Apple To Feds: Terrorist’s Apple ID Password Changed In Government Custody To Block Access

Here’s a plot twist that I wasn’t expecting. It appears that the password to the Apple ID associated with San Bernardino terrorists was changed less than 24 hours after the government took possession of the device. Now an Apple ID is a unique account that ties you to your iDevice, and Apple who now claims to have been helping the government get into this iPhone, could have used the Apple ID to download data from the phone without having to crack into it. But now that the password has changed, that’s apparently not possible. Here’s what Buzzfeed had to say on that front:

The executives said the company had been in regular discussions with the government since early January, and that it proposed four different ways to recover the information the government is interested in without building a backdoor. One of those methods would have involved connecting the iPhone to a known Wi-Fi network and triggering an iCloud backup that might provide the FBI with information stored to the device between the October 19th and the date of the incident.

Apple sent trusted engineers to try that method, the executives said, but they were unable to do it. It was then that they discovered that the Apple ID password associated with the iPhone had been changed. (The FBI claims this was done by someone at the San Bernardino Health Department.)

Had that password not been changed, the executives said, the government would not need to demand the company create a “backdoor” to access the iPhone used by Syed Rizwan Farook, who died in a shootout with law enforcement after a terror attack in California that killed 14 people. The Department of Justice filed a motion to compel the company to do that earlier Friday.

Now this seemed a bit odd to me that triggering an iCloud backup was even an option. So I dug deeper. If you look into this document, the FBI has access (via Apple presumably) to iCloud backups before October 19th which is when the attack happened, but not after that date.

This this is what I think Apple was trying to do. I think what they were trying to do was to have the phone connect to a known wifi network and leave it plugged into an AC charger so a backup of the phone would automatically be created. The feds could then use that backup to get whatever info they were looking for. But now that the password was changed, you probably need to unlock the device and input the new password before the device can create a backup again. That’s why the government needs to get Apple to come up with a custom version of iOS to get into the phone.

It also highlights one important thing. If you want your iDevice backups to be secure, don’t back them up to the iCloud. Instead back them up to a local computer and encrypt them.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading