. The hacking collective that stole the malware posted two sets of files online, including a free sample of the stolen data, which dates back to 2013, and a second encrypted file whose decryption key went up for sale in a bitcoin auction. Many saw the auction as a stunt.

But the attack code posted by the hackers appeared to be real, according to former NSA personnel who worked in the agency's hacking division, known as Tailored Access Operations (TAO).

"Without a doubt, they're the keys to the kingdom," said one former TAO employee, who spoke to The Washington Post on the condition of anonymity to discuss sensitive internal operations. "The stuff you're talking about would undermine the security of a lot of major government and corporate networks both here and abroad."

"It's a big deal," said Dave Aitel, an ex-NSA research scientist and CEO of penetration testing firm Immunity. "We'd be panicking." Whistle-blowing website Wikileaks tweeted that it also had the data and would release it "in due course".

News of the leak has been closely followed by technology companies, many of whom pushed back against the U.S. Senate Intelligence Committee's attempts to force them to provide "technical assistance" to government investigators seeking locked data.

The failed attempt to enact legislation came after Apple publicly clashed with the FBI over the government agency's insistence that it create a "back door" to its iPhone software.


The FBI claimed the software was needed to break into the iPhone owned by Syed Farook, one of the shooters in the December attack in San Bernardino, California. Apple refused to comply with the request, claiming that the code would lead to weaker smartphone encryption and inevitably get into the wrong hands.

Now, after a top-secret archive of some of the NSA's own exploits having been leaked online, privacy advocates are suggesting Apple's stance has been vindicated.

"The component of the government that is supposed to be absolutely best at keeping secrets didn't manage to keep this secret effectively," said Nate Cardozo, a senior staff attorney with the Electronic Frontier Foundation who spoke to Business Insider.

The NSA's stance on vulnerabilities seems to be based on the premise that secrets will never get out. That no one will ever discover the same bug, that no one will ever use the same bug, that there will never be a leak. We know for a fact, that at least in this case, that's not true.

Ex-NSA scientist Aitel believes the most likely scenario is that an insider walked out of a secure area with this data on a USB key, which could have been sold or stolen. "No one puts their exploits on a [command-and-control] server," Aitel said. "That's not a thing."

Another possibility suggested by NSA whistleblower Edward Snowden is that the malware toolkit was stolen from a "staging server" or segregated network outside the walls of the NSA, where it was used for conducting attacks. Snowden has also pointed to Russia as the chief suspect behind the leak.

News of the hack has also raised new questions about the legalities of government hacking, since many of the "zero day" exploits included in the leak have never been disclosed to the companies whose hardware is affected.

A policy framework called the Vulnerabilities Equities Process outlines how and when the state should disclose a vulnerability to an affected company if the larger security risk is greater than the reward it could yield. The FBI has informed Apple of security flaws in older versions of iOS and OS X in the past under the VEP framework.

However, Cardozo argues that the rules are "completely broken" because the VEP guidance is a non-binding policy created by the Obama administration, rather than an executive order or law. "We need rules, and right now there aren't any," Cardozo said. "Or at least none that work."

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Popular Stories

8 CarPlay Features in iOS 27 Feature

Which iOS 27 CarPlay Features Actually Work in Your Car?

Thursday September 17, 2026 4:17 am PDT by
In iOS 27, available now, CarPlay gets its biggest update in years, but some features depend on what type of car you have rather than your iPhone model. Some of the biggest additions won't do anything in the vast majority of vehicles on the road today. Here's how the new features pan out. Works in Any CarPlay Vehicle Custom widgets: In iOS 27, CarPlay is no longer limited to Apple's handful ...
Apple Watch New Charging Puck

Here's Why a New Apple Watch Charging Puck Was Just Released

Wednesday September 16, 2026 8:53 am PDT by
The new Apple Watch Series 12 and Apple Watch Ultra 4 have hardware changes that allow for faster charging, but you will need to use the new version of the Apple Watch Magnetic Fast Charger included in the box in order to achieve this boost. If you need extra ones for your own charging stands or travel or so forth, Apple released the new version of the charger on its online store last week, with...
ios272anniversary

iOS 27.2 Could Save Your Marriage

Wednesday September 16, 2026 1:32 pm PDT by
The iOS 27.2 beta that Apple released today adds a feature that reminds you it's your anniversary when you call someone, as long as you've added the date in the Contacts app. On the date of your anniversary, when you go to call the person, you'll see a reminder that it's an important day so you don't forget to say something. The anniversary alert uses Call Context, a feature Apple added in...

Top Rated Comments

keysofanxiety Avatar
132 months ago
Oops. Wish I could say this news was surprising. It was only a matter of time.
Score: 24 Votes (Like | Disagree)
132 months ago
So.. they wanted Apples backdoor exploit and stated that they would "keep it safe and secure" but couldn't keep their own "safe and secure"? K.
Score: 22 Votes (Like | Disagree)
SGT.GREER Avatar
132 months ago
Anyone with two brain cells saw this a mile away.
Score: 21 Votes (Like | Disagree)
djcerla Avatar
132 months ago
This is the knock-out punch for the Backdoors Party.
Score: 11 Votes (Like | Disagree)
OllyW Avatar
132 months ago
Not in the Politics section!
I'm sure it will be soon.
Score: 10 Votes (Like | Disagree)
VulchR Avatar
132 months ago
Europeans are among the worst when it comes to data protection and privacy!
Based on what evidence? I work for a UK university. Believe me, they take data security and privacy very seriously indeed.
Score: 9 Votes (Like | Disagree)