FBI Used Security Flaw Found by 'Professional Hackers' to Crack San Bernardino Shooter's iPhone

Rumors have suggested the FBI employed Israeli mobile forensics firm Cellebrite to hack into the iPhone 5c used by San Bernardino shooter Syed Farook, but new information from The Washington Post suggests it was instead done with the help of "professional hackers" at least one of which is a "gray hat" researcher that sells flaws to governments, black market groups, or companies that create surveillance tools.

According to sources who spoke to The Washington Post, the hackers told the FBI about a previously unknown software flaw, which was used to "create a piece of hardware" the FBI used to access the phone via its passcode. The hardware in question allowed the FBI to guess the passcode through multiple attempts without erasing the iPhone.

iphone5c

The new information was then used to create a piece of hardware that helped the FBI to crack the iPhone's four-digit personal identification number without triggering a security feature that would have erased all the data, the individuals said.

The researchers, who typically keep a low profile, specialize in hunting for vulnerabilities in software and then in some cases selling them to the U.S. government. They were paid a one-time flat fee for the solution.

The method the FBI allegedly used to break into the iPhone is similar in description to the tool that it had requested from Apple. Before finding an alternate way into the iPhone, the FBI had demanded Apple create a new version of iOS that would disable the passcode security features built into the operating system.

Apple was ordered to give the FBI software to disable the erase feature that would have wiped the iPhone after 10 incorrect guesses, eliminate the time added between entry attempts after the wrong passcode was entered, and create a way for the FBI to enter passcodes into the device electronically instead of manually.

The FBI did not need the services of Cellebrite "in this case," according to The Washington Post's sources, despite evidence the FBI signed a $15,000 contract with Cellebrite on March 21, the same day the Justice Department asked the court to postpone its imminent hearing with Apple. The tool acquired from the hackers did end up letting the FBI access the phone, leading the case against Apple to be dropped.

The U.S. government has not decided whether the method used to break into the iPhone will be shared with Apple, but FBI director James Comey has said the tool used to access the iPhone only works on a "narrow slice of phones" that does not include the iPhone 5s and later. Apple does not plan to sue to obtain the information.

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Top Rated Comments

aaronvan Avatar
104 months ago
FBI hacked the iPhone but they still can't decide what to do about Hillary's email server...
Score: 63 Votes (Like | Disagree)
Technarchy Avatar
104 months ago
Damage control story. FUD, psy-ops / counter ops misinformation.
Score: 19 Votes (Like | Disagree)
paradox00 Avatar
104 months ago
Exactly what Apple didn't want to happen happened.
Hardly. Apple can fix security flaws, they can't fix precedent. In court documents, Apple specifically stated that they didn't believe the FBI had exhausted all their efforts to hack the phone. This is proof Apple was right about that. Apple wanted the case to move forward (because they expected to win), but this is hardly the worst case scenario.
Score: 14 Votes (Like | Disagree)
vjl323 Avatar
104 months ago
Or they used PhoneView, an app for Mac that allows one to view contacts, messages, photos, call history, etc without typing in the passcode.
That's 100% untrue. I use PhoneView - it requires the phone to be unlocked just like iTunes in order to trust the computer it is attached to. You may not remember it, but when you first ran it, like iTunes, the phone prompted you, asking if you wish to trust the Mac/PC it is attached to.
Score: 9 Votes (Like | Disagree)
Nunyabinez Avatar
104 months ago
Damage control story and FUD, psy-ops / counter ops misinformation.
And a way to make Apple look bad. "Yeah, we got into the phone that Apple said was so secure that they couldn't get into unless they wrote new software, and we did it by exploiting a security flaw."
Score: 8 Votes (Like | Disagree)
CarlJ Avatar
104 months ago
The U.S. government has not decided ('https://www.macrumors.com/2016/04/05/fbi-iphone-data-still-under-analysis/') whether the method used to break into the iPhone will be shared with Apple, but FBI director James Comey has said the tool used to access the iPhone only works ('https://www.macrumors.com/2016/04/07/fbi-director-unlocking-iphone/') on a "narrow slice of phones" that does not include the iPhone 5s and later.
No no, the FBI swore up and down that this whole deal to have Apple create a special one-off version of iOS for them was JUST FOR THIS ONE PHONE, so I'm sure they'll be handing the exploit they used over to Apple, so that Apple can fix it to protect their customers from hackers. After all, the FBI wouldn't want to contribute to evil hackers breaking into citizen's phones.
Score: 8 Votes (Like | Disagree)

