Print

Print


Australian hacking firm Azimuth breaks into San Bernadino terrorist's iPhone. All along we thought it was Cellebrite.

________________________________

The FBI wanted to unlock the San Bernardino shooter’s iPhone. It turned to a little-known Australian firm.
Azimuth unlocked the iPhone at the center of an epic legal battle between the FBI and Apple. Now, Apple is suing the company co-founded by one of the hackers behind the unlock.
[Image without a caption]
(Jewel Samad/AFP/Getty Images)
By
Ellen Nakashima<https://www.washingtonpost.com/people/ellen-nakashima/> and
Reed Albergotti<https://www.washingtonpost.com/people/reed-albergotti/>
April 14, 2021 at 8:00 a.m. EDT


The iPhone used by a terrorist in the San Bernardino shooting was unlocked by a small Australian hacking firm in 2016, ending a momentous standoff between the U.S. government and the tech titan Apple.

Azimuth Security, a publicity-shy company that says it sells its cyber wares only to democratic governments, secretly crafted the solution the FBI used to gain access to the device, according to several people familiar with the matter. The iPhone was used by one of two shooters whose December 2015 attack left more than a dozen people dead.

The identity of the hacking firm has remained a closely guarded secret for five years. Even Apple didn’t know which vendor the FBI used, according to company spokesman Todd Wilder. But without realizing it, Apple’s attorneys came close last year to learning of Azimuth’s role — through a different court case, one that has nothing to do with unlocking a terrorist’s device.

Five years ago, Apple and the FBI both cast the struggle<https://www.washingtonpost.com/world/national-security/us-wants-apple-to-help-unlock-iphone-used-by-san-bernardino-shooter/2016/02/16/69b903ee-d4d9-11e5-9823-02b905009f99_story.html?itid=lk_inline_manual_8> over the iPhone as a moral battle. The FBI believed Apple should help it obtain information to investigate the terrorist attack. Apple believed that creating a back door into the phone would weaken security and could be used by malicious actors. The FBI sought a court order to compel Apple to help the government. Weeks later, the FBI backed down after it had found<https://www.washingtonpost.com/world/national-security/fbi-paid-professional-hackers-one-time-fee-to-crack-san-bernardino-iphone/2016/04/12/5397814a-00de-11e6-9d36-33d198ea26c5_story.html?itid=lk_inline_manual_8> an outside group that had a solution to gain access to the phone.

The tale of the unlocking of the terrorist’s iPhone, reconstructed through Washington Post interviews with several people close to the situation, shines a light on a hidden world of bug hunters and their often-fraught relationship with the creator of the devices whose flaws they uncover. Azimuth is a poster child for “white hat” hacking, experts say, which is good-guy cybersecurity research that aims to disclose flaws and disavows authoritarian governments.

Two Azimuth hackers teamed up to break into the San Bernardino iPhone, according to the people familiar with the matter, who like others quoted in this article, spoke on the condition of anonymity to discuss sensitive matters. Founder Mark Dowd, 41, is an Australian coder who runs marathons and who, one colleague said, “can pretty much look at a computer and break into it.” One of his researchers was David Wang, who first set hands on a keyboard at age 8, dropped out of Yale, and by 27 had won a prestigious Pwnie Award<https://secure-web.cisco.com/1-HcBs5253T16LS3wIxXFEtErzt4wYCUHGRJTXALTsE6_tm-AVs2WISmosPdGCGyMGtEGQYJ_YO4lfx0oa1kwoVeIo4dvEyP93LY_veCGeRpiwvL6J7uu_d6EXFSZh49xwaJVnTmnFmWEo-Zw1BA0vSP556iUvqQaFdorQOqW-OFW80-uMCswvSQ0NoJWNpFJ0bRJ4psyoCyffVSc_AAv_IKiaoalBWQrTeu-sJhKDT4alOgFvh9XqQfLUsnvLeDGhZ4bs2oFWJi1NitKLVt5OYMg5vpLiehyMD1nmiR1zZAHPHnbitIpjcc91cQ0gfNDH5i6tL6bxfm4cxOY76xFOIpUDwB95sBDMpJAd6AEaxBLJejTLUGo8hVJp_O71af4vumyrORra7GdsfefNOygeu9qWs2tvr1bfbzE85As2tfG7dRG2voOEWCByfpfzxIq/https%3A%2F%2Fpwnies.com%2Fprevious%2F2013%2Fbest-privilege-escalation-bug%2F> — an Oscar for hackers — for “jailbreaking” or removing the software restrictions of an iPhone.

