Hacker Leaks Cellebrite’s iOS Bypassing Tools, Tells FBI ‘Be Careful What You Wish For’

It’s been nearly a year since a U.S. federal judge originally ordered Apple to help the FBI hack into an iPhone owned by Syed Farook, one of the shooters in the December 2015 attacks in San Bernardino. As we learned in the months after the initial court order — which Apple continually opposed — the FBI enlisted the help of Israeli mobile software developer Cellebrite to open up the iPhone 5c in question.

Now a hacker has reportedly stolen and publicly released a cache of Cellebrite’s most sensitive data, including its tools used to hack into older iPhones, as well as Android and BlackBerry smartphones (via Motherboard). Techniques that the firm uses to open “newer iPhones” were not included in the public posting, but it’s also not clear exactly which models of iPhone are considered “older.” Farook’s iPhone 5c, which launched in 2013, is likely in that category.


Apple’s main stance against the court order last year was its fear that creating such an operating system that bypassed the iPhone’s basic security features — essentially creating a “master key” for all iOS devices — would set a “dangerous precedent” for the future of encryption and security. The bypass could also potentially make its way into the public and affect hundreds of millions of Apple customers, with Apple CEO Tim Cook claiming that the software the FBI wanted to use to force open Farook’s iPhone was “the equivalent of cancer.”

As pointed out by Motherboard, the newly leaked tools “demonstrate that those worries were justified.” According to the hacker in question who shared Cellebrite’s tools on Pastebin, the purpose behind the leak was to highlight the importance of the inevitability that any brute force tools aimed at bypassing encryption software “will make it out” into the public.

“The debate around backdoors is not going to go away, rather, its is almost certainly going to get more intense as we lurch toward a more authoritarian society,” the hacker told Motherboard in an online chat.

“It’s important to demonstrate that when you create these tools, they will make it out. History should make that clear,” they continued.

Back in January the same hacker stole 900GB of sensitive Cellebrite data, but according to a Cellebrite spokesperson, only its customers’ “basic contact information” had been put at risk. Delving into the cache of information, it was proven that the breach had uncovered much more detailed “customer information, databases, and a vast amount of technical data regarding Cellebrite’s products.”

In a README file posted alongside the more recent data dump on Pastebin, the hacker in question left a message directly addressing the FBI: “@FBI Be careful in what you wish for.”

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Tags: Apple-FBI, Cellebrite

Discuss this article in our forums

You can follow iPhoneFirmware.com on Twitter, add us to your circle on Google+ or like our Facebook page to keep yourself updated on all the latest from Apple and the Web.