FBI Used Security Flaw Found by 'Professional Hackers' to Crack San Bernardino Shooter's iPhone

Rumors have suggested the FBI employed Israeli mobile forensics firm Cellebrite to hack into the iPhone 5c used by San Bernardino shooter Syed Farook, but new information from The Washington Post suggests it was instead done with the help of "professional hackers" at least one of which is a "gray hat" researcher that sells flaws to governments, black market groups, or companies that create surveillance tools.

According to sources who spoke to The Washington Post, the hackers told the FBI about a previously unknown software flaw, which was used to "create a piece of hardware" the FBI used to access the phone via its passcode. The hardware in question allowed the FBI to guess the passcode through multiple attempts without erasing the iPhone.

iphone5c

The new information was then used to create a piece of hardware that helped the FBI to crack the iPhone's four-digit personal identification number without triggering a security feature that would have erased all the data, the individuals said.

The researchers, who typically keep a low profile, specialize in hunting for vulnerabilities in software and then in some cases selling them to the U.S. government. They were paid a one-time flat fee for the solution.

The method the FBI allegedly used to break into the iPhone is similar in description to the tool that it had requested from Apple. Before finding an alternate way into the iPhone, the FBI had demanded Apple create a new version of iOS that would disable the passcode security features built into the operating system.

Apple was ordered to give the FBI software to disable the erase feature that would have wiped the iPhone after 10 incorrect guesses, eliminate the time added between entry attempts after the wrong passcode was entered, and create a way for the FBI to enter passcodes into the device electronically instead of manually.

The FBI did not need the services of Cellebrite "in this case," according to The Washington Post's sources, despite evidence the FBI signed a $15,000 contract with Cellebrite on March 21, the same day the Justice Department asked the court to postpone its imminent hearing with Apple. The tool acquired from the hackers did end up letting the FBI access the phone, leading the case against Apple to be dropped.

The U.S. government has not decided whether the method used to break into the iPhone will be shared with Apple, but FBI director James Comey has said the tool used to access the iPhone only works on a "narrow slice of phones" that does not include the iPhone 5s and later. Apple does not plan to sue to obtain the information.

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Top Rated Comments

aaronvan Avatar
64 months ago
FBI hacked the iPhone but they still can't decide what to do about Hillary's email server...
Score: 63 Votes (Like | Disagree)
Technarchy Avatar
64 months ago
Damage control story. FUD, psy-ops / counter ops misinformation.
Score: 19 Votes (Like | Disagree)
paradox00 Avatar
64 months ago
Exactly what Apple didn't want to happen happened.
Hardly. Apple can fix security flaws, they can't fix precedent. In court documents, Apple specifically stated that they didn't believe the FBI had exhausted all their efforts to hack the phone. This is proof Apple was right about that. Apple wanted the case to move forward (because they expected to win), but this is hardly the worst case scenario.
Score: 14 Votes (Like | Disagree)
vjl323 Avatar
64 months ago
Or they used PhoneView, an app for Mac that allows one to view contacts, messages, photos, call history, etc without typing in the passcode.
That's 100% untrue. I use PhoneView - it requires the phone to be unlocked just like iTunes in order to trust the computer it is attached to. You may not remember it, but when you first ran it, like iTunes, the phone prompted you, asking if you wish to trust the Mac/PC it is attached to.
Score: 9 Votes (Like | Disagree)
Nunyabinez Avatar
64 months ago
Damage control story and FUD, psy-ops / counter ops misinformation.
And a way to make Apple look bad. "Yeah, we got into the phone that Apple said was so secure that they couldn't get into unless they wrote new software, and we did it by exploiting a security flaw."
Score: 8 Votes (Like | Disagree)
CarlJ Avatar
64 months ago
The U.S. government has not decided ('https://www.macrumors.com/2016/04/05/fbi-iphone-data-still-under-analysis/') whether the method used to break into the iPhone will be shared with Apple, but FBI director James Comey has said the tool used to access the iPhone only works ('https://www.macrumors.com/2016/04/07/fbi-director-unlocking-iphone/') on a "narrow slice of phones" that does not include the iPhone 5s and later.
No no, the FBI swore up and down that this whole deal to have Apple create a special one-off version of iOS for them was JUST FOR THIS ONE PHONE, so I'm sure they'll be handing the exploit they used over to Apple, so that Apple can fix it to protect their customers from hackers. After all, the FBI wouldn't want to contribute to evil hackers breaking into citizen's phones.
Score: 8 Votes (Like | Disagree)

Top Stories

microsoft edge ios android

Bill Gates Says His Preference for Android Over iPhone is Due to Pre-Installed Software

Friday February 26, 2021 3:35 am PST by
Microsoft co-founder Bill Gates this week participated in his first meeting on Clubhouse, the increasingly popular invite-only conversation app, where he fielded a range of questions as part of an ongoing book tour. Gates was interviewed by journalist Andrew Ross Sorkin, and given that the Clubhouse app is currently only available on iOS, naturally one of the questions that came up was...
Top Stories 47 Feature copy

