Saturday, March 5

What is a “lying-dormant cyber pathogen?” San Bernardino DA won’t say

(credit: pmquan)

One day after the San Bernardino County district attorney said that an iPhone used by one of the San Bernardino shooters might contain a "lying-dormant cyber pathogen," the county's top prosecutor went on the offense again. DA Michael Ramos said Apple must assist the FBI in unlocking the phone because an alleged security threat might have been "introduced by its product and concealed by its operating system."

Ramos, however, has been tight-lipped on exactly what security threat may be on the passcode-protected phone of Syed Farook, a county worker who was one of two shooters in the Dec. 2 massacre that killed 14 and wounded scores of others. The prosecutor suggested in a court filing yesterday that the iPhone—a county phone used by Farook and recovered after the shooting—might be some type of trigger to release a "lying-dormant cyber pathogen" into the county's computer infrastructure. On Friday, the district attorney again demanded that a federal magistrate presiding over the dispute command Apple to help decrypt the phone.

Apple has not advanced a single argument to indicating [sic] why the identification and prosecution of any outstanding coconspirators, or to detect and eliminate cyber security threats to San Bernardino County's infrastructure introduced by its product and concealed by its operating system, and Apple's refusal to assist in acquiring that information, is not a compelling governmental interest.

To the extent that Apple states in its brief at page 33 that there is no compelling state interest because the government "has produced nothing more than speculation that this iPhone might contain potentially relevant information," Apple completely forgets that a United States Magistrate has issued a search warrant based on a finding of probable cause that the iPhone does contain evidence of criminal activity. The reason we search is to find out if the device contains evidence or is an instrumentality of the crime. Such authority is granted by the United States Constitution.

But what exactly is a "lying-dormant cyber pathogen?" As the chatter on Twitter and elsewhere could attest, security and forensics experts have never heard of this type of threat. Online commenters called it everything from a "magical unicorn" to a make-believe plot that we might see on the broadcast TV show CSI: Cyber. 

Read 3 remaining paragraphs | Comments

No comments:

Post a Comment