Attorney general and FBI director blast Apple after tracing Pensacola gunman's phone to al-Qaeda<https://www.washingtonpost.com/national-security/fbi-links-al-qaeda-to-saudi-gunman-who-killed-three-us-sailors-in-pensacola-last-year/2020/05/18/b34e3f7a-990f-11ea-89fd-28fb313d1886_story.html?itid=lk_readmore_manual_11>

Apple has a tense relationship with security research firms. Wilder said the company believes researchers should disclose all vulnerabilities to Apple so that the company can more quickly fix them. Doing so would help preserve its reputation as having secure devices.

But many security researchers say it’s legitimate to sell these flaws to democratic governments. And the ability of government agencies to unlock iPhones has also spared Apple from direct conflict with these governments. For instance, by unlocking the terrorist’s iPhone, some say, Azimuth came to Apple’s rescue by ending a case that could have led to a court-ordered back door to the iPhone.

“This is the best possible thing that could have happened,” said Will Strafach, an iOS security researcher. The vendor that unlocked the phone, far from being unethical, potentially averted “a very bad precedent” for Apple “where everyone’s phone would have weakened security.”

Wilder said Apple supports “good faith” security research. “Our engineers work closely with the security community in numerous ways,” he said.

When contacted by The Post, the FBI, Azimuth, Wang and Dowd declined to provide a comment for this story.

An ‘exploit chain’

In September 2015, Apple released its new operating system, iOS 9, which it billed as having enhanced security<https://secure-web.cisco.com/1lPoUu8b7am0FmgxyVLZ4dZ9l8Zn1hTTnZ33ppeEmtpkoxTguq8xhT9D_wERUnVMG2Xj9a8m0M6NfMErjVvR5A8Hz89b3nYOgfU80YwgXBn6FExrr8nRZIDdxbYkUJF-kzSe1r6efz7knHz1EA6SdT6QlZW6rl9e1U1xiFW8HCNGnVWh6hUsh2dBHaLz3EsnsHRv30TP4LGYL4BXQ0ZzbgNIpPgBEVklXA0o_ob_HdF_DMWfQ2namIwgkiPtrta1u812S4cA1zZ7tjwnzh2bNAQEGVI4WrZ9JoLIlErVxDxU8g-r5csOzivrXZySCOWN6tGvyNdPsfCRm08gkJtVrs4WtbB79IjdsNPb6CGgDx9n6G4hlFZHNyDdG_qSUFfGv_WqfxLet00b95QmMHp0UO4wiwGt-pN2gfFntFemQ4BX0XxBQASyGH2cv7rWtr6Sx/https%3A%2F%2F9to5mac.com%2F2015%2F05%2F22%2Fios-9-os-x-10-11-to-bring-quality-focus-smaller-apps-rootless-security-legacy-iphoneipad-support%2F> to “protect customer data.” The new iOS was running on the iPhone 5C used by Syed Rizwan Farook, a public health inspector for San Bernardino County.

