Last month we saw an incredible showdown between the FBI, the Department of Justice, and Apple. The bone of contention was the San Bernardino shooter's iPhone, which Apple refused to unlock for the FBI.
The public confrontation and strongly worded rhetoric from the Justice Department ended when the FBI announced that an Israeli security company would “crack” the terrorist’s cell phone, withdrawing the lawsuit.
For those who don't know, there are many companies that supply zero-day exploits, and usually their best customers are government security agencies.
It is now widely known from Edward Snowden that the government uses zero-day flaws and does not announce it because if it simply reports it to software manufacturers, the security gap will be closed immediately.
Are you still wondering?
So the tweet by Christopher Soghoia of the ACLU probably answers the question in the title: “the government doesn’t disclose security vulnerabilities in companies like Apple,” if they prove useful to law enforcement.
[tweet_embed id=712067889071837184]
Law enforcement agencies that want to use these flaws for surveillance and tech companies that want to patch them immediately to protect their users from hackers. Meanwhile, the intelligence agencies sit right in the middle. The NSA has said before that it discloses the vast majority of zero-days, but it doesn't do so before they are used for the first time.
Will the FBI reveal the flaw when it uses it? “Unlikely,” Soghoian said.
Many believe that an outside security team could help the FBI crack the phone by mirroring the NAND memory, so that the device cannot be erased by brute force attacks no matter how many times password combinations are used.
Whatever flaw is actually exploited, it's no different than the government ordering Apple to rewrite its software to bypass the iPhone's security features, allowing the FBI to use brute force attacks to open the phone.
In any case, think of it as a backdoor that Apple and other tech companies would want to fix immediately like any other vulnerability.
Of course, the above assumptions may turn out to be completely untrue if the FBI plans to immediately deliver the exploit after unlocking the device.
Whatever the case, the US government will have to file a status report with the court by April 5th and we will learn more.
