Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    FBI Exploits Zero-Day on iOS to Hack Terrorist’s iPhone

    Written by

    Sean Michael Kerner
    Published March 29, 2016
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      A new zero-day exploit against Apple’s iOS mobile operating system enables an attacker to bypass a security lockout feature that will erase the device’s contents after 10 unsuccessful passcode tries. The group taking credit for the new zero-day is none other than the FBI.

      As reported on eWEEK yesterday, the FBI has ended its legal case against Apple in which it was trying to force the tech giant to provide a way to help get access to the contents of an iPhone 5c used by Syed Rizwan Farook, a gunman in the Dec. 2 shooting spree in San Bernardino, Calif.

      “The government has now successfully accessed the data stored on Farook’s iPhone and therefore no longer requires the assistance from Apple Inc. mandated by Court’s Order Compelling Apple Inc. to Assist Agents in Search dated February 16, 2016,” the Department of Justice’s legal filing on the matter simply states.

      The original court order had asked Apple to assist the DOJ by helping the FBI “bypass or disable the auto-erase function” on the iPhone 5c. As part of iOS’ security, iPhones have a passcode that protects access to the device and its contents. An additional security capability can be enabled that will erase the contents of a device after a specified number of incorrect passcode attempts. The FBI obviously didn’t want to trigger the auto-erase function; otherwise, the agency could have attempted to just “brute-force” the password, spooling through all the possible passcode combinations.

      As part of the original court order, the DOJ also requested that Apple’s technical assistance include “providing the FBI with a signed iPhone Software file, recovery bundle or other Software Image File (‘SIF’) that can be loaded on the subject device.”

      Apple CEO Tim Cook balked at the request, steadfastly claiming that such a bypass would undermine the security of all iPhone users.

      Now, despite Cook’s lack of cooperation, the FBI has what it wants.

      The precise method used by the FBI has not been publicly disclosed, though there is no shortage of speculation and possible options. Perhaps the FBI has in fact found a flaw in iOS and/or the mobile device management capability that would have triggered the auto-erase function. Perhaps the FBI found a way to clone the contents of the entire device, such that they can in fact attempt to brute-force the password without fear of erasing the only version of the data. Or perhaps the FBI found a way to physically bypass the software security provided by Apple by directly accessing the hardware on the iPhone 5c to pull data from the device at the electrical level or some other intricate means.

      Whatever the method, the simple fact of the matter is that it is now possible to bypass the passcode security auto-erase function on an iPhone 5c, and there is no known fix. In the security business, that’s typically what security researchers will call a zero-day exploit.

      So far as is publicly known at this point, only the FBI has this powerful new zero-day exploit. There is no way of knowing if the exploit has been made available to other governments around the world. There was some speculation last week, when the DOJ first asked to delay a legal court hearing with Apple, that an Israeli firm was now on the FBI payroll helping to bypass the iPhone 5c’s security. That speculation has not been officially confirmed, nor has any public admission yet been made by the DOJ or the FBI that it paid to acquire the bypass from any third party.

      No doubt, Apple today is pressuring the DOJ to find out what the bypass is so that it can fix the issue, protecting all iOS users. In a normal responsible disclosure process, a security researcher would report a zero-day issue to a vendor, so that the vendor could fix the issue before it becomes widely exploited. It’s not clear what, if any, formal disclosure will happen in this case.

      Of all the possible situations that could have enabled the iPhone 5c bypass, this scenario—where the FBI now has access to such an exploit that neither Apple nor anyone else knows about—is not a great one. Had Apple been forced to comply with the DOJ, perhaps there could have been some controls in place on usage of the mechanism and some form of tracking. Now Apple is on the outside looking in, wondering how this all happened.

      What exists now is a dangerous situation, where a working bypass, or a zero-day exploit, exists for one of the most popular technology platforms on the planet. Hopefully, this bypass only exists in the hands of good, law-abiding people who will not abuse this power and only use it in the interest of national security.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.