Showing posts with label FBI. Show all posts

Apple's FBI row is only just beginning

Tim CookYou could forgive Apple's legal team for coming across a little exasperated on Monday evening.
Just hours before its day in court - in the town of Riverside, California - the most unexpected twist yet: the trial had been postponed, perhaps indefinitely.
The FBI said it had, "this past weekend", been shown a way to unlock the iPhone used by San Bernardino gunman Rizwan Farook.
The FBI has until 5 April to let the court know how it gets on. If the method doesn't work, and the phone is still locked, we'll probably return to Riverside for the hearing.
If it is successful - then, well, who knows what will happen? Uncharted waters. The case, already the most fascinating tech legal tussle for years, enters murky territory.
And here's why. Let's say, for arguments sake, that the FBI does indeed have a new, credible method of getting into the iPhone.
Where on Earth did it come from?

Exhausted avenues

Apple's bewilderment is understandable given that, right up until the final hour, the FBI had insisted it had exhausted every possible route. It told Congress as much.
In a hearing earlier this month, FBI director James Comey stood firm as Congressman Darrell Issa gave him a dramatic dressing down for not pursuing a technique known as mirroring - essentially, and I'm simplifying here, duplicating the phone so repeated attempts can be made to unlock it without disturbing the original.
Mr Comey said he'd look into it - though that was 20 days ago.
James ComeyImage copyrightGetty Images
Image captionJames Comey had said the FBI needed Apple to help it gain access to the iPhone
Also during that congressional hearing, Mr Issa pressed Mr Comey on whether he had asked the National Security Agency (NSA) for its help.
In response, Mr Comey, making reference to the particular model of iPhone and the software contained on it, said: "We have engaged all parts of the US government to see does anybody have a way, short of asking Apple to do it, with a 5C running iOS 9 - to do this, and we do not."
Had Tuesday's hearing gone ahead, we were expecting to hear the witness testimony of Stacey Perino, an FBI electronics engineer, and Christopher Pluhar, a computer forensics professor from California State University.
Both were due to underline that Apple, and only Apple, would be able to break into the phone.
Prof Pluhar, who is a supervisory agent for the FBI, had in the past said he had been "unable to identify any other methods feasible for gaining access to the currently inaccessible data stored within the subject device".

Reputation at risk

But we're being told to put all that aside for a moment because the FBI has said it is "cautiously optimistic" a new method suggested by an as-yet unknown "outside party" could solve all its problems, allowing investigators access to the iPhone without Apple's help.
Apple's legal team has said it has no idea what that vulnerability could be - but it, of course, didn't rule out the possibility it existed.
After all, it's software - and no piece of software ever written has even been watertight.
Every time you update your phone, computer, tablet, it's often to plug a few new security holes.
So if, come 5 April, the FBI says it no longer needs Apple's help, it would mean the US government has knowledge of a cybersecurity vulnerability that potentially affects each and every iPhone out there.
Apple protestImage copyrightGetty Images
Image captionSome protesters supported Apple but the American public was split over the matter
Now, typically when something like this is discovered, and it happens fairly often, security researchers engage the company affected in a process called "responsible disclosure".
They tell the company privately about the flaw, and then agree how to make the issue public.
When the responsible disclosure system works, the problem is fixed before the public finds out.
It makes devices safer, and shares the discovery among everyone involved in computer security.
So keen are companies to encourage this kind of approach that many offer "bug bounties" - cash prizes for people who report new critical bugs.
Hackers that operate in this way are known as "white hat". The good guys.
The alternative - black hat - is to not tell the company about a flaw and instead sell the vulnerability on the black market to any buyer, be it for secret, state-sponsored activity, or simply for criminal means.
If the method proposed by the "outside party" works, here's the question: will the FBI engage in responsible disclosure with Apple after it has accessed the iPhone used by Farook?
If it does, Apple will surely seek to fix the flaw immediately, putting us back to square one when the inevitable next case comes around.
But if the FBI doesn't share the method, what will that do to the reputation of Apple's products if it's known the US government is openly in possession of a security flaw of this magnitude?

FBI 'may be able to unlock San Bernardino iPhone

The FBI says it may have found a way to unlock the San Bernardino attacker's iPhone without Apple's assistance.
A court hearing with Apple scheduled for Tuesday has been postponed at the request of the US Justice Department (DOJ), Apple has confirmed.
The DOJ had ordered Apple to help unlock the phone used by San Bernardino gunman Rizwan Farook.
But Apple has continued to fight the order, saying it would set a "dangerous precedent".
Rizwan Farook and his wife killed 14 people in San Bernardino, California, last December before police fatally shot them.
Grey line

Analysis: Dave Lee, BBC North America technology reporter

Ever since this issue arose, security experts have been saying "surely the FBI can do this themselves?" Well, maybe now they can.
An "outside party" - you'd assume a security company, but we don't know for sure - has approached the FBI and said it could unlock the phone.
If they can do it, the court case is irrelevant. The FBI gets what they need. But if it doesn't work, we'll find ourselves back here to resume the trial.
Apple's legal team told reporters it wasn't treating it as a legal victory. The issue still looms large over the company. If the FBI has found a way, who's to say it'll always work? Apple will, as any software maker would, frantically try and fix the flaw. After all - if the FBI can do it, so can any other hacker privy to the same information.
If this method works, then what? With each new iteration of iOS, Apple could find itself back in court.
The technology industry, led by Apple, has called for the matter to be debated in Congress. This case may be on the brink of going away, but the debate is just starting.
Grey line
Prosecutors said "an outside party" had demonstrated a possible way of unlocking the iPhone without the need to seek Apple's help.
"Testing is required to determine whether it is a viable method that will not compromise data on Farook's iPhone," a court filing said.
"If the method is viable, it should eliminate the need for the assistance from Apple."
DOJ spokeswoman Melanie Newman said in a statement that the government was "cautiously optimistic" that the possible method to unlock the phone would work.
The government said it would update the court on 5 April.
2014 file image of Tashfeen Malik, left, and Rizwan Farook, as they passed through O'Hare International Airport in ChicagoImage copyrightAP
Image captionRizwan Farook, right, and his wife Tashfeen Malik, killed 14 people at an office party on 2 December
Attorneys for Apple told reporters that the firm had no idea what method the FBI was exploring to try to unlock the phone.
They said they hoped that the government would share with Apple any vulnerabilities of the iPhone that might come to light.
The FBI says Farook and his wife Tashfeen Malik were inspired by so-called Islamic State and that the encrypted iPhone may contain crucial evidence.
It wants to access the data but the device can only be unlocked by entering the correct passcode.
Guessing the code incorrectly too many times could permanently delete all data on the phone, so the FBI had asked Apple to develop a new version of its operating system that circumvents some of its security features.
Last month the DOJ obtained a court order directing Apple to create that software,
But Apple has fought back, stating that creating a compromised version of the operating system would have security implications for millions of iPhone users and would set a precedent.
The company has received support from other tech giants including, Google, Microsoft, and Facebook, as it resisted a court order to unlock the iPhone.