Popular Stories

reset password request iphone

Warning: Apple Users Targeted in Phishing Attack Involving Rapid Password Reset Requests

Tuesday March 26, 2024 4:34 pm PDT by
Phishing attacks taking advantage of Apple's password reset feature have become increasingly common, according to a report from KrebsOnSecurity. Multiple Apple users have been targeted in an attack that bombards them with an endless stream of notifications or multi-factor authentication (MFA) messages in an attempt to cause panic so they'll respond favorably to social engineering. An...
maxresdefault

Apple to Launch New iPad Pro and iPad Air Models in May

Thursday March 28, 2024 11:07 am PDT by
Apple will introduce new iPad Pro and iPad Air models in early May, according to Bloomberg's Mark Gurman. Gurman previously suggested the new iPads would come out in March, and then April, but the timeline has been pushed back once again. Subscribe to the MacRumors YouTube channel for more videos. Apple is working on updates to both the iPad Pro and iPad Air models. The iPad Pro models will...
Generic iOS 18 Feature Purple

iOS 18: What to Expect From 'Biggest' Update in iPhone's History

Wednesday March 27, 2024 11:10 am PDT by
At least some Apple software engineers continue to believe that iOS 18 will be the "biggest" update in the iPhone's history, according to Bloomberg's Mark Gurman. Below, we recap rumored features and changes for the iPhone. "The iOS 18 update is expected to be the most ambitious overhaul of the iPhone's software in its history, according to people working on the upgrade," wrote Gurman, in a r...
maxresdefault

Apple Announces WWDC 2024 Event for June 10 to 14

Tuesday March 26, 2024 10:02 am PDT by
Apple today announced that its 35th annual Worldwide Developers Conference is set to take place from Monday, June 10 to Friday, June 14. As with WWDC events since 2020, WWDC 2024 will be an online event that is open to all developers at no cost. Subscribe to the MacRumors YouTube channel for more videos. WWDC 2024 will include online sessions and labs so that developers can learn about new...
apple maps 3d feature

Apple Maps May Gain Custom Routes With iOS 18

Tuesday March 26, 2024 3:10 pm PDT by
Apple may be planning to add support for "custom routes" in Apple Maps in iOS 18, according to code reviewed by MacRumors. Apple Maps does not currently offer a way to input self-selected routes, with Maps users limited to Apple's pre-selected options, but that may change in iOS 18. Apple has pushed an iOS 18 file to its maps backend labeled "CustomRouteCreation." While not much is revealed...
General iOS 17 Feature Orange Purple

Apple Releases Revised Versions of iOS 17.4.1 and iPadOS 17.4.1 With Updated Build Number

Wednesday March 27, 2024 5:59 am PDT by
Apple on late Tuesday released revised versions of iOS 17.4.1 and iPadOS 17.4.1 with an updated build number of 21E237, according to MacRumors contributor Aaron Perris. The updates previously had a build number of 21E236. The revised updates are available for all iPhone and iPad models that are compatible with iOS 17 and iPadOS 17, but they can only be installed via the Finder app on macOS...
applephilschiller

Apple's Phil Schiller Works 80 Hours a Week Overseeing App Store

Wednesday March 27, 2024 2:03 pm PDT by
With the App Store and app ecosystem undergoing major changes in the European Union, The Wall Street Journal today shared a profile on App Store chief Phil Schiller, who is responsible for the App Store. Though Schiller transitioned from marketing chief to "Apple Fellow" in 2020 to take a step back from Apple and spend more time on personal projects and friends, he is reportedly working...