The FBI suspected the iPhone 5C might have valuable clues about why Farook and Tashfeen Malik opened fire<https://secure-web.cisco.com/1-afAbR-OSRnDNFyxMHJltNARrn0gz3t5s1F_ybzketc_05iIXO1hA1xud0saJ4Tx-gmofuuFyqLThe2ZfOzOHJ6Dkh1puYFnXPCBEdAp-27BZdOxlFwWElHXLCTSHfvnnNw4cIV9xv-yyDt9s-mj3wag5fwfGcmvKk5m2VTLcyQImXM1mZ_Rc_9JFumgZURnDQgJliJTZdqF21lCCB40EbHJz_Ui_W1e8sk46wp3bcn20Qtu7jZk_HYu1RXn9dLlyG6xmTM06wqh14_ePIQPEHNBAlevW6SrZ8sJvdN_IYuK_zEUeZQ_oHDKaC4u8nfsC2McQT5E1UbswAQX8LPAXE5KMQBF86wJ-1xjHelsPtfxExeYrJHeixHItyRJExh7IcoV3RNN2Qs99lPKGK5b5iSosuAa2n6X169XrOu5qmoQNFrYtGJkFyrgqqE-lUMN/https%3A%2F%2Fwww.washingtonpost.com%2Fworld%2Fnational-security%2Freport-offers-new-details-on-san-bernardino-terrorist-attack%2F2016%2F09%2F09%2F599ea266-76be-11e6-b786-19d0cb1ed06c_story.html%3Fitid%3Dlk_inline_manual_23> on a holiday party at Farook’s office. Both Farook and Malik were killed in a shootout<https://secure-web.cisco.com/1fRZION4OFIef3kixdybLdQKerwuhougnoNbPnODOitlIrFzggQLCY7GKl7oO3yZf59Uc6J6RchS2Rr8SjKIMiyU7-cHJt9gRPcZBkZkAUsDFhyk03P_6nlVTfSAF9c0eJOPz7ue-rEcTo-qhP6BmeCU2VvxoQimOfkWU4PwUK6EkVxWpKctBTo5OnceyPEX0ILxLDAE6Jx1Lav8rL_PnadUK6HNX7xVERSharBJX1gXe7FzY_wqS9kfMnGibNhtP7A_iyS0T2RHLJNIOtZEM-D5FZqt3OaSBmZvypu-hExqPgJJONUbTikWsw8uEPVczehs17S2DJWW_nIx7PKlzC9yrGX8W7kFPER3Y8nzasBq3ItZLlaQixfeRXXVebTahB6oXNKteouoZl_s4qt0mJRcvbUV4W2QWl2ZP72sXlOvCAAMNtmCiygYWxvTU_MwJ/https%3A%2F%2Fwww.washingtonpost.com%2Fworld%2Fnational-security%2Ffor-a-small-town-cop-a-heart-stopping-moment-in-san-bernardino%2F2015%2F12%2F15%2Fb3528a4e-a35a-11e5-b53d-972e2751f433_story.html%3Fitid%3Dlk_inline_manual_23> with police.

Before the attack, Malik had posted a message on her Facebook page<https://www.washingtonpost.com/news/post-nation/wp/2015/12/08/both-san-bernardino-attackers-pledged-allegiance-to-the-islamic-state-officials-say/?itid=lk_inline_manual_24>, pledging loyalty to Abu Bakr al-Baghdadi, the leader of the Islamic State. (Baghdadi died in a U.S. Special Forces raid in Syria in 2019.) The FBI had few leads on whether the couple had accomplices or whether it was directed by the Islamic State, which was directing similar attacks around the world at the time. The FBI thought the contents of Farook’s iPhone 5C might provide useful information, such as who he had been communicating with in the lead-up to the attack.

But the phone, which belonged to Farook’s employer, was locked with Apple’s new security. In the past, the FBI could use software to quickly guess every possible combination of numbers for the four-digit passcode, a “brute force” effort that would normally take about 25 minutes. But the 5C included a feature that erased itself if the wrong password was entered more than 10 times.

Jeff Bezos's iPhone had Apple's state-of-the-art security, and that may have helped its alleged hackers<https://www.washingtonpost.com/technology/2020/01/29/apple-iphone-bezos-hack/?itid=lk_readmore_manual_28>

Months of effort to find a way to unlock the phone were unsuccessful. But Justice Department and FBI leaders, including Director James B. Comey, believed Apple could help and should be legally compelled to try<https://www.washingtonpost.com/news/morning-mix/wp/2016/02/22/fbi-director-urges-apple-to-help-unlock-killers-iphone-in-passionate-statement-its-about-the-victims-and-justice/?itid=lk_inline_manual_29>. And Justice Department officials felt this case — in which a dead terrorist’s phone might have clues to prevent another attack — provided the most compelling grounds to date to win a favorable court precedent.

In February 2016, the Justice Department obtained a court order directing Apple to write software to bypass the security feature. Apple said it would fight the order. Its argument: the government was seeking to force the company to break its own security, which could pose a threat to customer privacy.