Top Stories: MacBook Pro, iMac, and AirPods Rumors, macOS 11.2.2, MagSafe Wallet Revisited

Saturday February 27, 2021 6:00 am PST by
March is right around the corner, and that means our first good opportunity for Apple product launches in 2021 as the company frequently has significant launches in March or April each year. We're hearing rumors about MacBook Pro, iMac, AirPods, and more, although many of these will be coming out at different times over the course of the year. This week also saw a macOS update to address a ...
iphone 6 in hand

Apple Faces Another iPhone Lawsuit Over 'Programmed Obsolescence'

Monday March 1, 2021 6:44 am PST by
Apple faces a new class-action lawsuit that accuses it of deliberately releasing iOS updates that slowly reduce the performance of an iPhone, forcing customers to upgrade their devices. The lawsuit comes from the Portuguese Consumer Protection Agency, Deco Proteste (via Marketeer), which in a statement says that it will proceed with a case against the Cupertino tech giant because it...
maxresdefault

HomeKit Essentials Worth Checking Out

Saturday February 27, 2021 7:05 am PST by
HomeKit was slow to take off after its 2014 launch, but now that it's been around for seven years, there are hundreds of HomeKit products available, ranging from doorbells and speakers to TVs, lights, and cameras. In our latest YouTube video, we rounded up some of our favorite HomeKit products that we find most useful. Subscribe to the MacRumors YouTube channel for more videos. HomePod...
First Look Big Sur Feature2

Apple Releases macOS Big Sur 11.2.2 to Prevent MacBooks From Being Damaged by Third-Party Non-Compliant Docks

Thursday February 25, 2021 10:07 am PST by
Apple today released macOS Big Sur 11.2.2, the fourth update to the macOS Big Sur operating system that launched in November. macOS Big Sur 11.2.2 comes two weeks after the release of macOS Big Sur 11.2.1, a bug fix update. The new ‌‌‌‌macOS Big Sur‌‌‌ 11.2.2‌ update can be downloaded for free on all eligible Macs using the Software Update section of System Preferences....
iphone 12 pro display video

iPhone 13 to Include 1TB Storage Option and LiDAR Across the Board, Says Wedbush Analyst

Monday March 1, 2021 4:00 am PST by
Apple's forthcoming iPhone 13 could include a 1TB storage option for some models and LiDAR Scanners across the entire lineup, according to a report from Wedbush analysts. In a new note to investors, seen by MacRumors, Wedbush analyst Daniel Ives said that initial Asian supply chain checks gave the firm "increased confidence" that Apple's 5G-driven product cycle would extend well into 2022,...
flat mbp 14 inch feature yellow

Redesigned 14-Inch MacBook Pro Expected to Feature Brighter Mini-LED Display With Slimmer Bezels and More

Thursday February 25, 2021 7:48 am PST by
Apple plans to unveil new 14-inch and 16-inch MacBook Pro models with Mini-LED-backlit displays in the second half of this year, according to industry sources cited by Taiwanese supply chain publication DigiTimes. The report claims that Radiant Opto-Electronics will be the exclusive supplier of the Mini-LED backlight units, while Quanta Computer is said to be tasked with final assembly of the...
mac mini developer transition kit photo feature

Apple Requiring Developers to Return DTK Mac Minis by March 31

Friday February 26, 2021 3:57 pm PST by
Apple today sent out emails to developers who are in possession of a Developer Transition Kit, asking them to return the machines by March 31. The Developer Transition Kits are Mac minis with A12Z chips that Apple provided for development purposes ahead of the release of the M1 Macs. Apple in the emails provided developers with shipping instructions, and plans to begin collecting the DTKs...
iphone 12 120hz thumbnail feature

Kuo: iPhone 13 Lineup to Feature Smaller Notch and Larger Batteries, 120Hz Display for Pro Models, and More

Monday March 1, 2021 7:50 am PST by
iPhone 13 models will all feature a smaller notch, while the two Pro models will be equipped with low-power LTPO display technology for a 120Hz refresh rate, analyst Ming-Chi Kuo said today in a research note obtained by MacRumors. Several other sources have previously claimed that some iPhone 13 models will support a 120Hz refresh rate, including display industry analyst Ross Young, leakers ...
unc0ver version 6 release

Jailbreak Tool 'unc0ver' 6.0.0 Released With iOS 14.3 Compatibility

Sunday February 28, 2021 9:26 am PST by
The team behind the "unc0ver" jailbreaking tool for iOS has released version 6.0.0 of its software, which can allegedly be used to jailbreak any device running iOS 11.0 through iOS 14.3 using a kernel vulnerability. The unc0ver website describes how the tool has been extensively tested across a range of iOS devices running various software versions, including an iPhone 12 Pro Max running iOS ...