How the FBI cracked the San Bernardino iPhone and why your device isn’t safe

2

The FBI and Apple spent weeks screaming at each other. It looked like a family drama. Parents yelling, kids slamming doors. But this wasn’t about Snapchat or dinner table manners. This was about privacy, government power, and terrorism.

The government won. At least for this chapter.

The FBI cracked the iPhone belonging to one of the San Bernardino shooters. They got the data. They did it with help from hackers who aren’t exactly household names, but they got in.

Now the questions are louder than the yelling.

Who was right? What did they find? Will they share the hack? What does Apple do now?

And the big one: How did they actually crack the iPhone?

The reality of unlocking a locked iPhone

Robert Siciliano, an identity theft and mobile phone security expert, says he doesn’t know the technical details yet. He suspects we will. That is the problem. Once the method leaks, it spreads.

NBC News reports that an Israeli firm called Cellebrite helped the FBI. The secret is out. It can be done. The FBI has already said it will help other agencies with locked phones.

This isn’t surprising if you live in tech. Engineers build. Hackers break. Usually, it’s criminals breaking in. This time, it was the government.

Siciliano puts it bluntly.

“With every technology, whether it’s Microsoft, Android, Apple’s iPhone — heck it could be your car, it’s your friggin’ toaster, your refrigerator… with every technology, there’s a way to game it. There’s always a way to game it.”

That is the moral of the story. No matter how secure you think your iPhone is, someone wants to break it. The chase never stops.

How hackers bypass iOS security

Technically, the best way into a locked device is the passcode. You enter the numbers. You get in.

But hackers don’t ask nicely. They look for flaws in the operating system. They search the Interwebs for exploits. Some work. Some don’t.

The goal is to bypass the lock screen.

Sometimes it’s an arcane algorithm. Sometimes it’s a guess. Getting past the gate is what matters.

We know how to protect ourselves. We play games with hacked birds. We know the drill.

  • Password protect everything.
  • Use strong passwords.
  • Avoid unsecured Wi-Fi.
  • Secure your home network.
  • Don’t click links from random princes.
  • Don’t flash your tech on the train.

Most importantly, assume the worst. Assume your phone will be compromised. Don’t put sensitive data on it if you can’t handle that risk.

Siciliano compares digital safety to a factory floor. You don’t just put on a hard hat once and forget it. You wear it all day. It’s a process.

“Safety is a process… There’s no such thing as 100 percent safety or security, ever. And that never will be.”

So change your passcode. Delete those embarrassing selfies. Do it now. Before anyone shows up.

Methods used to exploit iOS vulnerabilities

No one knows exactly how Cellebrite got into Syed Farook’s iPhone. The FBI keeps that card close to its chest.

The most likely method involves exploiting a hole in the iOS operating system. Many online videos show this. It’s called a zero-day exploit. It finds a crack in the code that Apple hasn’t patched yet.

But there are physical methods too.

Hackers can reset memory chips. This allows them to have multiple tries at the passcode. Normally, the phone locks or erases data after too many wrong guesses. Resetting the chip resets that counter.

The Institute of Electrical and Electronics Engineers suggests five potential ways this happened.

We don’t need to know the exact code to know the truth. The lock is not unbreakable. Apple proved it by fighting the FBI. The FBI proved it by breaking the phone.

Your data is safer than you think. It is also less safe than you hope.

Keep your eyes open. Change the password again. Then again later.