“The U.S. government has asked us for something we simply do not have, and something we consider too dangerous to create,” Apple CEO Tim Cook wrote in a statement<https://www.apple.com/customer-letter/> at the time. “The government could extend this breach of privacy and demand that Apple build surveillance software to intercept your messages, access your health records or financial data, track your location, or even access your phone’s microphone or camera without your knowledge.”

All sophisticated software contains “bugs” or flaws that cause computer programs to act in unexpected ways. Not all bugs are significant, and on their own they don’t pose a security risk. But hackers can seek to take advantage of certain bugs by writing programs called exploits. Sometimes they combine a series into an “exploit chain” that can knock down the defenses of a device like the iPhone one-by-one.

Azimuth specialized in finding significant vulnerabilities. Dowd, a former IBM X-Force researcher whom one peer called “the Mozart of exploit design,” had found one in open-source code from Mozilla that Apple used to permit accessories to be plugged into an iPhone’s lightning port, according to the person. He found it even before Farook and his wife opened fire at the Inland Regional Center, and thought it might be useful at some point to develop into a hacking tool. But Azimuth was busy at the time with other projects.

Mozilla spokeswoman Ellen Canale said the company has no knowledge of any bug that was connected to the exploit.

Two months after the attack, Comey testified to Congress that investigators were still unable to unlock the terrorist’s iPhone. Seeing the media reports, Dowd realized he might have a way to help. Around that time, the FBI contacted him in Sydney. He turned to 30-year-old Wang, who specialized in exploits on iOS, the people said.

Using the flaw Dowd found, Wang, based in Portland, Ore., created an exploit that enabled initial access to the phone — a foot in the door. Then he hitched it to another exploit that permitted greater maneuverability, according to the people. And then he linked that to a final exploit that another Azimuth researcher had already created for iPhones, giving him full control over the phone’s core processor — the brains of the device. From there, he wrote software that rapidly tried all combinations of the passcode, bypassing other features, such as the one that erased data after 10 incorrect tries.

Wang and Dowd tested the solution on about a dozen iPhone 5Cs, including some bought on eBay, the people said. It worked. Wang dubbed the exploit chain “Condor.”

Google uncovers 2-year iPhone hack that was 'sustained' and 'indiscriminate'<https://www.washingtonpost.com/business/2019/08/30/google-researchers-uncover-year-iphone-hack-tied-malicious-websites/?itid=lk_readmore_manual_43>

In mid-March, Azimuth demonstrated the solution at FBI headquarters, showing Comey and other leaders how Condor could unlock an iPhone 5C. Then, one weekend, the FBI lab did a series of forensic tests to be sure it would work without destroying data. The tests were all successful, according to the people. The FBI paid the vendor $900,000, according to remarks by Sen. Dianne Feinstein (D-Calif.) in May 2017.

FBI officials were relieved but also somewhat disappointed, according to people familiar with the matter. They knew they were losing an opportunity to have a judge bring legal clarity to a long-running debate over whether the government may compel a company to break its own encryption for law enforcement purposes.

On March 21, 2016, the government canceled a hearing scheduled for the following day on the legal case in California.

Soon after, the FBI unlocked the phone. Nothing <https://www.washingtonpost.com/world/national-security/no-links-to-foreign-terrorists-found-on-san-bernardino-iphone-so-far-officials-say/2016/04/14/f1aa52ce-0276-11e6-9203-7b8670959b88_story.html?itid=lk_inline_manual_49> of real significance — no links to foreign terrorists — was found.

The government subsequently abandoned its legal bid<https://www.washingtonpost.com/world/national-security/fbi-has-accessed-san-bernardino-shooters-phone-without-apples-help/2016/03/28/e593a0e2-f52b-11e5-9804-537defcc3cf6_story.html?tid=a_inl_manual&itid=lk_inline_manual_50> to force Apple to unlock the phone.

