Get all your news in one place.
100’s of premium titles.
One app.
Start reading
The Guardian - UK
The Guardian - UK
Technology
Samuel Gibbs

FBI paid professional hackers to gain access to San Bernardino iPhone – report

iphone 5c
Should the iPhone 5C hack bought by the FBI be sold or passed onto cybercriminals, millions of older iPhones could be left vulnerable to hacking. Photograph: Rex/Zuma

The FBI reportedly bought a previously unknown security bug from a group of professional hackers to gain entry to the San Bernardino iPhone 5C, according to the Washington Post.

The report suggests hackers supplied at least one so-called zero-day flaw in the iPhone 5C’s security that allowed the FBI to circumvent the lockscreen and automatic wipe feature that kicks in after 10 wrong passcode entries.

The hack meant the FBI dropped its attempt to force Apple to create software to unlock the iPhone 5C, which the company said would put all iPhones at risk.

The FBI has already clarified that the hack bought for a one-time-fee cannot break into newer iPhones, including the iPhone 5S or later, but the hack could affect any iPhone 5C or older, including the iPhone 5 and 4S.

The hackers are said to be professional security experts who probe software, devices and services to find vulnerabilities that they can exploit. They then sell the bugs to governments and third-parties, including those who make surveillance tools similar to the software exposed during a data breach of Italian firm Hacking Team.

The security bugs are not disclosed to the makers of the software or hardware, in this case Apple, because they only retain value while functional. The US government has yet to decide whether it will disclose the vulnerability to Apple, but its hand may be forced if it is required to disclose the information in a criminal case under the rules of discovery.

It is unknown how the hack operates or whether the hackers sold the flaw to any other agencies or third-parties, but if it is not disclosed to and fixed by Apple, it could leave anyone with an iPhone without a fingerprint sensor at risk of having their smartphone hacked.

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.