‘Virtual’ iPhones

Apple sought to recruit Wang to work on security research, according to the people. Instead, in 2017 he co-founded Corellium<https://secure-web.cisco.com/1tPnBqxjW5497ThCpela8E7bpDtYATmWaUOvr94wuhwWaMMgyQzmusJqInRhhsmDwzRzaSH_u7TQhjM1LLZISF15rdhEANwfkYIXQY8E9dSGRPsf155jy-o8aZwUNV9xbTUG6U9ACOl2-fxAJgvdI-1gPPNch5cCopT5HWXR6dx7ytFDSnYuQF8mHq1fg33iNk17zgBpiGmAnr-Srub-3EXIHa5IXmxJY8FywquxPXJ_dyGo1df-E6YZRjRU1IJ27x5M084ZpwDkpwzPTTEyBEGtw5BFO_eZOSUlF264n8w3tgnfI-gZAbPXFxw2lWbw2Ok18-32JEPsycgK-51VQd20INYA1ARQsPzBeCgYeuHJpudveNMmTpv6XnH8fzxkr_0ujMEmg4yRy10YNnL6xQr7rirOl1VfJIcvI-tiHDN7R-X4kqGMyVmYWsbob5FYP/https%3A%2F%2Fcorellium.com%2Fsecurity-research>, a company based in South Florida whose tools help security researchers. The tools allow researchers to run tests on Apple’s mobile operating system using “virtual” iPhones. The virtual phones run on a server and display on a desktop computer.


In 2019, Apple sued Corellium<https://secure-web.cisco.com/1BzSEgKgFr7OZpgIm3bJw8ZRBbrjG2jAyzCb0Z3LhPLcwiGOD8iBFEqcKShHuAZp-0qLiQQO1YZWBvrsWMkAvPO7hFaecaFAZD7VPQe9892-SjIBz2Z43h_H7UfgQxMSarH4R4tky4FiEdDNXuiEUB-n2LUVeZBqsZtffs5jTD0EAKnD4J8PRaf22yUtaRcoi4zvWolkkQNeFHyq28Mfa1uAC4OnmoXwt6-C6juBSpdgUod1f9Ar8cRKprRwo6P0vrB0NzSUD1rGE-5wmvgje8YNBDYMSM0B57pKwvHDaXSj3MAyg-PQYSUPzeLa9MuCuJpPaiq2T9NxIWnRRqvSh0ByBGM8RoKMPD4ZTcUSj5uMJ2k-K9hCybyln2fyaW8PwnckhsjrQoBMfYM7Lzv0CZFMo7lXHwhaicjBBGK8jTJsqkTi6SRx3TodlvSIvCKwr/https%3A%2F%2Farstechnica.com%2Ftech-policy%2F2019%2F08%2Fapple-sues-virtual-iphone-vendor-that-helps-hackers-find-ios-bugs%2F> for copyright violation. As part of the lawsuit, Apple pressed Corellium and Wang to divulge information about hacking techniques that may have aided governments and agencies such as the FBI.

Apple subpoenaed Azimuth, Corellium’s first customer, according to court documents. Apple wanted client lists from Azimuth, which is now owned by L3 Harris, a major U.S. government contractor, that might show malign entities such as, potentially, authoritarian governments. L3 and Azimuth said they were “highly-sensitive and a matter of national security,” according to court documents.

Last April, Apple also made a document request in the lawsuit for “all documents concerning, evidencing, referring to, or relating to any bugs, exploits, vulnerabilities, or other software flaws in iOS of which Corellium or its employees currently are, or have ever been, aware.”

Those employees included Wang. The request would have turned up Condor.

The judge denied the request in part.

During a deposition, Apple questioned Wang about the morality of selling exploits to governments, according to court records. A lawyer pressed him during the deposition on whether he was aware of any bugs that were not reported to Apple but were later found by malicious hackers.

Apple “is trying to use a trick door to get [classified information] out of him,” Corellium attorney Justin Levine said, according to a transcript. Corellium declined to comment for this story.

Comey defends FBI's purchase of iPhone hacking tool<https://secure-web.cisco.com/1Fbzz3kQNhi3UUGby3RNd3n24KNk6qa0sakm1xKE6k0ZmbMtR47kth_PnTywoegM7yPIRXkyZ6teMLQ3oSYx9902GIopF-ap0B4aaxGC8SB6J1WVekWJnKMQvUhbeLM_o6kFMNoy39JiMfFvfdG3lVn127_7fRjdlPKrQZZqllJU9LrKaVAGhPZZXYqQmah5QXhQajtJJeHjoAtMwvVTi_j3Cj5x-cyNKIHGAW4wuSIDg4m5xEznQjap3JTZ40lh2tgiL7ZYpFDbDsWmf9SOxI3ix1Co7teMyKc2AsrH4RUV6ogQB_KrbFEcVTSX2epmKu5T2BFl1PfTcX_EX79XUvqKFFytGs2DpLE-8j_gWIrhq6LMlYGabtf1GqvL7HoetpQT4yl9HWbNWEoh9WtZWVxsHNTx77CUxzN5Jw4gZJwlFoP_WQBZgevYfUqpaxIUs/https%3A%2F%2Fwww.washingtonpost.com%2Fworld%2Fnational-security%2Fcomey-defends-fbis-purchase-of-iphone-hacking-tool%2F2016%2F05%2F11%2Fce7eae54-1616-11e6-924d-838753295f9a_story.html%3Fitid%3Dlk_readmore_manual_62>

In its statement, Apple said the case “is about Corellium attempting to profit by selling access to Apple’s copyrighted works.”

In its lawsuit, Apple argued that Corellium has “no plausible defense” for infringing on Apple’s copyright, in part because it “indiscriminately markets its iPhone replicas to any customer, including foreign governments and commercial enterprises.”

Corellium has denied the allegation. It has countered that the lawsuit is an attempt to put it out of business following a failed effort by Apple in 2018 to purchase the company.

“If Apple wants to make their phones more secure against these government-affiliated bug hunters, then they should make their phones more secure,” said Matthew D. Green, a computer scientist at Johns Hopkins University, who has led research that found holes in Apple’s encryption. “They shouldn’t be going after people in a courtroom.”

In December, U.S. District Judge Rodney Smith in Fort Lauderdale, Fla., dismissed Apple’s copyright claims<https://www.washingtonpost.com/technology/2020/12/29/apple-corellium-lawsuit/?itid=lk_inline_manual_67> against Corellium. He ruled Corellium’s virtual iPhones do not violate Apple’s copyright because they are used to find security vulnerabilities, not compete with Apple sales. He deemed “puzzling, if not disingenuous” Apple’s allegation that Corellium’s products are sold indiscriminately.

The legal fight is far from over<https://www.natlawreview.com/article/corellium-s-bite-apple-s-ios-security-research-fair-use-dmca-claims-loom>. Apple can appeal Smith’s ruling. And Apple has lodged another claim: that Corellium’s tools illegally bypass Apple’s security measures. That trial, which will be closely watched by security researchers<https://secure-web.cisco.com/1Ik6h5Iqh2TxpSevbCiW-p0j5sgJ_yfSmCMKeE3GucsvY0vI4DCuGOc_jti4gAY_BxjM3c98hrTffe9JFUeK2d6I0Q-Hq_EIcP8HXyss-mkFlSiJsHrhTBfs3qmUxoUTk19cujzE1sKnfbKi5ontJrJ8nymsLW73xeiItolK9-KWgm6FNsft3TvhDhY7XRpvpkieXy7PWWoSLXY4CxSW2qu2I-_5KZb6-VfbmFACWhstv5cZJDg-INCYNIZiNbtIQgkPNmnQ3kEF9ZV3_EdBgh2zK7D8WgNkWAUe6y2gsn6YgCh5XUPLJkYCup_GyUOn22aq4s__g7za54uava6i5FJjUMzLT0OEmN8bjPnJoPyjY3yLM94cYd-QPUCsvpFf1pR57t_nzYJfAp7WCLDtDRVVuKKvXjwNNV6YtZtDvfGuriggNTcBucgbzfnOj2dSqXyrbW06YqJCc1p6XGwHFSw/https%3A%2F%2Ftorrentfreak.com%2Fgithub-wants-to-get-rid-of-the-dmcas-anti-circumvention-fud-210312%2F>, is set for the summer.

Meanwhile, Corellium can keep selling tools that help researchers find iOS bugs.

But all exploits have a shelf life.

A month or two after the FBI unlocked the terrorist’s iPhone, Mozilla discovered the flaw in its software and patched it in a routine update. So did vendors that relied on the software, including Apple.

The exploit was rendered useless.